Suspicious
Unsigned ZIP with low-trust flagging and heuristic process-injection/C2 signals, but no tier-1 consensus or malicious children.
7eab791cf1ed2b345c…88ebec5679The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The sample presents a mixed-signal profile. On one hand, only 1 of 68 reporting engines flagged it, and that engine is low-trust; all 18 tier-1 engines reported clean. On the other hand, heuristic analysis identified process injection and direct-IP C2 contact — both offensive MITRE techniques associated with malware. The dropped children are not malicious, and no sandbox verdict confirmed malicious behaviour. The unsigned status and lack of signer history prevent us from grounding the call in publisher reputation. The medium prevalence (69 submitters, 77 submissions) and absence of external intel hits (CIRCL, YARAify, MalwareBazaar) suggest the sample is not a known malware family. The balance of evidence points toward a suspicious but not definitively malicious sample — likely a legitimate tool with unusual or obfuscated behaviour that triggers heuristic alarms.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 1/68 malicious (MaxSecure, low-trust); tier1Malicious=0; onlyLowTrustFlagging=true
triggeredHeuristics: T1055 (Process Injection) and direct-IP C2 contact (204.79.197.203, 209.85.200.94) — offensive MITRE techniques
droppedChildren: 2 inspected, 0 malicious, worst=suspicious; hasMaliciousChild=false
signing.verified=false; no signer history; unsigned ZIP
prevalence.classification=medium (69 submitters, 77 submissions); no external-intel hits (CIRCL, YARAify, MalwareBazaar)
- 18 tier-1 antivirus engines reported clean (Kaspersky, BitDefender, ESET, Avira, Fortinet, Ikarus, etc.)
- No malicious sandbox verdict recorded
- No malicious dropped children confirmed (0/2 inspected)
- No external intel hits (CIRCL, YARAify, MalwareBazaar)
- Medium prevalence (69 submitters, 77 submissions) suggests legitimate or widely-distributed software
- Process injection (T1055) detected — payload smuggled into legitimate process to bypass AV hooks
- Direct-IP C2 contact (204.79.197.203, 209.85.200.94) without DNS — bypasses reputation systems and domain blocklists
- Unsigned file with no signer history — no publisher reputation to ground trust
- One low-trust engine flagged as trojan — weak consensus but non-zero malicious signal
Treat this sample as suspicious pending further investigation. If the file is from an untrusted source, do not execute it. If it is a known legitimate tool, the heuristic triggers may be false alarms; verify the source and consider whitelisting after confirmation.
1 contradiction resolved by the scoring engine
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 204.79.197.203
- 209.85.200.94
- C:\Users\user\AppData\Local\Temp\aa0xqxbd.alt
- C:\Users\user\AppData\Local\Temp\aa0xqxbd.alt\ZEN_Scripter_10_4_5_12.exe
- C:\Users\user\AppData\Local\Temp\unarchiver.log
- C:\Users\user\AppData\Roaming
- \Device\ConDrv\\Connect
Files this sample writes at runtime
This file drops 2 children. 1 is flagged suspicious in our cache.
- 0e01904957d0d45f3a54…366a11Suspicious0/66 enginesrisk 52from our cache
- 17f1f75dfd92af557aff…6dcc97Never scannednever seen before
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
Evidence"C:\Users\<USER>\AppData\Local\Temp\ZEN_Scripter_10_4_5_12.exe"Sample contacted 2 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence204.79.197.203 · 209.85.200.94
1 detection across 75 engines
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- ZEN_Scripter_10_4_5_12.zip
- Size
- 6.05 MB
- MIME type
- (unknown)
- Detected type
- ZIP
- SHA-256
- 7eab791cf1ed2b345cfb2c8c7c1e1801e9780fdf0ca1a6c22f8bf688ebec5679
- MD5
- cf41e8ca62846f927aafcaa06d9ad343
- SHA-1
- 96ae1209d1e9af040da5b0d8efac6e584d24a4ca
- First seen (VT)
- 12/15/2022, 4:42:15 PM
- Last analysis (VT)
- 1/5/2025, 12:51:13 AM
- First scan (MalwareTips)
- 6/22/2026, 5:14:39 AM
- Last scan (MalwareTips)
- 6/22/2026, 5:14:39 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.