File verdict·Decided by the MT AI Engine
Our call

Suspicious

Unsigned ZIP with low-trust flagging and heuristic process-injection/C2 signals, but no tier-1 consensus or malicious children.

Trust score52Caution
MT AI confidence · 55%
ZEN_Scripter_10_4_5_12.zip
6.0 MB
7eab791cf1ed2b345c88ebec5679
Antivirus engines
1 of 75 flagged
Code signing
Unsigned
Age
First seen 4y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

55%Confidence
Moderate
Reasoning

The sample presents a mixed-signal profile. On one hand, only 1 of 68 reporting engines flagged it, and that engine is low-trust; all 18 tier-1 engines reported clean. On the other hand, heuristic analysis identified process injection and direct-IP C2 contact — both offensive MITRE techniques associated with malware. The dropped children are not malicious, and no sandbox verdict confirmed malicious behaviour. The unsigned status and lack of signer history prevent us from grounding the call in publisher reputation. The medium prevalence (69 submitters, 77 submissions) and absence of external intel hits (CIRCL, YARAify, MalwareBazaar) suggest the sample is not a known malware family. The balance of evidence points toward a suspicious but not definitively malicious sample — likely a legitimate tool with unusual or obfuscated behaviour that triggers heuristic alarms.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines: 1/68 malicious (MaxSecure, low-trust); tier1Malicious=0; onlyLowTrustFlagging=true

  2. triggeredHeuristics: T1055 (Process Injection) and direct-IP C2 contact (204.79.197.203, 209.85.200.94) — offensive MITRE techniques

  3. droppedChildren: 2 inspected, 0 malicious, worst=suspicious; hasMaliciousChild=false

  4. signing.verified=false; no signer history; unsigned ZIP

  5. prevalence.classification=medium (69 submitters, 77 submissions); no external-intel hits (CIRCL, YARAify, MalwareBazaar)

Points in its favour
  • 18 tier-1 antivirus engines reported clean (Kaspersky, BitDefender, ESET, Avira, Fortinet, Ikarus, etc.)
  • No malicious sandbox verdict recorded
  • No malicious dropped children confirmed (0/2 inspected)
  • No external intel hits (CIRCL, YARAify, MalwareBazaar)
  • Medium prevalence (69 submitters, 77 submissions) suggests legitimate or widely-distributed software
Points against
  • Process injection (T1055) detected — payload smuggled into legitimate process to bypass AV hooks
  • Direct-IP C2 contact (204.79.197.203, 209.85.200.94) without DNS — bypasses reputation systems and domain blocklists
  • Unsigned file with no signer history — no publisher reputation to ground trust
  • One low-trust engine flagged as trojan — weak consensus but non-zero malicious signal
What to do

Treat this sample as suspicious pending further investigation. If the file is from an untrusted source, do not execute it. If it is a known legitimate tool, the heuristic triggers may be false alarms; verify the source and consider whitelisting after confirmation.

Sources disagree

1 contradiction resolved by the scoring engine

Only low-trust / heuristic engines flagged this file
1 engine from the heuristic / generic-AI set flagged it. No tier-1 engine agreed.
Detection weight reduced in scoring.
Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
7

Adversary techniques mapped to the MITRE ATT&CK framework.

T1055T1056T1059T1071T1082T1497T1562.001
Spawned processes
1
$(unnamed)
"C:\Users\<USER>\AppData\Local\Temp\ZEN_Scripter_10_4_5_12.exe"
Network activity
2
IP addresses2
  • 204.79.197.203
  • 209.85.200.94
Filesystem & mutexes
5
Files written5
  • C:\Users\user\AppData\Local\Temp\aa0xqxbd.alt
  • C:\Users\user\AppData\Local\Temp\aa0xqxbd.alt\ZEN_Scripter_10_4_5_12.exe
  • C:\Users\user\AppData\Local\Temp\unarchiver.log
  • C:\Users\user\AppData\Roaming
  • \Device\ConDrv\\Connect
Dropped payload

Files this sample writes at runtime

This file drops 2 children. 1 is flagged suspicious in our cache.

1 suspicious1 unseen
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

2 synthesis
MITRE ATT&CK profile
Defense evasion× 1C2× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    "C:\Users\<USER>\AppData\Local\Temp\ZEN_Scripter_10_4_5_12.exe"
  • DirectIpC2medium

    Sample contacted 2 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    204.79.197.203 · 209.85.200.94
Antivirus engine breakdown

1 detection across 75 engines

1 malicious0 suspicious74 clean
Tier-118 engines
0flag
Top commercial AVs (low FP rate)
Tier-236 engines
0flag
Mainstream engines with mixed FP rates
Low-trust21 engines
1flag
Heuristic / generic-AI engines (high FP rate)
MaxSecure
malicious
Trojan.Malware.300983.susgen
Hash 7eab791cf1ed… cross-referenced against 75 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
69
Moderate upload volume.
Total submissions
77
Includes repeat uploads by the same source.
First seen by VT
4y ago
Dec 15, 2022
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
12/15/2022, 4:42:15 PM
First seen (MalwareBazaar)
Last analysis (VT)
1/5/2025, 12:51:13 AM
Scanned here
6/22/2026, 5:14:39 AM
File name
ZEN_Scripter_10_4_5_12.zip
Size
6.05 MB
MIME type
(unknown)
Detected type
ZIP
SHA-256
7eab791cf1ed2b345cfb2c8c7c1e1801e9780fdf0ca1a6c22f8bf688ebec5679
MD5
cf41e8ca62846f927aafcaa06d9ad343
SHA-1
96ae1209d1e9af040da5b0d8efac6e584d24a4ca
First seen (VT)
12/15/2022, 4:42:15 PM
Last analysis (VT)
1/5/2025, 12:51:13 AM
First scan (MalwareTips)
6/22/2026, 5:14:39 AM
Last scan (MalwareTips)
6/22/2026, 5:14:39 AM
Behavior tags
zipchecks-user-inputlong-sleepsdetect-debug-environmentcontains-pe
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.