Is sd-nfs14.rar safe?
Only 2 of 75 engines flagged this old archive, both low-trust, while trusted engines and the completed sandbox produced no corroborating malware conclusion.
The detections are limited to Jiangmin and VBA32, while no tier-1 engine identified malware or agreed on a family. One sandbox recorded defense-impairment technique T1562.001, so the archive should still be handled cautiously, especially because its two extracted children remain unclassified.
82665a415ec0bfc80d…7f24aa4353cfdbRecommended next actions
Before opening or extracting
Open or extract it only when its sender or download source has been independently verified.
If you already opened or extracted it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The detections are limited to Jiangmin and VBA32, while no tier-1 engine identified malware or agreed on a family. One sandbox recorded defense-impairment technique T1562.001, so the archive should still be handled cautiously, especially because its two extracted children remain unclassified.
Only 2 of 75 engines reported malware, and both detections came from the low-trust tier. Thirteen tier-1 engines reported no detection, and there is no tier-1 family consensus supporting the Convagent or Genome labels. A completed sandbox run recorded T1562.001, but produced no malicious sandbox verdict, persistence indicator, or observed network contact. The two extracted files were not identified as malicious, although their individual verdicts remain unknown. No YARA research rules or external malware-feed match corroborated the detections, and a complete contacted-host reputation result is unavailable.
What We Detected
Jiangmin and VBA32 flagged the archive, producing 2 detections among 75 engines. Both are low-trust detections, while tier-1 engines including Kaspersky, Microsoft, ESET-NOD32, Fortinet, and DrWeb reported no detection. The labels differ between Genome and Convagent, and no trusted family consensus was established.
Threat Behavior
One sandbox extracted and launched Speed.exe and recorded MITRE technique T1562.001, associated with impairing defenses. However, the run produced no malicious sandbox verdict, persistence indicator, or observed network contact. Two extracted files were inspected without a malicious-child finding, but both remain individually unclassified. No complete contacted-host reputation result is available.
What To Do Now
Keep endpoint protection enabled and avoid running the extracted executable unless its origin and purpose are trusted. For additional assurance, rescan the two extracted child hashes or execute them only in an isolated analysis environment.
Where this verdict could be wrong4 caveats
- T1562.001 indicates attempted impairment of defenses, which can be associated with malware even though the sandbox issued no malicious verdict.
- Jiangmin and VBA32 independently used trojan/downloader labels, but neither is a tier-1 detection and their family names differ.
- contactedHosts=null, so the absence of observed network contacts is not supplemented by a completed host-reputation cross-check.
- Both extracted children have unknown verdicts; hasMaliciousChild=false therefore does not establish that they are benign.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Only 2/75 engines detected malware, both from the low-trust tier.
- engines.tier1Malicious=0 with 13 tier-1 engines reporting no detection.
- behaviour.hasMaliciousSandboxVerdict=false.
- droppedChildren.hasMaliciousChild=false.
- No MalwareBazaar or YARAify match was found.
- MITRE T1562.001 was observed during sandbox execution.
- Jiangmin and VBA32 applied trojan or downloader labels.
- The archive launches an extracted executable named Speed.exe.
- Both extracted child verdicts remain unknown.
- No complete contacted-host reputation cross-check is available.
Keep security protection enabled and do not extract or run Speed.exe unless the archive came from a trusted source. If execution is necessary, first obtain separate scan results for both extracted child hashes.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete2 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 7MITRE ATT&CK techniques
- 8spawned processes
- 0network contacts
- 20filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- \REGISTRY\A\{8cdd7f5e-af1a-65e4-c3f5-af9d678b1c0e}\Root\InventoryApplicationFile\PermissionsCheckTestKey
- \REGISTRY\A\{8cdd7f5e-af1a-65e4-c3f5-af9d678b1c0e}\Root\InventoryApplicationFile\speed.exe|3f8c1054341da00
- \REGISTRY\A\{8cdd7f5e-af1a-65e4-c3f5-af9d678b1c0e}\Root\InventoryApplicationFile\speed.exe|3f8c1054341da00\ProgramId
- \REGISTRY\A\{8cdd7f5e-af1a-65e4-c3f5-af9d678b1c0e}\Root\InventoryApplicationFile\speed.exe|3f8c1054341da00\FileId
- \REGISTRY\A\{8cdd7f5e-af1a-65e4-c3f5-af9d678b1c0e}\Root\InventoryApplicationFile\speed.exe|3f8c1054341da00\LowerCaseLongPath
- \REGISTRY\A\{8cdd7f5e-af1a-65e4-c3f5-af9d678b1c0e}\Root\InventoryApplicationFile\speed.exe|3f8c1054341da00\Name
- C:\ProgramData\Microsoft\Windows\WER\Temp
- C:\ProgramData\Microsoft\Windows\WER\Temp\e5e9d3fd-dc28-4cb6-b32f-a514f54394d5
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue
- C:\ProgramData\Microsoft\Windows\WER\Temp\d7c7d1bb-82a2-4e4a-888c-67f3bd61b012
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive
- Local\DirectSound DllMain mutex (0x00001630)
- \Sessions\1\BaseNamedObjects\Local\DirectSound DllMain mutex (0x00001984)
- \Sessions\1\BaseNamedObjects\Local\__DDrawExclMode__
- \Sessions\1\BaseNamedObjects\Local\__DDrawCheckExclMode__
- \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess6532
Files this sample writes at runtime
This file drops 2 children at runtime. None are currently flagged malicious in our cache.
- b0d008f03df732427f19…e2d45aNever scannednever seen before
- 7565ead162f26d6df3b2…a0e956Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 2 / 75engines flagged
- 23sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
2 of 75 antivirus engines flagged the file, including Jiangmin and VBA32.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 24 times from 23 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: sd-nfs14.rar — 82665a415ec0bfc80d3b3501586a9443520c2b9b06f7775dfc7f24aa4353cfdb
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — "C:\Users\<USER>\AppData\Local\Temp\Speed.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — C:\Windows\SysWOW64\WerFault.exe -u -p 5680 -s 1384
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: Temp — C:\ProgramData\Microsoft\Windows\WER\Temp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: e5e9d3fd-dc28-4cb6-b32f-a514f54394d5 — C:\ProgramData\Microsoft\Windows\WER\Temp\e5e9d3fd-dc28-4cb6-b32f-a514f54394d5
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
2 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- sd-nfs14.rar
- Format
- RAR
- Code signing
- Not applicable to this file type
- Size
- 1.3 MB
- Last analyzed
- Oct 5, 2026, 7:56 AM UTC
82665a415ec0bfc80d3b3501586a9443520c2b9b06f7775dfc7f24aa4353cfdbSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open or extract it only when its sender or download source has been independently verified.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is sd-nfs14.rar safe?
What is sd-nfs14.rar?
How many antivirus engines detected sd-nfs14.rar?
What is the SHA-256 hash of sd-nfs14.rar?
Is it safe to open or extract sd-nfs14.rar?
How up to date is this analysis of sd-nfs14.rar?
Community
Member reviews and reports for this exact file hash.