Is BFTSetup_V1.7.rar safe?
Nine tier-1 engines flag this archive, including VMProtect trojan detections, while sandbox evidence shows defense impairment, elevation, destructive capability, and LSASS-related activity.
The archive drew detections from 33 of 74 engines, including nine high-trust engines and two VMProtect-family identifications. A completed sandbox also recorded three offensive MITRE techniques and LSASS-related activity, so the evidence is substantially stronger than a packer-only false positive.
979e3056db81304954…eea4d759fcbbc0Recommended next actions
Before opening or extracting
Do not open or extract it. Delete this archive from the device, then empty the Recycle Bin or Trash.
If you already opened or extracted it
Close it. If it opened links, requested credentials, or triggered unexpected behavior, disconnect from the internet and run a full device scan.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The archive drew detections from 33 of 74 engines, including nine high-trust engines and two VMProtect-family identifications. A completed sandbox also recorded three offensive MITRE techniques and LSASS-related activity, so the evidence is substantially stronger than a packer-only false positive.
The strongest evidence is the breadth and quality of antivirus detections: 33 of 74 engines flagged the archive, including nine tier-1 engines. ESET-NOD32 and Ikarus specifically identify a VMProtect-packed trojan, although the two-engine family agreement does not meet the strong-consensus threshold. Runtime observation recorded T1485, T1548, and T1562.001, plus LSASS-related process activity that triggered a credential-dumper heuristic. No explicit malicious sandbox verdict was issued, and the sole observed host had no adverse cached reputation, but these points do not explain away the high-trust engine findings. The archive is established and widely submitted, yet its negative reputation and persistent multi-vendor detections support treating it as a generic packed trojan rather than ordinary installer software.
What We Detected
Thirty-three of 74 antivirus engines flagged the archive, including nine tier-1 engines. ESET-NOD32 and Ikarus identified VMProtect-related trojan content, while BitDefender, Emsisoft, GData, Symantec, and TrendMicro supplied additional generic-trojan detections. Two tier-1 engines agree on VMProtect, which supports the packer or family association but is below the strong-consensus threshold.
Threat Behavior
One completed sandbox run recorded T1485, T1548, and T1562.001, covering destructive impact, privilege elevation, and impairment of defenses. It also recorded LSASS-related process activity, causing the MalwareTips.Synth.CredentialDumper heuristic to fire. The run did not issue an explicit malicious sandbox verdict, and its only observed domain, nexusrules.officeapps.live.com, was fully checked without a cached malicious or suspicious match. Ten dropped files were inspected, but all remained unclassified rather than confirmed clean.
What To Do Now
Do not extract or run this archive on a production system. Keep endpoint protection enabled, quarantine or remove the file, and obtain any required flashing utility only from its verified official publisher. If it has already run, perform a full endpoint scan and review the system for credential access, security-control changes, and unauthorized privilege elevation.
Where this verdict could be wrong5 caveats
- engines.tier1FamilyConsensus.strong=false: only 2 tier-1 engines agree on VMProtect, while several other detections are generic or PUA labels.
- behaviour.hasMaliciousSandboxVerdict=false, and the single completed sandbox did not issue an explicit malware verdict.
- contactedHosts inspected 1/1 observed host and found no cached malicious or suspicious match.
- droppedChildren inspected 10 files without a malicious child, although every child remained unclassified.
- prevalence shows 749 submitters and 846 submissions, indicating the file is neither rare nor newly observed.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- contactedHosts inspected the sole observed domain and found no cached malicious or suspicious match.
- behaviour.hasMaliciousSandboxVerdict=false.
- droppedChildren.hasMaliciousChild=false, although all 10 children remain unknown.
- The file is established, with 749 submitters and 846 submissions.
- brandMismatch.detected is not present.
- 33/74 antivirus engines reported malicious content.
- Nine tier-1 engines detected the sample.
- ESET-NOD32 and Ikarus supplied VMProtect trojan labels.
- Sandbox observation included T1485, T1548, and T1562.001.
- LSASS-related activity triggered MalwareTips.Synth.CredentialDumper.
- The archive carries long-sleep and debug-environment-detection tags.
Quarantine the archive and do not run its installer; acquire the tool only through a verified official source. If execution already occurred, keep protection enabled and perform a full scan plus credential-access and security-control review.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete33 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Complete1 contacted host was cross-checked.
YARA
Complete1 signature or behavior rule matched.
External intel
PartialIndependent reference checks were attempted but are incomplete.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 9MITRE ATT&CK techniques
- 15spawned processes
- 1network contacts
- 40filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Attempted to impair or bypass security controls.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Scans through your files and folders.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Collects details about your system.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
BFTSetup_V1.7.rar
979e3056db81304954455f664087671c11ce988841c5fe140deea4d759fcbbc0
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\BFTSetup1.7.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\Explorer.EXE
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
setupConfiguration.archive
C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\setupConfiguration.archive
04Isolated runtime analysis - Written fileObserved
SC.dat
C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\SC.dat
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
nexusrules.officeapps.live.com
Contact observed during runtime.
06Isolated runtime analysis
6 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- nexusrules.officeapps.live.com
- HKEY_USERS\S-1-5-21-575823232-3065301323-1442773979-1000\Software\WinRAR\Interface\Themes\ShellExtIcon
- HKEY_USERS\S-1-5-21-575823232-3065301323-1442773979-1000\Software\WinRAR\Interface\Themes\ShellExtBMP
- HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\DirectSound\\Speaker Configuration\Speaker Configuration
- HKEY_USERS\S-1-5-21-575823232-3065301323-1442773979-1000\Software\WinRAR\FileList\FileColumnWidths\mtime
- HKEY_USERS\S-1-5-21-575823232-3065301323-1442773979-1000\Software\WinRAR\FileList\FileColumnWidths\type
- HKEY_USERS\S-1-5-21-575823232-3065301323-1442773979-1000\Software\WinRAR\FileList\FileColumnWidths\name
- C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\setupConfiguration.archive
- C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\SC.dat
- C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\languages.dat
- C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\Desktop.dat
- C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\OS.dat
- C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\Commands.dat
- C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\default.ifl
- C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\Desktop.dat
- C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\English.ifl
- C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\languages.dat
- {InstallForgeSetup}
- DirectSound Administrator shared thread array (lock
- cversions.3.m
- \BaseNamedObjects\Local\SM0:7048:304:WilStaging_02
- \BaseNamedObjects\Local\SM0:7048:120:WilError_03
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 5f5cd5c3f88a17190a22…164b37Never scannednever seen before
- caedc30ce16ca036b86d…3fd3d5Never scannednever seen before
- 9624fc5fec690c911467…e4ceb6Never scannednever seen before
- 20f6d12eac29bd6ddc6a…4c253fNever scannednever seen before
- 59c8b5ae2d98acae9fdd…06727bNever scannednever seen before
- d97e289fe7fbde1a3a52…f2b7f1Never scannednever seen before
- 38f778cbb7aa3d52f7fd…459ca5Never scannednever seen before
- ab0f734c1d96451e8c88…92da62Never scannednever seen before
- 4475efd7ef35f11d17a3…aeee14Never scannednever seen before
- 68a81865084c6e011fb6…e4b348Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 33 / 74engines flagged
- 749sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
33 of 74 antivirus engines flagged the file, including alibabacloud and ALYac.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 749 sources.
ProvenanceDerivedSourceSubmission historyObserved at - 03
The hash has been submitted 846 times from 749 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: BFTSetup_V1.7.rar — 979e3056db81304954455f664087671c11ce988841c5fe140deea4d759fcbbc0
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\BFTSetup1.7.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\Explorer.EXE
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: setupConfiguration.archive — C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\setupConfiguration.archive
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: SC.dat — C:\Users\<USER>\AppData\Local\Temp\IF{15D556CA-ADB1-485A-A758-0E41883EAB47}\SC.dat
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: nexusrules.officeapps.live.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: generic-trojan
Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.
Signatures and behavior heuristics
Behavioral heuristics matched patterns associated with malware. Corroborating evidence determines how much weight they carry.
33 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- BFTSetup_V1.7.rar
- Format
- RAR
- Code signing
- Not applicable to this file type
- Size
- 31.5 MB
- Last analyzed
- Sep 28, 2026, 2:19 PM UTC
979e3056db81304954455f664087671c11ce988841c5fe140deea4d759fcbbc0Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't open or extract this archive. Delete this archive from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already opened or extracted it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the original trusted source and verify its exact hash when possible.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is BFTSetup_V1.7.rar a virus?
What is BFTSetup_V1.7.rar?
How many antivirus engines detected BFTSetup_V1.7.rar?
What should I do if I already opened or extracted BFTSetup_V1.7.rar?
How do I remove BFTSetup_V1.7.rar?
What kind of malware is BFTSetup_V1.7.rar?
What is the SHA-256 hash of BFTSetup_V1.7.rar?
How up to date is this analysis of BFTSetup_V1.7.rar?
Community
Member reviews and reports for this exact file hash.