Is AssetRipper_win_x64.zip safe?
No antivirus engine detected the archive, but one sandbox mapped execution to credential-access, process-injection, and defense-evasion techniques that warrant caution.
All 75 antivirus engines were silent, including 17 tier-1 products, and the completed sandbox did not issue a malware finding. However, that run recorded LSASS-related activity and mappings to process injection, credential access, and defense evasion, so the archive should be verified before use.
9a7ef0e7c5c3ea5b90…194c6a7b01baf7Recommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 75 antivirus engines were silent, including 17 tier-1 products, and the completed sandbox did not issue a malware finding. However, that run recorded LSASS-related activity and mappings to process injection, credential access, and defense evasion, so the archive should be verified before use.
The archive received no malicious or suspicious detections from 75 antivirus engines, which is substantial evidence against a recognized malware payload. One completed sandbox also produced no malware finding, and no malicious child or external intelligence match was reported. Against that, the runtime record includes T1003, T1055, T1555.003, and T1562.001, plus heuristic findings for LSASS access and rundll32 loading a temporary DLL. Those behaviors can be high risk, although the evidence does not establish their exact method or intent. Host-reputation coverage was incomplete because five of seven distinct observed domains and IPs were inspected. The conflicting static and runtime signals justify caution rather than an unequivocal clean assessment.
What We Detected
No malicious or suspicious result was reported by any of 75 antivirus engines, including 17 tier-1 engines. No malware family consensus, external intelligence match, or confirmed malicious child was present.
Threat Behavior
One completed sandbox did not issue a malware finding, but its telemetry mapped activity to credential access, process injection, and defense evasion. Of particular concern are T1003 and T1555.003 credential-access mappings, T1055 process injection, T1562.001 defense impairment, reported LSASS targeting, and rundll32 loading a temporary DLL. These mappings are important warning signs, but a single run does not prove hostile intent or the precise technique used.
What To Do Now
Obtain the archive from the project's official release channel and verify its SHA-256 before opening it. Keep endpoint protection enabled, extract it in a restricted environment, and avoid granting administrator access until the embedded executables have been independently verified.
Where this verdict could be wrong3 caveats
- The complete 0/75 detection result, including 17 tier-1 engines without a detection, weighs strongly against the concerning behavioral mappings.
- The only completed sandbox labeled the execution clean, so the MITRE mappings may reflect instrumentation, crash handling, or library behavior rather than hostile intent.
- All ten extracted children lack individual verdicts, so droppedChildren.hasMaliciousChild=false does not establish that those children were affirmatively cleared.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0 of 75 antivirus engines reported a malicious or suspicious result.
- All 17 tier-1 engines that reported results had no detection.
- The completed sandbox did not issue a malware finding.
- No malicious dropped child or persistence indicator was identified.
- MalwareBazaar and YARAify returned no matching intelligence.
- One sandbox mapped activity to seven offensive MITRE techniques.
- Reported LSASS targeting triggered a credential-dumper heuristic.
- rundll32 loading capstone.dll from a temporary directory triggered a process-injection heuristic.
- Contacted-host reputation coverage included only five of seven distinct observed domains and IPs.
- All ten extracted children remain individually unclassified.
Download only from the official AssetRipper release channel and compare SHA-256 9a7ef0e7c5c3ea5b90b4e6d855e2d98d5f7ec8c3f9e26fccbc194c6a7b01baf7. Keep protection enabled and test the embedded executable without administrative privileges.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial5 of 7 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 15MITRE ATT&CK techniques
- 15spawned processes
- 7network contacts
- 31filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Accessed operating-system credential data, which can expose saved passwords.
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Searched files or settings where passwords and keys may be stored.
High concern: Accessed browser or password-store data that may contain saved logins.
High concern: Attempted to impair or bypass security controls.
High concern: Manipulated how the operating system loads code, which can redirect execution.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
AssetRipper_win_x64.zip
9a7ef0e7c5c3ea5b90b4e6d855e2d98d5f7ec8c3f9e26fccbc194c6a7b01baf7
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\AssetRipper.GUI.Free.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\capstone.dll",#1
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
AssetRipper_20260824_194404.log
C:\Users\<USER>\AppData\Local\Temp\AssetRipper_20260824_194404.log
04Isolated runtime analysis - Written fileObserved
Temp
C:\ProgramData\Microsoft\Windows\WER\Temp
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
api.bing.com
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
api-bing-com.bx-0004.bx-msedge.net
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- api.bing.com
- api-bing-com.bx-0004.bx-msedge.net
- bx-0004.bx-dc-msedge.net
- www.bing.com
- www.msn.com
- 8.8.8.8
- 162.159.36.2
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SlowContextMenuEntries
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix
- Software\Microsoft\Internet Explorer\TabbedBrowsing\NTPDaysSinceLastAutoMigration
- Software\Microsoft\Internet Explorer\TabbedBrowsing\NTPLastLaunchLowDateTime
- Software\Microsoft\Internet Explorer\TabbedBrowsing\NTPLastLaunchHighDateTime
- C:\Users\<USER>\AppData\Local\Temp\AssetRipper_20260824_194404.log
- C:\ProgramData\Microsoft\Windows\WER\Temp
- C:\ProgramData\Microsoft\Windows\WER\Temp\0c088866-1490-4188-827c-9f5384bcaab0
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue
- C:\ProgramData\Microsoft\Windows\WER\Temp\adf78251-4f61-4a0b-abe2-276758fd9cb7
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER2E2F.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER341C.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER3555.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER2E2F.tmp.dmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER341C.tmp.WERInternalMetadata.xml
- Local\WERReportingForProcess2448
- Global\345e5d3a-a021-4dce-9154-ae761953222e
- Local\SessionImmersiveColorMutex
- Global\C::Users:Bruno:AppData:Local:Microsoft:Windows:Explorer:thumbcache_idx.db!rwWriterMutex
- Global\C::Users:Bruno:AppData:Local:Microsoft:Windows:Explorer:thumbcache_16.db!dfMaintainer
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 1d2aaa7eda0713a637dc…f07bb4Never scannednever seen before
- 0c6e533e29f9487cc5e9…c68009Never scannednever seen before
- 928ddd164d42804733bd…0db975Never scannednever seen before
- 58bb4c6a78507d77ea11…499fffNever scannednever seen before
- 04f6e464db50e4c20bf0…4d6535Never scannednever seen before
- f03321188a1615d04431…92dcbbNever scannednever seen before
- 7e8b8ff7b1475e6368aa…648020Never scannednever seen before
- 9193127415d80e2c4f85…66a1c4Never scannednever seen before
- d0eb9572375ceb800589…bd9457Never scannednever seen before
- 2fb6b42d5fb97f557fac…264432Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 2rule hits recorded
- 0 / 75engines flagged
- 258sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
0 of 75 antivirus engines flagged the file.
ProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 270 times from 258 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: AssetRipper_win_x64.zip — 9a7ef0e7c5c3ea5b90b4e6d855e2d98d5f7ec8c3f9e26fccbc194c6a7b01baf7
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\AssetRipper.GUI.Free.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\capstone.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: AssetRipper_20260824_194404.log — C:\Users\<USER>\AppData\Local\Temp\AssetRipper_20260824_194404.log
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: Temp — C:\ProgramData\Microsoft\Windows\WER\Temp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: api.bing.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: api-bing-com.bx-0004.bx-msedge.net — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\capstone.dll",#1Sandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exe
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- AssetRipper_win_x64.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 42.4 MB
- Last analyzed
- Sep 25, 2026, 6:36 PM UTC
9a7ef0e7c5c3ea5b90b4e6d855e2d98d5f7ec8c3f9e26fccbc194c6a7b01baf7Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or extract it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is AssetRipper_win_x64.zip safe, or is it malware?
What is AssetRipper_win_x64.zip?
How many antivirus engines detected AssetRipper_win_x64.zip?
What should I do if I already opened or extracted AssetRipper_win_x64.zip?
How do I remove AssetRipper_win_x64.zip?
What is the SHA-256 hash of AssetRipper_win_x64.zip?
How up to date is this analysis of AssetRipper_win_x64.zip?
Community
Member reviews and reports for this exact file hash.