File verdict·Decided by the MT AI Engine
Our call

Safe

Ryujinx emulator archive; zero tier-1 detections; heuristic triggers on benign DLL loading and DNS resolver contact.

Trust score88High trust
MT AI confidence · 92%
ryujinx-canary-1.3.308-win_x64.zip
34.8 MB
aedbc0cff468c69d9d83cb70f83c
Antivirus engines
0 of 75 flagged
Code signing
Unsigned
Age
First seen 10 days ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

92%Confidence
Very high
Reasoning

The file is a legitimate, widely-distributed emulator archive with zero malicious detections from high-trust engines. The triggered heuristics (T1055 process injection, direct-IP C2) fired on benign patterns: DLL loading is normal for multimedia-heavy software, and the contacted IP is a public DNS service. The 536 unique submitters and 'common_new' prevalence classification confirm this is a known, legitimate release. Dropped children are all safe or unknown, with no malicious verdicts. The absence of any tier-1 consensus on malware, combined with the file's legitimate identity and benign runtime behaviour, strongly indicates false-positive heuristic triggers.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. tier1Malicious=0; 17 tier-1 engines (Kaspersky, BitDefender, ESET-NOD32, Avira, Fortinet, F-Secure, Emsisoft, Ikarus, GData, DrWeb, Avast, AVG) all silent

  2. Ryujinx is a legitimate open-source Nintendo Switch emulator; filename matches official release pattern (ryujinx-canary-1.3.308-win_x64.zip)

  3. Prevalence: 536 unique submitters, 580 submissions, classified 'common_new' — consistent with widely-distributed legitimate software

  4. Contacted IP 162.159.36.2 is Cloudflare public DNS (1.1.1.1 range), not a malicious C2; process injection is rundll32.exe loading multimedia DLLs (OpenAL32.dll, SDL3.dll), standard emulator behaviour

  5. Dropped children: 4/4 cached verdicts 'safe' (scores 88-92); no malicious children; no malicious sandbox verdict; no persistence indicators

Points in its favour
  • Zero tier-1 malicious detections; 17 high-trust engines silent
  • Legitimate open-source software (Ryujinx emulator) with established GitHub presence
  • Common prevalence (536 submitters, 580 submissions) — widely distributed and known
  • All cached dropped children verdicted safe (scores 88–92)
  • No malicious sandbox verdict, no malicious contacted hosts, no persistence indicators
What to do

This file is safe. The heuristic alerts are false positives on benign emulator code. You may download and use Ryujinx from its official GitHub repository without concern.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
14

Adversary techniques mapped to the MITRE ATT&CK framework.

T1033T1055T1056T1057T1059T1071T1074T1082T1105T1106T1129T1497T1562.001T1574
Spawned processes
15
$(unnamed)
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\publish/OpenAL32.dll",#1
$(unnamed)
"C:\Users\<USER>\AppData\Local\Temp\publish/Ryujinx.exe"
$(unnamed)
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\publish/SDL3.dll",#1
$(unnamed)
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\publish/av_libglesv2.dll",#1
$(unnamed)
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\publish/avcodec-60.dll",#1
$(unnamed)
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\publish/avutil-58.dll",#1
$(unnamed)
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\publish/glfw3.dll",#1
$(unnamed)
C:\Windows\system32\WerFault.exe -u -p 3824 -s 500
+7 more processes captured.
Network activity
1
IP addresses1
  • 162.159.36.2
Filesystem & mutexes
32
Files written15
  • C:\ProgramData\Microsoft\Windows\WER\Temp
  • C:\ProgramData\Microsoft\Windows\WER\Temp\7141e594-59aa-4d3d-a600-b8ab3e9c8c29
  • C:\ProgramData\Microsoft\Windows\WER\ReportQueue
  • C:\ProgramData\Microsoft\Windows\WER\Temp\3a5fd360-9316-46fe-b681-c9825c03e629
  • C:\ProgramData\Microsoft\Windows\WER\ReportArchive
+10 more
Files deleted12
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER3812.tmp
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER462D.tmp
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER4A25.tmp
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER3812.tmp.dmp
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER462D.tmp.WERInternalMetadata.xml
+7 more
Mutexes created5
  • Local\WERReportingForProcess3824
  • Global\AmiProviderMutex_InventoryApplicationFile
  • Global\0c82ddb6-840b-4189-bcc2-7f5be7d3c852
  • Local\WERReportingForProcess2936
  • Global\638779d0-860e-4a29-8516-d6eaa49fc82b
Dropped payload

Files this sample writes at runtime

This file drops 10 children at runtime. None are currently flagged malicious in our cache.

4 clean6 unseen
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

2 synthesis
MITRE ATT&CK profile
Defense evasion× 1C2× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    "C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\publish/OpenAL32.dll",#1
  • DirectIpC2medium

    Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    162.159.36.2
Antivirus engine breakdown

0 detections across 75 engines

0 malicious0 suspicious75 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust20 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 75 engines report this file as clean.
Hash aedbc0cff468… cross-referenced against 75 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.

Common & new
Unique uploaders
536
Hundreds of people have uploaded this — common.
Total submissions
580
Includes repeat uploads by the same source.
First seen by VT
10d ago
May 31, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
5/31/2026, 6:48:32 AM
First seen (MalwareBazaar)
Last analysis (VT)
6/10/2026, 10:03:16 AM
Scanned here
6/10/2026, 10:11:31 AM
File name
ryujinx-canary-1.3.308-win_x64.zip
Size
34.78 MB
MIME type
(unknown)
Detected type
ZIP
SHA-256
aedbc0cff468c69d9d27251c5dc8d146111700dcaa1196b96cc91c83cb70f83c
MD5
0296c6d667cb1c7d45c98d61d67b5007
SHA-1
499892259c80bc3a3314c1a67d977cfd66fc326d
First seen (VT)
5/31/2026, 6:48:32 AM
Last analysis (VT)
6/10/2026, 10:03:16 AM
First scan (MalwareTips)
6/10/2026, 10:11:31 AM
Last scan (MalwareTips)
6/10/2026, 10:11:31 AM
Behavior tags
detect-debug-environmentlong-sleepscontains-pezipchecks-user-input
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Scanned by
viruscheck
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.