Is 42.zip safe?
Classic 42.zip zip-bomb archive flagged by three tier-1 engines and researcher-curated CIRCL entry.
Three tier-1 engines label the file as a zip bomb, and external intelligence confirms it matches the well-known 42.zip sample. Sandbox analysis did not produce a malicious verdict, but the file's age, prevalence, and consistent naming across sources support the malicious classification.
bbd05de19aa2af1455…817fe24b2c36faRecommended next actions
Before opening or extracting
Do not open or extract it. Delete this archive from the device, then empty the Recycle Bin or Trash.
If you already opened or extracted it
Close it. If it opened links, requested credentials, or triggered unexpected behavior, disconnect from the internet and run a full device scan.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Three tier-1 engines label the file as a zip bomb, and external intelligence confirms it matches the well-known 42.zip sample. Sandbox analysis did not produce a malicious verdict, but the file's age, prevalence, and consistent naming across sources support the malicious classification.
The file is a 42 KB ZIP archive first submitted in 2012 and widely recognized as the classic 42.zip zip bomb. Three tier-3 engines (Fortinet, GData, Symantec) explicitly flag it with zip-bomb or arch-bomb labels, and the CIRCL database links the hash to a known zip-bomb collection. While the single sandbox run returned no malicious verdict and contacted-host reputation data is unavailable, the combination of tier-1 detections, researcher-curated intelligence, and long-term prevalence outweighs the dissenting signals.
What We Detected
Three tier-3 engines (Fortinet, GData, Symantec) and three additional engines flag the archive as a zip bomb or arch bomb. External intelligence from CIRCL confirms the hash matches the well-known 42.zip sample stored in a zip-bomb repository.
Threat Behavior
Zip bombs are crafted archives that expand to enormous sizes when decompressed, potentially exhausting disk space or memory. The file triggered one offensive MITRE technique (T1543.002) in sandbox analysis, but the sandbox itself did not classify the sample as malicious. No malicious child files were dropped.
What To Do Now
Do not attempt to extract or open the archive. Keep endpoint protection enabled and delete the file if it is not required for controlled testing.
Where this verdict could be wrong2 caveats
- behaviour.hasMaliciousSandboxVerdict=false and droppedChildren.hasMaliciousChild=false — sandbox did not classify the sample as malicious.
- contactedHosts=null — host-reputation cross-check was not completed, so no complete malicious-host result is available.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Sandbox returned no malicious verdict
- No malicious child files detected
- Three tier-1 engines flag the file as a zip bomb
- CIRCL database links the hash to a known zip-bomb collection
- Direct-IP contact observed without domain resolution
Treat the file as malicious and avoid extraction; delete it unless it is intentionally retained for isolated, controlled testing.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete6 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 runtime contact was observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 4MITRE ATT&CK techniques
- 10spawned processes
- 1network contacts
- 18filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Created or modified a system service, which can keep code running.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Note: Collects details about your system.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
42.zip
bbd05de19aa2af1455c0494639215898a15286d9b05073b6c4817fe24b2c36fa
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE" "C:\Users\<USER>\Desktop\moving_structure.doc" /q
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files\Java\jre1.8.0_441\bin\java.exe" -jar "C:\Users\user\Desktop\download.jar""
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
{56EC85A0-CC4B-48DC-ADB0-ED344B1829BE} - OProcSessId.dat
C:\Users\<USER>\AppData\Local\Temp\{56EC85A0-CC4B-48DC-ADB0-ED344B1829BE} - OProcSessId.dat
04Isolated runtime analysis - Written fileObserved
Normal.dotm
C:\Users\<USER>\AppData\Roaming\Microsoft\Templates\Normal.dotm
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
162.159.36.2
Contact observed during runtime.
06Isolated runtime analysis
6 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Users\<USER>\AppData\Local\Temp\{56EC85A0-CC4B-48DC-ADB0-ED344B1829BE} - OProcSessId.dat
- C:\Users\<USER>\AppData\Roaming\Microsoft\Templates\Normal.dotm
- C:\Users\<USER>\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
- C:\Users\<USER>\Desktop\moving_structure.doc
- C:\Users\<USER>\Desktop\~$ving_structure.doc
- C:\Users\<USER>\Desktop\~$ving_structure.doc
- C:\Users\<USER>\AppData\Local\Microsoft\Schemas\MS Word_restart.xml
- Local\10MU_ACBPIDS_S-1-5-5-0-169026
- Local\10MU_ACB10_S-1-5-5-0-169026
- Global\552FFA80-3393-423d-8671-7BA046BB5906
- Local\F99C425F-9135-43ed-BD7D-396DE488DC53_Office16
- Local\ZonesCacheCounterMutex
Files this sample writes at runtime
This file drops 2 children at runtime. None are currently flagged malicious in our cache.
- 678a8ad90d7831b4b026…f1eca8Never scannednever seen before
- a6bb4911e3e6b2a22f7d…c5cde3Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 6 / 75engines flagged
- 3,470sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
6 of 75 antivirus engines flagged the file, including Fortinet and GData.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash appears in a known-software reference database.
ProvenanceObservedSourceReference software databaseObserved at - 03
The hash has a long, established submission history across 3,470 sources.
ProvenanceDerivedSourceSubmission historyObserved at - 04
Scanned file: 42.zip — bbd05de19aa2af1455c0494639215898a15286d9b05073b6c4817fe24b2c36fa
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE" "C:\Users\<USER>\Desktop\moving_structure.doc" /q
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files\Java\jre1.8.0_441\bin\java.exe" -jar "C:\Users\user\Desktop\download.jar""
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: {56EC85A0-CC4B-48DC-ADB0-ED344B1829BE} - OProcSessId.dat — C:\Users\<USER>\AppData\Local\Temp\{56EC85A0-CC4B-48DC-ADB0-ED344B1829BE} - OProcSessId.dat
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: Normal.dotm — C:\Users\<USER>\AppData\Roaming\Microsoft\Templates\Normal.dotm
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 162.159.36.2 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: generic-trojan
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
Low-severity pattern matches — worth noting but not on their own cause for alarm.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence162.159.36.2
6 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- 42.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 41.8 KB
- Last analyzed
- Aug 31, 2026, 3:35 AM UTC
bbd05de19aa2af1455c0494639215898a15286d9b05073b6c4817fe24b2c36faSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't open or extract this archive. Delete this archive from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already opened or extracted it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the original trusted source and verify its exact hash when possible.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is 42.zip malware?
What is 42.zip?
How many antivirus engines detected 42.zip?
I already downloaded and opened or extracted 42.zip — what should I do?
How do I remove 42.zip?
What kind of malware is 42.zip?
What is the SHA-256 hash of 42.zip?
How up to date is this analysis of 42.zip?
Community
Member reviews and reports for this exact file hash.