Is 554cbccc.zip safe?
No antivirus engine detected the archive, but Run-key persistence, possible process injection, and reported LSASS access justify caution pending source verification.
All 76 antivirus engines returned no detection, including 18 tier-1 engines, and the completed sandbox did not issue a malware finding. However, the runtime record includes Run-key persistence, possible T1055 process injection, and reported LSASS access; these may be driver-related false positives, but they warrant caution.
bc69a41d91be595c64…b4f9b616110277Recommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 76 antivirus engines returned no detection, including 18 tier-1 engines, and the completed sandbox did not issue a malware finding. However, the runtime record includes Run-key persistence, possible T1055 process injection, and reported LSASS access; these may be driver-related false positives, but they warrant caution.
The archive has a strong static scanning result: 0 of 76 engines detected it, including all 18 reporting tier-1 engines. One completed sandbox did not issue a malware finding, and none of the 10 inspected dropped files was identified as malicious, although their individual verdicts remain unknown. The main concern is behavioural evidence mapping activity to T1055, T1486, T1562.001, and a Run-key persistence entry. A heuristic also reports interaction with LSASS, but that claim is not corroborated by engine detections, a malicious sandbox conclusion, or external intelligence. Some of these mappings could arise from low-level gaming mouse software using hooks, services, and automatic startup. No complete contacted-host reputation check is available, although the recorded run lists no network contacts.
What We Detected
The archive received 0 detections from 76 antivirus engines, including no detections from 18 tier-1 engines. MalwareBazaar, CIRCL, and YARAify also returned no matching intelligence, and the sample has been known since November 2020.
Threat Behavior
One completed sandbox run installed files under the REDRAGON PHOENIX Gaming Mouse directory and created a Run-key entry for automatic startup. The runtime record maps activity to six offensive techniques, including T1055 process injection, T1486 data encryption for impact, and T1562.001 impairment of defenses. A heuristic further reports activity involving LSASS. These are concerning indicators, but the sandbox itself did not issue a malware finding, and peripheral software can trigger broad behavioural mappings through hooks, services, and configuration utilities.
What To Do Now
Only use this archive if its hash matches a download obtained directly from the hardware vendor's official support channel. Keep endpoint protection enabled, inspect the extracted executables individually, and avoid running it if the source cannot be verified.
Where this verdict could be wrong3 caveats
- The strong 0/76 detection result, including no flags from 18 tier-1 engines, argues against known malware.
- The sole completed sandbox labeled the run clean, so the offensive MITRE mappings may overstate legitimate gaming-device driver and configuration activity.
- No MalwareBazaar, CIRCL, or YARAify match was found, though absence of an intelligence hit does not prove benignness.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0 of 76 antivirus engines detected the archive.
- All 18 reporting tier-1 engines returned no detection.
- behaviour.hasMaliciousSandboxVerdict=false.
- droppedChildren.hasMaliciousChild=false.
- No MalwareBazaar, CIRCL, or YARAify hit was found.
- Runtime evidence maps possible process injection to T1055.
- A Run-key entry establishes automatic startup persistence.
- A heuristic reports process activity involving LSASS.
- Six offensive MITRE techniques were recorded in one sandbox run.
- All 10 dropped-child verdicts remain unknown.
- No complete contacted-host reputation result is available.
Verify the SHA-256 against the hardware vendor's official download before use and scan the extracted executables separately. Keep endpoint protection enabled and do not run the package if its origin is uncertain.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 76 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete4 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 25MITRE ATT&CK techniques
- 15spawned processes
- 0network contacts
- 33filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Used removable-media replication behaviour that can spread files between devices.
High concern: Encrypted files or data, behaviour commonly associated with ransomware.
High concern: Changed an auto-start location that can make code run after sign-in or restart.
High concern: Attempted to impair or bypass security controls.
High concern: Manipulated how the operating system loads code, which can redirect execution.
Moderate concern: Runs hidden system commands (script or shell).
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
554cbccc.zip
bc69a41d91be595c640f8724833d2839b73e76b0abe5143375b4f9b616110277
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\Phoenix_2_2018.01.10/setup.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\is-QMH2R.tmp\setup.tmp" /SL5="$40038,4181044,421888,C:\Users\<USER>\AppData\Local\Temp\Phoenix_2_2018.01.10\setup.exe"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
setup.tmp
C:\Users\<USER>\AppData\Local\Temp\is-QMH2R.tmp\setup.tmp
04Isolated runtime analysis - Written fileObserved
_setup64.tmp
C:\Users\<USER>\AppData\Local\Temp\is-46SRC.tmp\_isetup\_setup64.tmp
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\REDRAGON PHOENIX Gaming Mouse
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000\RegFiles0000
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000\RegFilesHash
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\REDRAGON PHOENIX Gaming Mouse
- HKEY_CURRENT_USER\Control Panel\Desktop\LowLevelHooksTimeout
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4B6A2850-CCB8-4568-B8AB-D8347CC8949C}}_is1\Inno Setup: Setup Version
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4B6A2850-CCB8-4568-B8AB-D8347CC8949C}}_is1\Inno Setup: App Path
- C:\Users\<USER>\AppData\Local\Temp\is-QMH2R.tmp\setup.tmp
- C:\Users\<USER>\AppData\Local\Temp\is-46SRC.tmp\_isetup\_setup64.tmp
- C:\Program Files (x86)\REDRAGON PHOENIX Gaming Mouse\CheckPidVid.dll
- C:\Program Files (x86)\REDRAGON PHOENIX Gaming Mouse\keydll3.dll
- C:\Program Files (x86)\REDRAGON PHOENIX Gaming Mouse\hid.exe
- C:\Windows\is-96DIB.tmp
- C:\Program Files (x86)\REDRAGON PHOENIX Gaming Mouse\images\is-IDAJF.tmp
- C:\Program Files (x86)\REDRAGON PHOENIX Gaming Mouse\images\is-DKJ0B.tmp
- C:\Program Files (x86)\REDRAGON PHOENIX Gaming Mouse\images\is-9VP4V.tmp
- C:\Program Files (x86)\REDRAGON PHOENIX Gaming Mouse\images\0409\background\is-16CH8.tmp
- cversions.3.m
- PHOENIX_GamingMouse_HID_Mutex
- PHOENIX_GAMING_MOUSE_CONFIG_MUTEX
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 3e76838d9930794f0fe6…0d253aNever scannednever seen before
- 009ac508b305684e1b9c…6b214dNever scannednever seen before
- 77f91b0cdd46e60877cd…9b6f85Never scannednever seen before
- a3363fefd6cf1a232418…ad95f5Never scannednever seen before
- 9dd356e2f90694918f5a…0d6647Never scannednever seen before
- ea77737831df22b7f6c7…b11254Never scannednever seen before
- 245632a421e5ebb6d054…0dd107Never scannednever seen before
- c6ba41d8cdff5eddcb73…9d4795Never scannednever seen before
- 22b8d7d5cf899efefc58…6b9906Never scannednever seen before
- 454f7b7712433fd755c4…a6a277Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 4rule hits recorded
- 0 / 76engines flagged
- 13sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
2 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
0 of 76 antivirus engines flagged the file.
ProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 14 times from 13 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: 554cbccc.zip — bc69a41d91be595c640f8724833d2839b73e76b0abe5143375b4f9b616110277
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\Phoenix_2_2018.01.10/setup.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Users\<USER>\AppData\Local\Temp\is-QMH2R.tmp\setup.tmp" /SL5="$40038,4181044,421888,C:\Users\<USER>\AppData\Local\Temp\Phoenix_2_2018.01.10\setup.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: setup.tmp — C:\Users\<USER>\AppData\Local\Temp\is-QMH2R.tmp\setup.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: _setup64.tmp — C:\Users\<USER>\AppData\Local\Temp\is-46SRC.tmp\_isetup\_setup64.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
Sandbox flagged persistence indicators (registry Run keys / services / scheduled tasks).
EvidenceHKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\REDRAGON PHOENIX Gaming MouseUnsigned sample writes to AppData/Temp/ProgramData AND creates a Run key. Textbook user-mode persistence — legit installers sign their binaries.
EvidenceC:\Users\<USER>\AppData\Local\Temp\is-QMH2R.tmp\setup.tmp → HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\REDRAGON PHOENIX Gaming MouseThe saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\Explorer.EXESandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exe
0 of 76 engines flagged this file
View all 76 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- 554cbccc.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 4.1 MB
- Last analyzed
- Sep 29, 2026, 1:02 AM UTC
bc69a41d91be595c640f8724833d2839b73e76b0abe5143375b4f9b616110277Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or extract it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is 554cbccc.zip safe, or is it malware?
What is 554cbccc.zip?
How many antivirus engines detected 554cbccc.zip?
What should I do if I already opened or extracted 554cbccc.zip?
How do I remove 554cbccc.zip?
What is the SHA-256 hash of 554cbccc.zip?
How up to date is this analysis of 554cbccc.zip?
Community
Member reviews and reports for this exact file hash.