File verdict·Decided by the MT AI Engine
Our call

Malicious

14 tier-1 antivirus engines independently flagged this RAR archive as a trojan patcher/keygen tool with strong family consensus.

Agent Tesla
Trust score8Critical
MT AI confidence · 96%
UNLOCKER_MODS.rar
18.3 MB
bd50ae2f1c5b54b6d9e72c1c5422
Antivirus engines
38 of 75 flagged
Code signing
Unsigned
Age
First seen 3y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

96%Confidence
Very high
Reasoning

The evidence overwhelmingly supports a malicious classification. Fourteen tier-1 antivirus engines independently reported trojan detections, with five engines converging on the 'win32' family. The filename 'UNLOCKER_MODS.rar' paired with 'patcher' threat labeling and multiple HackTool detections (alibabacloud, Antiy-AVL, CAT-QuickHeal, Malwarebytes) indicate software-cracking or license-bypass tooling. The file is unsigned and has no legitimate signer history. Prevalence data shows this is a well-known malicious sample (206 unique submitters, 223 submissions since March 2023), not a rare new file. Community researchers independently scored it 8/10 threat severity. The tier-1 consensus is not driven by low-trust heuristics; it reflects established malware signatures from leading security vendors.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. tier1Malicious=14/17 tier-1 engines flagged malicious; tier1FamilyConsensus.strong=true (5 engines agreeing on 'win32' family)

  2. BitDefender, Microsoft, Sophos, Avast, ESET-NOD32, TrendMicro all independently reported trojan/malware detections

  3. Filename 'UNLOCKER_MODS.rar' + 'patcher' threat label + HackTool detections (alibabacloud, Antiy-AVL, CAT-QuickHeal, Malwarebytes) indicate software-cracking tooling

  4. prevalence.classification='common_old' (206 submitters, 223 submissions since 2023-03-28) — established malware circulation, not a rare new sample

  5. Community researcher (jaffacakes118) independently scored 8/10 threat severity and tagged #malware

Points in its favour
  • No adversarial filename injection or hidden unicode detected
  • No brand mismatch — file does not impersonate a legitimate publisher
Points against
  • 14 tier-1 antivirus engines report trojan/malware detections
  • Filename and threat labels indicate software-cracking or keygen tooling
  • File is unsigned with no legitimate signer history
  • Widely circulated malware (206 submitters, 223 submissions since March 2023)
  • Multiple HackTool detections across independent vendors
  • Community researchers independently scored 8/10 threat severity
What to do

Block and quarantine this file immediately. Do not extract or execute the archive. If already downloaded, perform a full system scan and monitor for unauthorized software modifications or system changes.

Threat family attribution

patcher corroborated by 2 sources

  • VT (75 engines)
    patcher
  • MT AI Engine
    Agent Tesla
No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

38 detections across 75 engines

38 malicious0 suspicious37 clean
Tier-117 engines
14flag
Top commercial AVs (low FP rate)
Tier-238 engines
15flag
Mainstream engines with mixed FP rates
Low-trust20 engines
9flag
Heuristic / generic-AI engines (high FP rate)
alibabacloud
malicious
HackTool:Win/Patcher.9157e163
ALYac
malicious
Trojan.GenericKD.63889696
Antiy-AVL
malicious
HackTool/Win32.KeyGen
Arcabit
malicious
Trojan.Generic.D3CEE120 [many]
Avast
malicious
Win32:Malware-gen
AVG
malicious
Win32:Malware-gen
Avira
malicious
TR/W32.Malware
BitDefender
malicious
Trojan.GenericKD.63889696
CAT-QuickHeal
malicious
HackTool.Patcher.A
ClamAV
malicious
Win.Trojan.Agent-179437
CTX
malicious
rar.trojan.patcher
Cynet
malicious
Malicious (score: 99)
DeepInstinct
malicious
MALICIOUS
DrWeb
malicious
Trojan.DownLoader26.20894
Emsisoft
malicious
Trojan.GenericKD.63889696 (B)
ESET-NOD32
malicious
Generik.KOBFQJF trojan
F-Secure
malicious
Trojan.TR/W32.Malware
Fortinet
malicious
PossibleThreat
GData
malicious
Win32.Trojan.PSE.176P27H
Google
malicious
Detected
Lionic
malicious
Trojan.ZIP.Patcher.4!c
Malwarebytes
malicious
Patcher.Trojan.HackTool.DDS
McAfeeD
malicious
ti!BD50AE2F1C5B
Microsoft
malicious
Trojan:Win32/Malgent!rfn
MicroWorld-eScan
malicious
Trojan.GenericKD.63889696
NANO-Antivirus
malicious
Trojan.Win32.Dynara.kfukmk
Rising
malicious
Trojan.Convagent!8.12323 (CLOUD)
Sangfor
malicious
Trojan.Win32.Save.a
SentinelOne
malicious
Static AI - Malicious Archive
Skyhigh
malicious
GenericRXDV-SS!2A13FED0DD59
Sophos
malicious
Mal/Generic-S
TrendMicro
malicious
TROJ_FRS.0NA103JT20
TrendMicro-HouseCall
malicious
Trojan.Win32.VSX.PE04CA3
Varist
malicious
W32/Patcher.G.gen!Eldorado
VBA32
malicious
Malware-Cryptor.MSIL.AgentTesla.Heur
VIPRE
malicious
Trojan.GenericKD.63889696
Webroot
malicious
W32.Malware.gen
Xcitium
malicious
TrojWare.Win32.TrojanDropper.Agent.~OD@7p6s
Hash bd50ae2f1c5b… cross-referenced against 75 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.

Common & old
Unique uploaders
206
Hundreds of people have uploaded this — common.
Total submissions
223
Includes repeat uploads by the same source.
First seen by VT
3y ago
Mar 28, 2023
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
here
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
3/28/2023, 7:23:27 AM
First seen (MalwareBazaar)
Last analysis (VT)
6/15/2026, 9:16:19 AM
Scanned here
6/22/2026, 6:48:26 PM
File name
UNLOCKER_MODS.rar
Size
18.26 MB
MIME type
(unknown)
Detected type
RAR
SHA-256
bd50ae2f1c5b54b6d935a81a02dee0eb3637801683332b3520c628e72c1c5422
MD5
be7343b14fae5a29f161f717cfd12612
SHA-1
40ba8c3b3213999ec19c44dfc715d85e2f7062f1
First seen (VT)
3/28/2023, 7:23:27 AM
Last analysis (VT)
6/15/2026, 9:16:19 AM
First scan (MalwareTips)
6/22/2026, 6:48:26 PM
Last scan (MalwareTips)
6/22/2026, 6:48:26 PM
Community reputation
-9flagged
Behavior tags
rarupx
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.