Is v1.19.923.zip safe?
Five of 75 engines flagged this newly observed ZIP, with ESET-NOD32 and Varist naming WinGo, but runtime and independent intelligence corroboration are unavailable.
The archive warrants caution because 5 of 75 engines detected it, including ESET-NOD32 identifying WinGo/Kryptik and Varist independently naming WinGo. However, only one tier-1 engine flagged it, and there is no completed runtime analysis or independent intelligence hit to confirm the threat.
c356eaa3db04b7b4fe…73f9ce297c3edaRecommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The archive warrants caution because 5 of 75 engines detected it, including ESET-NOD32 identifying WinGo/Kryptik and Varist independently naming WinGo. However, only one tier-1 engine flagged it, and there is no completed runtime analysis or independent intelligence hit to confirm the threat.
Five of 75 engines flagged the archive, and two detections specifically converge on the WinGo name. ESET-NOD32 supplies the only tier-1 detection, so the evidence falls short of strong tier-1 family consensus. The file is newly observed with only one submission, leaving little reputation history to reduce uncertainty. No completed runtime observation is available, and contacted-host reputation was not checked or saved. Research intelligence produced no matches, while file-type-only historical comparisons are too broad to carry substantial weight.
What We Detected
Five of 75 antivirus engines flagged the ZIP archive. ESET-NOD32 identified WinGo/Kryptik.UZ, while Varist reported a WinGo generic variant; DeepInstinct, Google, and Bkav supplied broader detections.
Threat Behavior
No completed sandbox run is available, so execution behavior, persistence, payload extraction, and network activity were not observed. A complete contacted-host reputation result is also unavailable. The archive is newly observed and has only one recorded submission, which increases uncertainty.
What To Do Now
Do not open or extract the archive on a production system. Keep endpoint protection enabled, obtain the file from a verified official source if it is expected, and use an isolated analysis environment if further inspection is necessary.
Where this verdict could be wrong3 caveats
- Only 5/75 engines detected the archive, while 15 tier-1 engines reported no detection and tier1Malicious=1.
- externalIntel.yaraify.ruleCount=0, externalIntel.circl.hit=false, and externalIntel.malwareBazaar.hit=false provide no independent corroboration, though coverage gaps remain possible.
- The two similarHashes entries are matchKind=filetype only, so their suspicious and malicious outcomes do not establish a close relationship to this archive.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 15 tier-1 engines reported no detection
- engines.tier1FamilyConsensus.strong=false
- externalIntel.yaraify.ruleCount=0
- externalIntel.circl.hit=false
- externalIntel.malwareBazaar.hit=false
- 5/75 antivirus-engine detections
- ESET-NOD32 tier-1 WinGo/Kryptik detection
- Varist independently names WinGo
- Only one recorded submitter and submission
- No completed runtime analysis
- No complete contacted-host reputation result
Quarantine the archive and avoid extracting or running its contents until its source and contents are independently verified. Keep antivirus and endpoint protection enabled throughout any further analysis.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete5 of 75 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 5 / 75engines flagged
- 1sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
5 of 75 antivirus engines flagged the file, including Bkav and DeepInstinct.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 1 time from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at
Detection sources at a glance
Category: generic-trojan
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
5 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. 5 antivirus detections make that low prevalence materially relevant, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- v1.19.923.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 84.2 MB
- Last analyzed
- Sep 12, 2026, 10:31 AM UTC
c356eaa3db04b7b4fe89bfd62ee88994e58313f9b7b9794b4c73f9ce297c3edaSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or extract it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is v1.19.923.zip safe, or is it malware?
What is v1.19.923.zip?
How many antivirus engines detected v1.19.923.zip?
What should I do if I already opened or extracted v1.19.923.zip?
How do I remove v1.19.923.zip?
What kind of malware is v1.19.923.zip?
What is the SHA-256 hash of v1.19.923.zip?
How up to date is this analysis of v1.19.923.zip?
Community
Member reviews and reports for this exact file hash.