Is Karlson.zip safe?
No antivirus engine detected a threat, and the long-established Unity game archive produced no malicious sandbox verdict or confirmed malicious child.
The archive drew no detections from 76 antivirus engines, including 17 tier-1 engines, despite being widely submitted since 2020. One sandbox observed Unity-related execution without a malicious verdict or network contacts, though an anti-defense technique and unclassified extracted files warrant ordinary source verification.
c6cb79c2f6291a78ba…c59e84a16ed61bRecommended next actions
Before opening or extracting
Open or extract it only when its sender or download source has been independently verified.
If you already opened or extracted it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The archive drew no detections from 76 antivirus engines, including 17 tier-1 engines, despite being widely submitted since 2020. One sandbox observed Unity-related execution without a malicious verdict or network contacts, though an anti-defense technique and unclassified extracted files warrant ordinary source verification.
None of 76 antivirus engines flagged the archive, and all 17 reporting tier-1 engines found no detection. The file has been submitted 1,111 times by 1,005 sources since 2020, making an unnoticed widespread threat unlikely. A completed sandbox run showed Unity game components and issued no malicious verdict, although it mapped one activity to T1562.001. Ten extracted children were inspected without a confirmed malicious result, but their individual verdicts remain unknown. No malware family, malicious intelligence hit, persistence indicator, or observed network contact supports the isolated risk signal.
What We Detected
The archive received 0 detections from 76 antivirus engines, including no detections from 17 tier-1 engines. It has a substantial history—1,111 submissions from 1,005 sources since January 2020—and no named threat family or external intelligence match.
Threat Behavior
One sandbox run executed Karlson.exe with UnityPlayer.dll and other Unity-managed components, wrote game settings and logs under Dani\Karlson, and produced no malicious sandbox verdict or persistence indicator. T1562.001 was mapped as an offensive technique, but no network contacts were observed and no malicious child was confirmed. The ten extracted children remain individually unclassified, and no complete host-reputation result is available.
What To Do Now
Use a copy obtained from the developer's official distribution channel and keep endpoint protection enabled. If the archive came from an unofficial mirror or behaves differently from a Unity game, delete it and obtain a fresh copy.
Where this verdict could be wrong4 caveats
- behaviour.offensiveTechniques includes T1562.001, an indicator associated with impairing defenses, though the single sandbox issued no malicious verdict.
- All 10 droppedChildren entries have verdict=null, so hasMaliciousChild=false does not establish that every extracted component is benign.
- contactedHosts=null means no complete host-reputation cross-check is available, although the sandbox recorded no contacted domains, IPs, or URLs.
- One communityComments entry alleges remote control, but it is uncorroborated by engines, runtime verdicts, or threat intelligence.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/76 antivirus detections.
- 17 tier-1 engines reported no detection.
- 1,111 submissions from 1,005 sources since 2020.
- No malicious sandbox verdict or persistence indicators.
- No malicious child or external intelligence hit was confirmed.
- Sandbox activity included MITRE T1562.001.
- Ten extracted children remain individually unclassified.
- No complete contacted-host reputation cross-check is available.
- A community allegation of remote control is present but uncorroborated.
Use the archive only if it came from the developer's official channel, and keep endpoint protection enabled. An unofficial or modified copy should be replaced with a verified download.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 76 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 9MITRE ATT&CK techniques
- 15spawned processes
- 0network contacts
- 15filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- HKEY_CURRENT_USER\SOFTWARE\Dani\Karlson\UnitySelectMonitor_h17969598
- HKEY_CURRENT_USER\SOFTWARE\Dani\Karlson\Screenmanager Resolution Width_h182942802
- HKEY_CURRENT_USER\SOFTWARE\Dani\Karlson\Screenmanager Resolution Height_h2627697771
- HKEY_CURRENT_USER\SOFTWARE\Dani\Karlson\Screenmanager Fullscreen mode_h3630240806
- HKEY_CURRENT_USER\SOFTWARE\Dani\Karlson\UnityGraphicsQuality_h1669003810
- HKEY_CURRENT_USER\SOFTWARE\Dani\Karlson\Screenmanager Resolution Use Native_h1405027254
- C:\Users\user\AppData\LocalLow\Dani
- C:\Users\user\AppData\LocalLow\Dani\Karlson
- C:\Users\user\AppData\LocalLow\Dani\Karlson\Player.log
- C:\Users\user\AppData\Local\Temp\5k1my12e.l25
- C:\Users\user\AppData\Local\Temp\5k1my12e.l25\Karlson.exe
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 6919d5af506aae0d93e9…4db664Never scannednever seen before
- edc5bcf685d930a607bc…34b7ceNever scannednever seen before
- 3c1a76a5849074b437d2…601dfcNever scannednever seen before
- f1a6416eeedd9d040387…2efb31Never scannednever seen before
- 49c6160f9d54af4270a3…44f9a2Never scannednever seen before
- e2a782db9d2ccf2e560d…fec717Never scannednever seen before
- b220af136b7ca77b63be…a2bf46Never scannednever seen before
- 49af015e2150b098a36d…d7c742Never scannednever seen before
- d6b6c2325ec0bc02ebf6…0949a8Never scannednever seen before
- 277c8c0c339050d03dcc…136740Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 76engines flagged
- 1,005sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 76 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 1,005 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
The hash has been submitted 1,111 times from 1,005 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: Karlson.zip — c6cb79c2f6291a78ba3216adda65cf38d64b271be182f45dfac59e84a16ed61b
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\Karlson.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Users\<USER>\AppData\Local\Temp\UnityCrashHandler64.exe" --attach 2652 1740272898048
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Dani — C:\Users\user\AppData\LocalLow\Dani
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: Karlson — C:\Users\user\AppData\LocalLow\Dani\Karlson
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 76 engines flagged this file
View all 76 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- Karlson.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 42.0 MB
- Last analyzed
- Sep 30, 2026, 4:49 AM UTC
c6cb79c2f6291a78ba3216adda65cf38d64b271be182f45dfac59e84a16ed61bSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open or extract it only when its sender or download source has been independently verified.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Karlson.zip safe?
What is Karlson.zip?
How many antivirus engines detected Karlson.zip?
What is the SHA-256 hash of Karlson.zip?
Is it safe to open or extract Karlson.zip?
How up to date is this analysis of Karlson.zip?
Community
Member reviews and reports for this exact file hash.