Is papasscooperia_v102.swf safe?
No antivirus engine detected the longstanding Flash file, and its completed sandbox run found no offensive behavior or malware-associated child file.
All 75 antivirus engines were free of detections, including 17 tier-1 engines, and the file has circulated broadly since 2020. One sandbox run produced no malicious verdict or offensive technique, although direct-IP traffic lacked a completed host-reputation check.
ca7ae36d1e1b5ca92b…594f51694b49d2Recommended next actions
Before opening
Open it only when its sender or download source is one you independently trust.
If you already opened it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 75 antivirus engines were free of detections, including 17 tier-1 engines, and the file has circulated broadly since 2020. One sandbox run produced no malicious verdict or offensive technique, although direct-IP traffic lacked a completed host-reputation check.
The sample received no malicious or suspicious detections from 75 antivirus engines, with all 17 reporting tier-1 engines silent. Its history spans more than six years and includes 164 distinct submitters, which weighs strongly against a newly distributed threat. One completed sandbox run recorded no offensive techniques, no malicious sandbox verdict, and no persistence indicators. Ten child hashes were inspected without identifying a malicious child, though their individual classifications remain unknown. The only material caution is low-severity direct-IP traffic to 150.171.22.17, whose reputation was not completely checked.
What We Detected
No malicious or suspicious detections appeared among 75 antivirus engines. The file has been observed since 2020 across 164 distinct sources and 188 submissions, indicating longstanding, broad circulation.
Threat Behavior
One completed sandbox run recorded no offensive techniques, malicious sandbox verdict, persistence indicators, or identified malicious child. It did contact 150.171.22.17 directly, but no complete reputation result is available for that address because the host cross-check was not saved.
What To Do Now
The evidence supports ordinary use if the file came from an expected source. Because Flash is obsolete and historically vulnerable, open it only in a maintained, isolated player or emulator while keeping endpoint protection enabled.
Where this verdict could be wrong2 caveats
- triggeredHeuristics[0] recorded direct-IP traffic to 150.171.22.17, and contactedHosts=null leaves that host without a complete reputation cross-check.
- droppedChildren.rollup.unknown=10 means none of the 10 inspected child hashes received a confirmed benign classification.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 antivirus engines reported a detection.
- 17 tier-1 engines reported no detection.
- Observed since 2020 across 164 unique sources and 188 submissions.
- One sandbox run produced no malicious verdict and no offensive techniques.
- No malicious child was identified among 10 inspected hashes.
- Direct-IP contact to 150.171.22.17 had no complete host-reputation cross-check.
- All 10 inspected child hashes retained unknown individual verdicts.
- Flash is obsolete and should not be opened through legacy browser components.
Use only if its origin is expected, and avoid legacy browser-based Flash execution. Keep endpoint protection enabled and prefer an isolated, maintained Flash emulator.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 runtime contact was observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 9MITRE ATT&CK techniques
- 14spawned processes
- 1network contacts
- 40filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
papasscooperia_v102.swf
ca7ae36d1e1b5ca92b655f1ba415fb9bff5fa609a57c2482a5594f51694b49d2
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
C:\Windows\System32\cmd.exe /c start iexplore.exe "C:\Users\user\Desktop\14 Papas Scooperia.swf
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Microsoft
C:\Users\user\AppData\Local\Microsoft
04Isolated runtime analysis - Written fileObserved
Internet Explorer
C:\Users\user\AppData\Local\Microsoft\Internet Explorer
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
150.171.22.17
Contact observed during runtime.
06Isolated runtime analysis
6 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 150.171.22.17
- C:\Users\user\AppData\Local\Microsoft
- C:\Users\user\AppData\Local\Microsoft\Internet Explorer
- C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery
- C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High
- C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active
- C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Autofill\4.0.1.15
- C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Autofill\4.0.1.15\autofill_bypass_cache_forms.json
- C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Autofill\4.0.1.15\edge_autofill_global_block_list.json
- C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Autofill\4.0.1.15\manifest.fingerprint
- C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Autofill\4.0.1.15\manifest.json
- \Sessions\1\BaseNamedObjects\Global\SyncRootManager
- \Sessions\1\BaseNamedObjects\Local\!BrowserEmulation!SharedMemory!Mutex
- \Sessions\1\BaseNamedObjects\Local\VERMGMTBlockListFileMutex
- \Sessions\1\BaseNamedObjects\SmartScreen_AppRepSettings_Mutex
- \Sessions\1\BaseNamedObjects\SmartScreen_ClientId_Mutex
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- e9a0d5fcfb96a982e10a…88444bNever scannednever seen before
- 05edd978094c3bfa437e…fad0ddNever scannednever seen before
- 7446d9936c87e024a79b…7501f5Never scannednever seen before
- 3b4a703ac7371b8a4d79…ab3f42Never scannednever seen before
- d3d0c39dc413af266024…76727aNever scannednever seen before
- 8f2cc9c1af2303901606…a31181Never scannednever seen before
- 933a52fde8ae0f396991…00a6acNever scannednever seen before
- 610a16c57c77de32c49b…bc4f12Never scannednever seen before
- d4a3aa71b4b1987239f0…d8c074Never scannednever seen before
- 60ca10af906198a6a299…9d3080Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 0 / 75engines flagged
- 164sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 164 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
The hash has been submitted 188 times from 164 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: papasscooperia_v102.swf — ca7ae36d1e1b5ca92b655f1ba415fb9bff5fa609a57c2482a5594f51694b49d2
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — C:\Windows\System32\cmd.exe /c start iexplore.exe "C:\Users\user\Desktop\14 Papas Scooperia.swf
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Microsoft — C:\Users\user\AppData\Local\Microsoft
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: Internet Explorer — C:\Users\user\AppData\Local\Microsoft\Internet Explorer
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 150.171.22.17 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Low-severity pattern matches — worth noting but not on their own cause for alarm.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence150.171.22.17
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- papasscooperia_v102.swf
- Format
- Flash
- Code signing
- Not applicable to this file type
- Size
- 19.8 MB
- Last analyzed
- Sep 15, 2026, 5:39 PM UTC
ca7ae36d1e1b5ca92b655f1ba415fb9bff5fa609a57c2482a5594f51694b49d2Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open it only when its sender or download source is one you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is papasscooperia_v102.swf safe?
What is papasscooperia_v102.swf?
How many antivirus engines detected papasscooperia_v102.swf?
What is the SHA-256 hash of papasscooperia_v102.swf?
Is it safe to open papasscooperia_v102.swf?
How up to date is this analysis of papasscooperia_v102.swf?
Community
Member reviews and reports for this exact file hash.