Is S&R-P 1.0.0.mrpack safe?
No antivirus engine detected the archive, but one sandbox mapped activity to process injection and LSASS access, warranting caution until independently verified.
All 74 antivirus engines were silent, including 17 high-trust engines, and no curated intelligence source identified a malware family. However, one sandbox associated execution with process injection and LSASS-related activity, while the archive is newly observed and its ten extracted components remain unclassified.
cb567a4826eb5985f8…cecb751a6034fdRecommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 74 antivirus engines were silent, including 17 high-trust engines, and no curated intelligence source identified a malware family. However, one sandbox associated execution with process injection and LSASS-related activity, while the archive is newly observed and its ten extracted components remain unclassified.
Static scanning produced no detections across 74 engines, which strongly reduces the likelihood of recognized malware. One completed sandbox run nevertheless mapped activity to T1055 and T1543.002, and a heuristic associated process evidence with LSASS. Those mappings are concerning, but the saved evidence does not prove that injection or credential-memory access actually occurred, and the sandbox issued no malicious verdict. Ten extracted files were inspected without a malicious result, although every child remains unclassified rather than confirmed benign. The archive also has only one submission and no established history, while no complete host-reputation result is available. These mixed signals support cautious handling pending source verification or deeper component analysis.
What We Detected
The archive received 0 detections from 74 antivirus engines, including no detections from 17 high-trust engines. CIRCL, MalwareBazaar, and YARAify supplied no matching malicious intelligence or family identification. The file is newly observed, with only one source and one submission.
Threat Behavior
One sandbox run mapped activity to MITRE T1055 and T1543.002. A separate heuristic associated the process evidence with LSASS, but the available record lists system processes and does not establish actual memory reading or a specific injection mechanism. The sandbox did not issue a malicious verdict. Ten extracted children were inspected without a malicious child result, but all ten remain unclassified, and no complete contacted-host reputation check is available.
What To Do Now
Keep endpoint protection enabled and obtain the archive only from its expected official distribution channel. If its origin cannot be verified, do not import or execute its contents; instead, inspect the manifest and rescan each extracted component when more reputation data becomes available.
Where this verdict could be wrong4 caveats
- The complete 0/74 detection result, including silence from all 17 tier-1 engines, weighs strongly against known malware.
- behaviour.hasMaliciousSandboxVerdict=false, so the runtime system did not independently label the execution as malicious.
- The T1055 and credential-dumping heuristics rely on process evidence that lists svchost.exe and lsass.exe; this may reflect observed system processes rather than proven injection or memory access.
- All 10 extracted children remain unknown rather than positively benign, limiting the reassurance provided by droppedChildren.hasMaliciousChild=false.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0 of 74 antivirus engines reported a detection.
- All 17 reporting tier-1 engines were silent.
- No malicious sandbox verdict was recorded.
- No malicious extracted child was identified.
- YARAify returned zero rules, while CIRCL and MalwareBazaar returned no hits.
- One sandbox mapped execution to process injection technique T1055.
- The runtime heuristic associated process activity with LSASS.
- MITRE T1543.002 was present among the offensive-technique mappings.
- The archive has only one source and one submission.
- All 10 extracted children remain unclassified.
- No complete contacted-host reputation result is available.
Verify the archive against the expected publisher or project release before use, and keep endpoint protection enabled. Avoid executing or importing it when the source cannot be confirmed.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 15MITRE ATT&CK techniques
- 15spawned processes
- 0network contacts
- 7filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Created or modified a system service, which can keep code running.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Transferred a file over the network; malware can use this to fetch additional payloads.
Moderate concern: Checks which security software you have installed.
Note: Reads your Windows user-account details.
Note: Collects details about your system.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
S&R-P 1.0.0.mrpack
cb567a4826eb5985f88fc2ac32dbe209b5db51a70fb665202ccecb751a6034fd
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\system32\cmd.exe" /c "cd ^"C:\Users\<USER>\AppData\Local\Temp^" && start /wait ^"^" ^"C:\Users\<USER>\AppData\Local\Temp\overrides/mods/Baubles-1.12-1.5.2.jar^"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Program Files\Java\jre-1.8\bin\javaw.exe" -jar "C:\Users\<USER>\AppData\Local\Temp\overrides\mods\Baubles-1.12-1.5.2.jar"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
5676
C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\5676
04Isolated runtime analysis - Written fileObserved
3903daac9bc4a3b7.timestamp
C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\5676
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
- /root/.cache/dconf/user
- /var/log/auth.log.1.gz
- /var/log/dpkg.log.1.gz
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 597668321180a840a0bf…25d2cfNever scannednever seen before
- 73fe0f6009e7edd42407…52a7d8Never scannednever seen before
- fdaa5b21817f08eb8c7a…191b31Never scannednever seen before
- bbff985423437e9097d1…6393cfNever scannednever seen before
- c2e35b1346c62dc6e7fb…2a7d6fNever scannednever seen before
- 12514f658681c2bfc35d…3780d0Never scannednever seen before
- f396789fba6b2f22444a…f4ff7cNever scannednever seen before
- a92a86b0830fa5d1ea80…0e3fffNever scannednever seen before
- a902f5285015aa7dbd83…2c5ebcNever scannednever seen before
- 2422e7440f150f4c3c16…8ca022Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 2rule hits recorded
- 0 / 74engines flagged
- 1sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
0 of 74 antivirus engines flagged the file.
ProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 1 time from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: S&R-P 1.0.0.mrpack — cb567a4826eb5985f88fc2ac32dbe209b5db51a70fb665202ccecb751a6034fd
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\system32\cmd.exe" /c "cd ^"C:\Users\<USER>\AppData\Local\Temp^" && start /wait ^"^" ^"C:\Users\<USER>\AppData\Local\Temp\overrides/mods/Baubles-1.12-1.5.2.jar^"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Program Files\Java\jre-1.8\bin\javaw.exe" -jar "C:\Users\<USER>\AppData\Local\Temp\overrides\mods\Baubles-1.12-1.5.2.jar"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: 5676 — C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\5676
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: 3903daac9bc4a3b7.timestamp — C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exe
0 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. That limits reputation evidence, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- S&R-P 1.0.0.mrpack
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 513.3 KB
- Last analyzed
- Sep 19, 2026, 12:34 PM UTC
cb567a4826eb5985f88fc2ac32dbe209b5db51a70fb665202ccecb751a6034fdSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or extract it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is S&R-P 1.0.0.mrpack safe, or is it malware?
What is S&R-P 1.0.0.mrpack?
How many antivirus engines detected S&R-P 1.0.0.mrpack?
I already downloaded and opened or extracted S&R-P 1.0.0.mrpack — what should I do?
How do I remove S&R-P 1.0.0.mrpack?
What is the SHA-256 hash of S&R-P 1.0.0.mrpack?
How up to date is this analysis of S&R-P 1.0.0.mrpack?
Community
Member reviews and reports for this exact file hash.