Malicious
10 tier-1 antivirus engines detect this unsigned ZIP as a trojan dropper with direct-IP C2 communication and embedded malware.
d2a4288b2682d22f37…cec86f4388The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The evidence strongly indicates this is a malicious trojan dropper. Ten tier-1 antivirus engines report malware families (ABTrojan, Trojan-Dropper.PowerShell.Agent, Trojan:Win32/Suschil, Trojan.GenericKD), with 3 engines converging on the win32 family — this tier-1 consensus is a high-confidence malware signal. The filename 'CN_GreenLumaGUI' references GreenLuma, a known game-licensing bypass tool frequently used in trojan distribution chains. The sample contacted an external IP address (162.159.36.2) without any DNS domain queries, which our heuristic engine flagged as direct-IP C2 communication — a hallmark of malware command infrastructure designed to evade reputation-based blocklists. Sandbox execution shows the ZIP was decompressed using 7za.exe and an embedded executable (CN_GreenLumaGUI.exe) was launched from the temp directory, consistent with dropper behaviour. The unsigned status and embedded PE content further support the malicious classification.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
tier1Malicious=10 engines (Avast, AVG, Avira, BitDefender, Emsisoft, F-Secure, Fortinet, G-Data, Ikarus, Microsoft) flagging malware families
tier1FamilyConsensus.strong=true — 3 tier-1 engines agree on 'win32' family classification
Unsigned PE-containing ZIP; filename 'CN_GreenLumaGUI' matches known game-licensing bypass tool used in trojan distribution
triggeredHeuristics: MalwareTips.Synth.DirectIpC2 fired (medium severity) — direct IP contact (162.159.36.2) with zero DNS domains indicates C2 communication
Behaviour: T1562.001 (Impair Defenses) offensive technique; sandbox shows extraction and execution of embedded executable from temp directory
- Dropped children (2 inspected) not confirmed malicious in our cache
- 10 tier-1 antivirus engines report malware families
- Tier-1 family consensus (win32) across 3 high-trust engines
- Direct IP-based C2 communication (162.159.36.2) with zero DNS queries
- Unsigned executable embedded in ZIP archive
- Filename references GreenLuma, a known game-licensing bypass tool used in trojan distribution
- Sandbox execution shows extraction and launch of embedded executable from temp directory
Block and quarantine this file immediately. Do not execute under any circumstances. If already executed, perform a full system scan and change all credentials from a clean device.
abtrojan corroborated by 2 sources
- VT (75 engines)abtrojan
- MT AI EngineABTrojan
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
- C:\Users\user\AppData\Local\Temp\1k5bmq0c.hlm
- C:\Users\user\AppData\Local\Temp\1k5bmq0c.hlm\CN_GreenLumaGUI.exe
- C:\Users\user\AppData\Local\Temp\unarchiver.log
- \Device\ConDrv\\Connect
Files this sample writes at runtime
This file drops 2 children at runtime. None are currently flagged malicious in our cache.
- 02ab13f16c239ad22c1e…1f10abNever scannednever seen before
- ef2c8084facdf09f7d6f…2017d6Never scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence162.159.36.2
23 detections across 75 engines
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- CN_GreenLumaGUI.v1.6.14.24149.zip
- Size
- 18.52 MB
- MIME type
- (unknown)
- Detected type
- ZIP
- SHA-256
- d2a4288b2682d22f3765fc770336275181f26065220aa3c83fb868cec86f4388
- MD5
- d699a672a8c46a8ff7d51c1b9288a2da
- SHA-1
- b030b69e0bf647ca26b5e711d0bedae8e8d32474
- First seen (VT)
- 5/23/2026, 1:17:09 PM
- Last analysis (VT)
- 5/25/2026, 9:38:26 AM
- First scan (MalwareTips)
- 6/29/2026, 9:48:18 AM
- Last scan (MalwareTips)
- 6/29/2026, 9:48:18 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.