Is BeamNG-drive-C4-B0ndir-574346.zip safe?
Two of 75 engines flagged this ZIP, but weak family agreement, broad tier-1 disagreement, and missing runtime evidence leave the risk unresolved.
TrendMicro-HouseCall and VBA32 flagged the archive, but only one high-trust engine detected it and their family labels do not form a strong consensus. Most high-trust engines did not flag it, while no sandbox run or complete contacted-host check is available, so avoid opening it unless its source and contents can be independently verified.
da8cd7833a1783d62e…f54741669de78dRecommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
TrendMicro-HouseCall and VBA32 flagged the archive, but only one high-trust engine detected it and their family labels do not form a strong consensus. Most high-trust engines did not flag it, while no sandbox run or complete contacted-host check is available, so avoid opening it unless its source and contents can be independently verified.
Two of 75 antivirus engines detected the archive, with one detection coming from high-trust TrendMicro-HouseCall. The other detection came from low-trust VBA32, and the engines used differing generic trojan and ransomware labels rather than a corroborated family name. Sixteen of 17 reporting high-trust engines did not flag the file, which makes a false positive plausible but does not negate the tier-1 warning. No curated external-intelligence source matched the hash. Because no completed runtime observation or contacted-host reputation check is available, the archive's actual behavior remains unresolved.
What We Detected
Two of 75 antivirus engines flagged this ZIP archive. TrendMicro-HouseCall reported Trojan.Win32.Gen.TL0101HD26ZU, while VBA32 reported BScope.TrojanRansom.Exxroute. Only the TrendMicro-HouseCall result is a tier-1 detection, and there is no strong family consensus.
Threat Behavior
No completed sandbox observation is available, so execution behavior was not observed. The contacted-host reputation check was also not completed or saved, preventing any conclusion about network destinations. MalwareBazaar, CIRCL, and YARAify supplied no corroborating hit, although absence of a match does not prove harmlessness.
What To Do Now
Do not extract or run files from this archive on a production system until the download source and contained files are verified. Keep endpoint protection enabled, obtain the archive from an official source if possible, and scan each extracted item in an isolated environment.
Where this verdict could be wrong3 caveats
- TrendMicro-HouseCall is a tier-1 engine and identified a generic trojan label, so the detection warrants caution despite the broader engine disagreement.
- VBA32 independently used the Exxroute ransomware label, but it is low-trust and does not match the tier-1 label closely enough to establish a family consensus.
- Absence of external-intelligence hits may reflect coverage gaps rather than proving the archive is benign.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Only 2/75 engines detected the archive
- 16/17 reporting tier-1 engines did not flag it
- No strong tier-1 family consensus
- No MalwareBazaar, CIRCL, or YARAify hit
- Medium prevalence across 469 sources and 571 submissions
- TrendMicro-HouseCall tier-1 trojan detection
- VBA32 Exxroute ransomware-style detection
- No completed runtime observation
- No complete contacted-host reputation result
- Archive filename suggests unofficial portable game content
Avoid opening the archive unless it came from a verified official source. Keep security protection enabled and inspect its contents in an isolated environment before any execution.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete2 of 75 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 2 / 75engines flagged
- 469sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
2 of 75 antivirus engines flagged the file, including TrendMicro-HouseCall and VBA32.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 571 times from 469 sources.
ProvenanceDerivedSourceSaved report factsObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
2 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- BeamNG-drive-C4-B0ndir-574346.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 17.8 MB
- Last analyzed
- Sep 27, 2026, 6:19 PM UTC
da8cd7833a1783d62e8a5694f262114f4b244b130c4081ccdff54741669de78dSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or extract it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is BeamNG-drive-C4-B0ndir-574346.zip safe, or is it malware?
What is BeamNG-drive-C4-B0ndir-574346.zip?
How many antivirus engines detected BeamNG-drive-C4-B0ndir-574346.zip?
I already downloaded and opened or extracted BeamNG-drive-C4-B0ndir-574346.zip — what should I do?
How do I remove BeamNG-drive-C4-B0ndir-574346.zip?
What is the SHA-256 hash of BeamNG-drive-C4-B0ndir-574346.zip?
How up to date is this analysis of BeamNG-drive-C4-B0ndir-574346.zip?
Community
Member reviews and reports for this exact file hash.