Is loader.rar safe?
The archive drew 33 of 74 detections, including eight tier-1 votes, and exhibited defense-impairment behavior while extracting a loader executable.
Thirty-three of 74 engines flagged this RAR archive, with eight high-trust detections reporting trojan, VMProtect, or generic malware labels. A sandbox also observed extraction of loader.exe and technique T1562.001, while the contacted IP lacked a completed reputation check.
e88eb8157c7a6d39c4…b48146bcdb777eRecommended next actions
Before opening or extracting
Do not open or extract it. Delete this archive from the device, then empty the Recycle Bin or Trash.
If you already opened or extracted it
Close it. If it opened links, requested credentials, or triggered unexpected behavior, disconnect from the internet and run a full device scan.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Thirty-three of 74 engines flagged this RAR archive, with eight high-trust detections reporting trojan, VMProtect, or generic malware labels. A sandbox also observed extraction of loader.exe and technique T1562.001, while the contacted IP lacked a completed reputation check.
The detection volume is substantial: 33 of 74 engines flagged the archive, including eight independent high-trust votes. Several established engines identify a generic trojan or VMProtect-protected payload, although their family labels do not converge strongly enough to assign a precise family. One completed sandbox observed the archive extracting loader.exe and recorded T1562.001, which is consistent with attempts to impair defenses. It also contacted 162.159.36.2 directly, but no complete host-reputation result is available because the host cross-check was not saved. The two extracted children remain unclassified, so they neither confirm nor negate the broader evidence.
What We Detected
Thirty-three of 74 antivirus engines flagged loader.rar. Eight high-trust engines contributed detections, including BitDefender and Emsisoft with Trojan.GenericKD.80177790, Avast with Win64:MalwareX-gen, and TrendMicro with Trojan.Win32.ZYX.USBLES26. The labels vary, so the exact malware family remains unresolved, but the breadth of detection is significant.
Threat Behavior
One completed sandbox run extracted loader.exe from the archive and recorded MITRE technique T1562.001, associated with impairing defenses. The sample also used long-sleep and debugger-detection traits and contacted 162.159.36.2 without an application domain. No complete reputation result is available for that IP, and the two extracted child hashes remain unclassified.
What To Do Now
Do not open or extract this archive on a production device. Keep endpoint protection enabled, quarantine the file, and investigate any system where its contents were executed, including reviewing outbound connections and recently created files.
Where this verdict could be wrong4 caveats
- engines.tier1FamilyConsensus.strong=false; no single named family has strong independent tier-1 agreement.
- behaviour.hasMaliciousSandboxVerdict=false, so the completed sandbox did not issue an explicit malware verdict.
- externalIntel.yaraify.ruleCount=0 and externalIntel.circl.hit=false provide no researcher-curated corroboration, though absence of such hits is not exculpatory.
- droppedChildren.hasMaliciousChild=false, but both extracted children have unknown verdicts rather than confirmed clean results.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- No explicit malicious sandbox verdict was issued
- No persistence indicators were observed
- No strong tier-1 family consensus was established
- CIRCL and YARAify returned no corroborating hits
- 33/74 antivirus detections
- Eight independent tier-1 malicious votes
- RAR archive extracts loader.exe
- Observed MITRE technique T1562.001
- Direct-IP traffic to 162.159.36.2 without completed reputation coverage
- Tags indicate long sleeps and debugger-environment detection
Quarantine and remove the archive without extracting it. If it was executed, isolate the affected system, keep security protection enabled, and perform a full endpoint and network investigation.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete33 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 runtime contact was observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 3MITRE ATT&CK techniques
- 3spawned processes
- 1network contacts
- 6filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Attempted to impair or bypass security controls.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Collects details about your system.
Note: Connected to 1 server during sandbox analysis.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
loader.rar
e88eb8157c7a6d39c4deec0804ee20ce473a0bedfd5f065002b48146bcdb777e
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
C:\Windows\SysWOW64\unarchiver.exe "C:\Windows\SysWow64\unarchiver.exe" "C:\Users\user\Desktop\loader.rar"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\SysWOW64\7za.exe "C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\ccz42ncj.hcy" "C:\Users\user\Desktop\loader.rar"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
ccz42ncj.hcy
C:\Users\user\AppData\Local\Temp\ccz42ncj.hcy
04Isolated runtime analysis - Written fileObserved
loader
C:\Users\user\AppData\Local\Temp\ccz42ncj.hcy\loader
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
162.159.36.2
Contact observed during runtime.
06Isolated runtime analysis
6 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Users\user\AppData\Local\Temp\ccz42ncj.hcy
- C:\Users\user\AppData\Local\Temp\ccz42ncj.hcy\loader
- C:\Users\user\AppData\Local\Temp\ccz42ncj.hcy\loader\loader.exe
- C:\Users\user\AppData\Local\Temp\unarchiver.log
- \Device\ConDrv\\Connect
Files this sample writes at runtime
This file drops 2 children at runtime. None are currently flagged malicious in our cache.
- 3ad44d0b739b43078efc…40940bNever scannednever seen before
- 07b943ead65eae1fff5e…184aefNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 33 / 74engines flagged
- 286sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
33 of 74 antivirus engines flagged the file, including alibabacloud and ALYac.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 327 times from 286 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: loader.rar — e88eb8157c7a6d39c4deec0804ee20ce473a0bedfd5f065002b48146bcdb777e
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — C:\Windows\SysWOW64\unarchiver.exe "C:\Windows\SysWow64\unarchiver.exe" "C:\Users\user\Desktop\loader.rar"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — C:\Windows\SysWOW64\7za.exe "C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\ccz42ncj.hcy" "C:\Users\user\Desktop\loader.rar"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: ccz42ncj.hcy — C:\Users\user\AppData\Local\Temp\ccz42ncj.hcy
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: loader — C:\Users\user\AppData\Local\Temp\ccz42ncj.hcy\loader
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Contacted host: 162.159.36.2 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: generic-trojan
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Low-severity pattern matches — worth noting but not on their own cause for alarm.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence162.159.36.2
33 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- loader.rar
- Format
- RAR
- Code signing
- Not applicable to this file type
- Size
- 12.0 MB
- Last analyzed
- Sep 20, 2026, 6:49 PM UTC
e88eb8157c7a6d39c4deec0804ee20ce473a0bedfd5f065002b48146bcdb777eSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't open or extract this archive. Delete this archive from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already opened or extracted it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the original trusted source and verify its exact hash when possible.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is loader.rar a virus?
What is loader.rar?
How many antivirus engines detected loader.rar?
What should I do if I already opened or extracted loader.rar?
How do I remove loader.rar?
What kind of malware is loader.rar?
What is the SHA-256 hash of loader.rar?
How up to date is this analysis of loader.rar?
Community
Member reviews and reports for this exact file hash.