Is Velocity.7z safe?
Archive contains PE files that trigger process-injection heuristics yet lacks tier-1 consensus or confirmed malicious children.
Two tier-2 engines flag RiskWare.DllInjector behaviour; sandbox shows T1055 activity but returns no malicious verdict. Medium prevalence and zero tier-1 detections keep the file in mixed-signals territory.
Treat as suspicious; do not execute without additional verification or sandbox re-analysis.
f27865ff8f60776ebd…4f765e047b05aaRecommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Two tier-2 engines flag RiskWare.DllInjector behaviour; sandbox shows T1055 activity but returns no malicious verdict. Medium prevalence and zero tier-1 detections keep the file in mixed-signals territory.
The file is a 7-Zip archive whose extracted contents exhibit process-injection indicators (T1055) and defensive-impairment calls (T1562.001) inside a single sandbox run. Only two tier-2 engines label the sample, none of them tier-1, and no dropped child or external-intel source corroborates malice. Medium prevalence and the absence of a completed host-reputation check leave the evidence balanced between suspicious and clean.
What We Detected
Two tier-2 engines (Gridinsoft, Malwarebytes) label the archive contents Risk.Win32.Gen.bot / RiskWare.DllInjector. Sandbox logs show rundll32 loading multiple WebView2Loader.dll instances and Microsoft.Web.* assemblies, mapped to MITRE T1055 and T1562.001. Ten dropped children were inspected; none carried malicious verdicts.
Threat Behavior
Observed activity is consistent with a portable application or research tool that injects into processes, yet no tier-1 engine, external-intel rule, or malicious child confirms an actual threat. contactedHosts data is unavailable, so network reputation cannot be assessed.
What To Do Now
Keep endpoint protection enabled. If the archive is required, extract and scan the individual PE files in an isolated environment before execution. Monitor for unusual child-process or network activity.
Where this verdict could be wrong1 caveat
- communityComments contain one annotation claiming 'Malicious' with centralBox score 70/100, but no corroborating tier-1 engine detections or external-intel hits.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Zero tier-1 malicious detections
- No malicious dropped children
- Medium prevalence across thousands of submissions
- Process-injection techniques observed in sandbox
- Two tier-2 detections without tier-1 support
Treat as suspicious; do not execute without additional verification or sandbox re-analysis.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete2 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Attempted to impair or bypass security controls.
High concern: Manipulated how the operating system loads code, which can redirect execution.
Moderate concern: Removed execution artefacts or logs, which can conceal activity.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Reads your Windows user-account details.
Note: Listed running processes; both legitimate software and malware may do this.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Velocity.7z
f27865ff8f60776ebd4febc0d8528aa3530396d4e4534ebe2b4f765e047b05aa
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\runtimes\win-arm64\native\WebView2Loader.dll",#1
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\Microsoft.Web.WebView2.Core.dll",#1
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Temp
C:\ProgramData\Microsoft\Windows\WER\Temp
04Isolated runtime analysis - Written fileObserved
e319c940-8ee9-4095-bdc5-4564dc107f5c
C:\ProgramData\Microsoft\Windows\WER\Temp\e319c940-8ee9-4095-bdc5-4564dc107f5c
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\ProgramData\Microsoft\Windows\WER\Temp
- C:\ProgramData\Microsoft\Windows\WER\Temp\e319c940-8ee9-4095-bdc5-4564dc107f5c
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue
- C:\ProgramData\Microsoft\Windows\WER\Temp\9b487937-2d35-45fa-921e-c555f3d6d8e7
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER1826.tmp
- Local\WERReportingForProcess5688
- Global\b1f925d4-625c-4672-93ea-2b3c17e6afe1
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 8427b1fc58ec707813e5…1e0f1cNever scannednever seen before
- 44ab92c2246ebfb5f98a…5e63f0Never scannednever seen before
- e28716662c6aa158eecf…9a3dd3Never scannednever seen before
- b6a200f3dfcf2cb6c3b6…02972fNever scannednever seen before
- bcf3a14e8712a90837fc…fb23dbNever scannednever seen before
- c4c0b8e1593bc5481521…8ce545Never scannednever seen before
- 9945bf0b137c9f60e4fd…9a607cNever scannednever seen before
- 08c7014d311979c3e37e…9cf08aNever scannednever seen before
- df5816669f5123595c47…8b73a6Never scannednever seen before
- 96bc2946dff8790400d6…a1fbd3Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
2 of 75 antivirus engines flagged the file, including Gridinsoft and Malwarebytes.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 5,041 times from 3,205 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: Velocity.7z — f27865ff8f60776ebd4febc0d8528aa3530396d4e4534ebe2b4f765e047b05aa
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\runtimes\win-arm64\native\WebView2Loader.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\Microsoft.Web.WebView2.Core.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Temp — C:\ProgramData\Microsoft\Windows\WER\Temp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: e319c940-8ee9-4095-bdc5-4564dc107f5c — C:\ProgramData\Microsoft\Windows\WER\Temp\e319c940-8ee9-4095-bdc5-4564dc107f5c
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\runtimes\win-arm64\native\WebView2Loader.dll",#1
2 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Velocity.7z
- Format
- 7ZIP
- Code signing
- Not applicable to this file type
- Size
- 19.7 MB
- Last analyzed
- Aug 3, 2026, 9:37 PM UTC
f27865ff8f60776ebd4febc0d8528aa3530396d4e4534ebe2b4f765e047b05aaSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
Don't open or extract it unless you're certain it came from a source you trust.
Check where you got it — an unexpected attachment or a random download link is a red flag.
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.