Is vibranceGUI.zip safe?
Only 1 of 75 engines produced a generic low-trust detection, while extensive prevalence, tier-1 results, runtime observation, and host checks provide no corroboration.
Only MaxSecure flagged the archive, using a generic heuristic label; all 17 reporting tier-1 engines found nothing. The file has circulated extensively since 2018, and the completed sandbox run, child inspection, external intelligence checks, and fully covered host-reputation check produced no corroborating malware evidence.
fd3d994a8df5d39bc5…6a6ab35d08c21cRecommended next actions
Before opening or extracting
Open or extract it only when its sender or download source has been independently verified.
If you already opened or extracted it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Only MaxSecure flagged the archive, using a generic heuristic label; all 17 reporting tier-1 engines found nothing. The file has circulated extensively since 2018, and the completed sandbox run, child inspection, external intelligence checks, and fully covered host-reputation check produced no corroborating malware evidence.
The antivirus result is isolated: 1 of 75 engines flagged the archive, and that detector is low-trust with a generic label. All 17 reporting tier-1 engines were silent, and no engine family consensus exists. The file has accumulated 14,084 submissions from 3,682 sources since 2018, which strongly conflicts with the idea of an active, consistently detectable trojan. One completed sandbox run recorded T1562.001, but produced no malicious verdict or persistence indicators, and none of 10 inspected children was identified as malicious. Reputation checks covered all 20 distinct contacted domains and IPs and found no malicious or suspicious hosts, while MalwareBazaar and YARAify supplied no corroboration. The contaminated community-comment text was disregarded, leaving the lone MaxSecure detection most consistent with a false positive.
What We Detected
Only 1 of 75 antivirus engines flagged the archive. The sole detection came from MaxSecure and used the generic label Trojan.Malware.300983.susgen; all 17 reporting tier-1 engines found nothing, and there was no family consensus.
Threat Behavior
One completed sandbox run mapped T1562.001 alongside 16 commonly observed techniques, but it did not produce a malicious runtime verdict or any persistence indicators. Ten child hashes were inspected without an identified malicious child, although their individual classifications remain unknown. Host-reputation coverage included all 20 distinct contacted domains and IPs and returned no malicious or suspicious hosts. No MalwareBazaar match or YARAify rule was present.
What To Do Now
The evidence strongly supports an isolated heuristic false positive, particularly given 14,084 submissions from 3,682 sources since 2018. Keep endpoint protection enabled, obtain software from its official distribution channel, and rescan if the archive's hash changes or new detections emerge.
Where this verdict could be wrong3 caveats
- MaxSecure labels the file Trojan.Malware.300983.susgen, although no tier-1 or tier-2 engine corroborates that generic detection.
- The sandbox mapped T1562.001, an impairment-of-defenses technique, but recorded no malicious sandbox verdict and no persistence indicators.
- All 10 inspected child hashes have unknown individual verdicts, so hasMaliciousChild=false reflects no identified malicious child rather than affirmative benign classifications.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 17 reporting tier-1 engines produced no malicious detection.
- Only 1 of 75 engines flagged the sample, and it was low-trust.
- The hash has 14,084 submissions from 3,682 sources dating to 2018.
- The completed sandbox run had no malicious verdict or persistence indicators.
- All 20 distinct contacted hosts were covered, with no malicious or suspicious matches.
- MaxSecure reported the generic detection Trojan.Malware.300983.susgen.
- The sandbox mapped offensive technique T1562.001.
- The ZIP contains executable content.
- The 10 inspected child hashes have unknown individual classifications.
Keep endpoint protection enabled and use this archive only if it came from the project's official distribution channel. Recheck the hash if the package changes or additional reputable engines begin detecting it.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete1 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial20 of 40 contacted hosts were cross-checked; coverage is incomplete.
YARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 17MITRE ATT&CK techniques
- 15spawned processes
- 40network contacts
- 35filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- twitter.com
- edge-mobile-static.azureedge.net
- business.bing.com
- x.com
- bzib.nelreports.net
- abs.twimg.com
- t.co
- pbs.twimg.com
- api.x.com
- api.twitter.com
- 104.244.42.65
- 13.107.6.158
- 104.244.42.193
- 23.215.55.144
- 152.199.24.185
- 72.21.81.130
- 146.75.104.159
- 104.244.42.194
- 104.244.42.66
- 104.244.43.131
- HKU\S-1-5-21-575823232-3065301323-1442773979-1000\Software\Microsoft\Internet Explorer\Toolbar\Locked
- HKU\S-1-5-21-575823232-3065301323-1442773979-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Count
- HKU\S-1-5-21-575823232-3065301323-1442773979-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Type
- HKU\S-1-5-21-575823232-3065301323-1442773979-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Time
- HKEY_USERS\S-1-5-21-575823232-3065301323-1442773979-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Type
- HKEY_USERS\S-1-5-21-575823232-3065301323-1442773979-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Time
- C:\Users\<USER>\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\vibranceGUI.exe.log
- C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
- C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
- C:\ProgramData\Microsoft\Network\Downloader\edb.chk
- C:\ProgramData\Microsoft\Network\Downloader\edb.log
- C:\ProgramData\Microsoft\Network\Downloader\res1.log
- C:\ProgramData\Microsoft\Network\Downloader\res2.log
- C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-63985F7E-1B2C.pma
- C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-651CC9E4-1D28.pma
- C:\Users\user\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma
- vibranceGUI~Mutex
- Global\OneSettingQueryMutex+compat+encapsulation
- \Sessions\1\BaseNamedObjects\vibranceGUI~Mutex
- \Sessions\1\BaseNamedObjects\Local\ChromeProcessSingletonStartup!
- \Sessions\1\BaseNamedObjects\{A946A6A9-917E-4949-B9BC-6BADA8C7FD63}
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 1cbaa4d4c817743a7ec8…62970fNever scannednever seen before
- 8bbac5712dafe082096b…364a10Never scannednever seen before
- 41fe8d4da0de4b24f0f0…b73133Never scannednever seen before
- d551c96ef6363c0f6ec1…22afa0Never scannednever seen before
- a94ac434454ff4432b9b…26738bNever scannednever seen before
- 6bda5ee03ad84a4a5007…58b33bNever scannednever seen before
- c40aaf1cb87297045680…44b42aNever scannednever seen before
- 9cf94355051bf0f4a457…7b13d8Never scannednever seen before
- e01b60bfee21b6c722d9…aa5b8dNever scannednever seen before
- 2380b7ea30af7a89ceba…d43b28Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 1 / 75engines flagged
- 3,682sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
The hash has a long, established submission history across 3,682 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 02
1 of 75 antivirus engines flagged the file, including MaxSecure.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 14,084 times from 3,682 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: vibranceGUI.zip — fd3d994a8df5d39bc52913d67378da483e638cf2655630de616a6ab35d08c21c
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\vibranceGUI.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://twitter.com/juvlarN
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: vibranceGUI.exe.log — C:\Users\<USER>\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\vibranceGUI.exe.log
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: qmgr0.dat — C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: twitter.com — Saved reputation verdict: safe.
ProvenanceDerivedSourceContacted-host cross-checkObserved at - 10
Contacted host: edge-mobile-static.azureedge.net — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
1 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- vibranceGUI.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 231.4 KB
- Last analyzed
- Oct 6, 2026, 11:50 AM UTC
fd3d994a8df5d39bc52913d67378da483e638cf2655630de616a6ab35d08c21cSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open or extract it only when its sender or download source has been independently verified.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is vibranceGUI.zip safe?
What is vibranceGUI.zip?
How many antivirus engines detected vibranceGUI.zip?
What is the SHA-256 hash of vibranceGUI.zip?
Is it safe to open or extract vibranceGUI.zip?
How up to date is this analysis of vibranceGUI.zip?
Community
Member reviews and reports for this exact file hash.