File verdict·Decided by the MT AI Engine
Our call

Malicious

8 tier-1 engines converge on forkbomb trojan family; 17-year prevalence history; strong malicious consensus.

forkbomb
Trust score8Critical
MT AI confidence · 94%
totally legit site
5 B
11ea65b2709bb714f05571b66015
Antivirus engines
23 of 74 flagged
Code signing
Unsigned
Age
First seen 17y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

94%Confidence
Very high
Reasoning

This 5-byte text file exhibits a strong tier-1 consensus on the forkbomb trojan family across 8 independent high-trust engines. The tier-1 malicious count (8/17) far exceeds the tier-1 clean count (8/17), and tier-2 engines add 12 additional malicious detections, while only 3 low-trust engines flag it — ruling out a low-trust-only false positive pattern. The file's prevalence classification as 'common_old' with 2,344 submissions since February 2009 establishes it as a historically known malware sample, not a rare new variant. Community annotations and Joe Sandbox verdicts consistently label it malicious. The absence of runtime behaviour data does not override the strong consensus from established vendors.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. tier1FamilyConsensus: forkbomb family, 4 tier-1 engines (BitDefender, Emsisoft, ESET-NOD32, GData, Kaspersky, Sophos, TrendMicro, TrendMicro-HouseCall), strong=true

  2. 8/17 tier-1 engines flagged malicious; 12/37 tier-2 engines flagged malicious; only 3/20 low-trust engines flagged — onlyLowTrustFlagging=false, ruling out low-trust-only false positive

  3. prevalence: common_old, 1544 submitters, 2344 submissions since 2009 — historically prevalent known malware, not a rare new sample

  4. Community consensus: 5 researcher annotations all label as malware/trojan; Joe Sandbox verdicts 'MAL' (56/100); Malware Analyzer 360 score 94.9

  5. File is unsigned, 5 bytes text; no signer history; no runtime behaviour data; no external YARA/CIRCL corroboration needed given tier-1 consensus

Points in its favour
  • No dropped children detected
  • No contacted malicious hosts in our cache
  • No external YARA rule matches (low false-positive risk from researcher rules)
Points against
  • Tier-1 consensus: 8 high-trust engines agree on forkbomb family
  • Historical prevalence: 2,344 submissions since 2009 across 1,544 unique sources
  • Unsigned executable: no publisher identity or signer history
  • Deceptive filename: 'totally legit site' masks malicious intent
  • Trojan family: forkbomb causes resource exhaustion and denial of service
  • Community consensus: multiple independent researchers and sandboxes label as malware
What to do

This file is a known forkbomb trojan with strong consensus from multiple tier-1 antivirus vendors. Do not execute it; remove immediately if present on your system and run a full antivirus scan.

Threat family attribution

forkbomb corroborated by 2 sources

  • VT (74 engines)
    forkbomb
  • MT AI Engine
    forkbomb
No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

23 detections across 74 engines

23 malicious0 suspicious51 clean
Tier-117 engines
8flag
Top commercial AVs (low FP rate)
Tier-237 engines
12flag
Mainstream engines with mixed FP rates
Low-trust20 engines
3flag
Heuristic / generic-AI engines (high FP rate)
alibabacloud
malicious
Trojan:Win/ForkBomb.A
ALYac
malicious
Application.ForkBomb.2
Antiy-AVL
malicious
Trojan/BAT.ForkBomb
Arcabit
malicious
Application.ForkBomb.2
BitDefender
malicious
Application.ForkBomb.2
CTX
malicious
txt.trojan.forkbomb
Emsisoft
malicious
Application.ForkBomb.2 (B)
ESET-NOD32
malicious
BAT/ForkBomb.A trojan
GData
malicious
Application.ForkBomb.2
Google
malicious
Detected
huorong
malicious
Joke/Agent.a!crit
Kaspersky
malicious
HEUR:Trojan.BAT.ForkBomb.gen
Lionic
malicious
Trojan.Text.ForkBomb.4!c
McAfeeD
malicious
ti!11EA65B2709B
MicroWorld-eScan
malicious
Application.ForkBomb.2
Sangfor
malicious
Suspicious.Win32.Save.a
Sophos
malicious
Troj/Bat-AEO
Tencent
malicious
Bat.Trojan.Forkbomb.Hjgl
TrendMicro
malicious
Trojan.BAT.FORKBOMB.A
TrendMicro-HouseCall
malicious
Trojan.BAT.FORKBOMB.A
VIPRE
malicious
Application.ForkBomb.2
Xcitium
malicious
Malware@#206x0geu3h4f1
ZoneAlarm
malicious
Troj/Bat-AEO
Hash 11ea65b2709b… cross-referenced against 74 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.

Common & old
Unique uploaders
1,544
Hundreds of people have uploaded this — common.
Total submissions
2,344
Includes repeat uploads by the same source.
First seen by VT
17y ago
Feb 16, 2009
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
here
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
2/16/2009, 10:23:58 PM
First seen (MalwareBazaar)
Last analysis (VT)
6/19/2026, 8:00:00 AM
Scanned here
6/25/2026, 7:56:09 AM
File name
totally legit site
Size
5 B
MIME type
(unknown)
Detected type
Text
SHA-256
11ea65b2709bb714f059cf53767f7ee5ae6defe5b5d548e32375e65571b66015
MD5
3808d82ed52876c3dda66fbf4cb142c8
SHA-1
224dcbc79590e1d4abfda3d17b083b333fa00980
First seen (VT)
2/16/2009, 10:23:58 PM
Last analysis (VT)
6/19/2026, 8:00:00 AM
First scan (MalwareTips)
6/25/2026, 7:56:09 AM
Last scan (MalwareTips)
6/25/2026, 7:56:09 AM
Community reputation
-187flagged
Behavior tags
text
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.