Suspicious
Unsigned 3 KB DLL with three low-trust detections and one prior suspicious imphash match.
21395b734f1360456c…6c8d7a6b3cThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Low-trust-only detections on an unsigned DLL with medium prevalence and clean runtime signals point to a borderline case rather than clear malware. The single RAG match on the same imphash also returned suspicious. No tier-1 consensus, no sandbox hits, and no external intelligence strengthen the mixed-signal assessment.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines.onlyLowTrustFlagging=true and tier1Malicious=0 (CrowdStrike, Cynet, McAfeeD only)
signing.signed=false and signerStats.found=false
similarHashes[0].verdict=suspicious (matchKind=imphash)
prevalence.classification=medium (21 uniqueSources, 26 submissions)
- Zero tier-1 malicious detections
- Medium prevalence over 7 years
- No malicious behaviour observed
- Unsigned binary
- Low-trust engine detections
- Prior similar-hash suspicious verdict
Treat as untrusted until the source is verified; avoid loading in critical 3ds Max workflows without additional validation.
1 contradiction resolved by the scoring engine
3 detections across 76 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- vray_v41003_max_fix.dll
- Size
- 3.0 KB
- MIME type
- (unknown)
- Detected type
- Win32 DLL
- SHA-256
- 21395b734f1360456c25891fe43765484b21df095b0a5fd594de046c8d7a6b3c
- MD5
- c3100df4ba6b778b3db6939610dc3338
- SHA-1
- 6143808146056a8c588f2661e572821cb73a7188
- PE imphash
- 79b3362178937bf9559741c46bb9e035
- First seen (VT)
- 4/1/2019, 1:10:05 PM
- Last analysis (VT)
- 1/29/2026, 12:02:02 AM
- First scan (MalwareTips)
- 7/3/2026, 9:52:36 AM
- Last scan (MalwareTips)
- 7/3/2026, 9:52:36 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.