File verdict·Decided by the MT AI Engine
Our call

Safe

Plain-text .nfo metadata file; 17 tier-1 antivirus engines report clean; no executable code or malicious behaviour detected.

Trust score92High trust
MT AI confidence · 98%
AIR.Music.Technology.Xpand!.2.v2.4.0-TCD.nfo
628 B
27a04c6ed65e4d6501e5fcbe442e
Antivirus engines
0 of 76 flagged
Code signing
Unsigned
Age
First seen 8mo ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

98%Confidence
Very high
Reasoning

The file is a plain-text release-info document, not executable code. Across 62 reporting engines, zero flagged it as malicious or suspicious. The tier-1 antivirus network — including high-trust vendors like Kaspersky, BitDefender, ESET-NOD32, Microsoft, and Fortinet — unanimously reports it undetected. No sandbox behaviour data, external-intelligence hits, or malicious host contacts exist. The medium prevalence (65 submitters, 72 submissions) is consistent with legitimate software release metadata circulating in scene communities. The unsigned status is expected for a text file.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. 17/17 tier-1 engines undetected (Avast, BitDefender, ESET-NOD32, Kaspersky, Microsoft, Fortinet, Emsisoft, Ikarus, DrWeb, F-Secure, GData, Avira, AVG all clean)

  2. 0/62 reporting engines flagged malicious or suspicious — unanimous clean across all tiers

  3. File type: Text (628 bytes) — .nfo metadata file, not executable; no PE analysis applicable

  4. Prevalence: medium (65 submitters, 72 submissions) — expected distribution for scene release metadata

  5. No external-intel hits (CIRCL, MalwareBazaar, YARAify all negative); no sandbox verdicts; no malicious host contacts

Points in its favour
  • Unanimous tier-1 antivirus consensus (17/17 engines clean)
  • Plain-text file format — no executable code
  • No malicious behaviour, dropped files, or host contacts
  • No external-intelligence hits (CIRCL, MalwareBazaar, YARAify negative)
  • Medium prevalence consistent with legitimate software metadata
What to do

This file is safe. It is a plain-text metadata document with no executable code or malicious behaviour. No action is required.

No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

0 detections across 76 engines

0 malicious0 suspicious76 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust21 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 76 engines report this file as clean.
Hash 27a04c6ed65e… cross-referenced against 76 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
65
Moderate upload volume.
Total submissions
72
Includes repeat uploads by the same source.
First seen by VT
8mo ago
Nov 2, 2025
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
11/2/2025, 10:43:37 AM
First seen (MalwareBazaar)
Last analysis (VT)
11/2/2025, 10:43:37 AM
Scanned here
6/29/2026, 9:49:00 AM
File name
AIR.Music.Technology.Xpand!.2.v2.4.0-TCD.nfo
Size
628 B
MIME type
(unknown)
Detected type
Text
SHA-256
27a04c6ed65e4d6501c2545c2885b5fc5a6384fb08e95c224eda76e5fcbe442e
MD5
6d30c7afb927ccfa6af2a3368c0bf083
SHA-1
18aae3575ded9d84e258036a3e712fabe19a764c
First seen (VT)
11/2/2025, 10:43:37 AM
Last analysis (VT)
11/2/2025, 10:43:37 AM
First scan (MalwareTips)
6/29/2026, 9:49:00 AM
Last scan (MalwareTips)
6/29/2026, 9:49:00 AM
Behavior tags
text
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.