File verdict·Decided by the MT AI Engine
Our call

Safe

SiriusLLM.exe is a signed Win32 EXE with zero malicious detections across 76 engines including all Tier-1 scanners, confirming it is safe.

Verified · VoodooSoft
Trust score6Critical
MT AI confidence · 95%
SiriusLLM.exe
1.2 MB
30da4f4ffd927b7c0e13ff45de3d
Antivirus engines
0 of 76 flagged
Code signing
Signed by VoodooSoft
Age
First seen 2mo ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

95%Confidence
Very high
Reasoning

The file claims to be SiriusLLM.exe, a signed Win32 PE executable with a valid Authenticode signature from VoodooSoft dated April 6, 2026. Our malware engines, including 17 Tier-1 scanners like BitDefender, Kaspersky, ESET-NOD32, Avast, and Microsoft, all report it undetected with zero malicious hits out of 76 total engines. Network tags note behaviors like detecting debug environments, long sleeps, and CPU checks, but these alone do not trigger detections without engine consensus. No hits in external intel sources like MalwareBazaar or CIRCL, and neutral reputation aligns with its young age of 15 days. Overall, this points to a clean file.

Points in its favour
  • Zero malicious detections from 76 engines, including 17 Tier-1 like BitDefender, Kaspersky, ESET-NOD32.
  • Valid Authenticode signature by VoodooSoft.
  • No hits in MalwareBazaar, YARAify, or CIRCL hashlookup.
  • Healthy scan coverage with no timeouts.
Points against
  • File is new, first seen 15 days ago with neutral reputation score of 0.
  • Network tags include detect-debug-environment, long-sleeps, and checks-cpu-name, common in evasive software.
What to do

Download from the official VoodooSoft source and re-scan before running. No quarantine needed based on our analysis.

No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

0 detections across 76 engines

0 malicious0 suspicious76 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust21 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 76 engines report this file as clean.
Hash 30da4f4ffd92… cross-referenced against 76 AV engines via our AV network.
File identity

Forensic fingerprint

File biography
First seen (VT)
4/6/2026, 2:33:58 AM
First seen (MalwareBazaar)
Last analysis (VT)
4/20/2026, 10:30:10 AM
Scanned here
4/20/2026, 3:58:37 PM
File name
SiriusLLM.exe
Size
1.17 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
30da4f4ffd927b7c0e6ddae343d57055e710c76b3ad5418fda366e13ff45de3d
MD5
613d25afdd87190d499c913ecd36a2cb
SHA-1
3bcd956cdcc3d074cbdfd2775239dff4f700b30f
First seen (VT)
4/6/2026, 2:33:58 AM
Last analysis (VT)
4/20/2026, 10:30:10 AM
First scan (MalwareTips)
4/20/2026, 3:58:37 PM
Last scan (MalwareTips)
4/20/2026, 3:58:37 PM
Code signer
VoodooSoftverified
Behavior tags
detect-debug-environmentlong-sleeps64bitssignedassemblypeexeoverlaychecks-cpu-name
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Scanned by
harlan4096Staff
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.