VirusTotal is still analysing this freshly-seen file — this page refreshes automatically and will show the verdict the moment its engines finish reporting.
File verdict·Decided by the MT AI Engine
Our call

Unknown

VirusTotal is still analysing this file — its antivirus engines haven't finished reporting yet. This is normal for a freshly-seen file and usually clears within a few minutes. This page re-checks automatically and updates the moment results come in.

Trust score50Caution
SNDA Estoppel RSL MARKED 6.12.26.docx
2.6 MB
44ed480889bb8585b452482a3b56
Antivirus engines
0 of 0 flagged
Code signing
Unsigned
MT AI Engine · Verdict analysis

The reasoning behind this verdict

The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.

10%Confidence
Exploratory
Reasoning

VirusTotal is still analysing this file — its antivirus engines haven't finished reporting yet. This is normal for a freshly-seen file and usually clears within a few minutes. This page re-checks automatically and updates the moment results come in.

Key signals · 2

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. file.fileSize=2720307

  2. engines.total=0

Recommended action

No action needed — the scan finishes automatically once VirusTotal completes. You can also re-check from this report in a minute.

What to do now

There isn't enough information to give this file a clear rating.

  1. Be cautious — an unknown rating is not the same as a clean bill of health.

  2. Only run it if it came directly from the official maker of the software.

  3. When in doubt, don't open it — or scan it again later once it's more widely seen.

No researcher-database hits
External threat-intel sources were not collected for this scan.
File identity

Forensic fingerprint

File biography
First seen (VT)
First seen (MalwareBazaar)
Last analysis (VT)
6/15/2026, 12:53:50 PM
Scanned here
6/15/2026, 12:55:04 PM
File name
SNDA Estoppel RSL MARKED 6.12.26.docx
Size
2.59 MB
MIME type
application/vnd.openxmlformats-officedocument.wordprocessingml.document
Detected type
(unknown)
SHA-256
44ed480889bb8585b41cec3423aeae16b9af69566feab68cda356152482a3b56
MD5
9be3ccb01b3433af1e39fca9ed22358e
SHA-1
2c419f8f265690e1eb90b31eec3cf5db28d8cda6
Last analysis (VT)
6/15/2026, 12:53:50 PM
First scan (MalwareTips)
6/15/2026, 12:55:04 PM
Last scan (MalwareTips)
6/15/2026, 12:55:04 PM
Frequently asked

Safety FAQ

Common questions about SNDA Estoppel RSL MARKED 6.12.26.docx, answered from the scan data above.

  • We can't give SNDA Estoppel RSL MARKED 6.12.26.docx a confident verdict yet — too few engines have an opinion on this exact file. Uncommon or brand-new files often show little coverage before vendors catch up, so treat it as untrusted: don't opened it unless you're certain of the source.
  • SNDA Estoppel RSL MARKED 6.12.26.docx is a document file (application/vnd.openxmlformats-officedocument.wordprocessingml.document), about 2.6 MB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
  • The SHA-256 hash of SNDA Estoppel RSL MARKED 6.12.26.docx is 44ed480889bb8585b41cec3423aeae16b9af69566feab68cda356152482a3b56, and its MD5 is 9be3ccb01b3433af1e39fca9ed22358e. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on June 15, 2026. Because a file's hash never changes, the identity of SNDA Estoppel RSL MARKED 6.12.26.docx is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.