Suspicious
Unsigned 3 KB DLL with three low-to-mid tier detections and medium prevalence but no tier-1 consensus or behavioural confirmation.
46f8e8a5073082afed…356dff4d2dThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The detection pattern is dominated by low-trust engines with one tier-2 contribution and zero tier-1 malicious hits, placing the sample in mixed-signals territory. Absence of signing, sandbox data, or external intelligence prevents a clean or malicious classification. Medium prevalence over six years suggests possible legitimate but uncommon use, yet the generic labels keep suspicion elevated.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines.tier1Malicious=0 with 3 total malicious (Bkav, MaxSecure, Skyhigh)
signing.signed=false and signerStats.found=false
prevalence.classification=medium (19 uniqueSources, 24 timesSubmitted)
peAnalysis.highEntropyCode=false and likelyPacked=false
- Zero tier-1 malicious detections
- Medium prevalence over 2208 days
- No packing or high-entropy code
- Unsigned binary
- Generic malicious labels from low-trust engines
- No behavioural confirmation available
Treat as suspicious pending further verification; do not load in production environments without additional context or a signed version.
3 detections across 76 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- vray_v50003_max_fix.dll
- Size
- 3.0 KB
- MIME type
- (unknown)
- Detected type
- Win32 DLL
- SHA-256
- 46f8e8a5073082afedb17c5ea8fcdb57eb2672312e32c079fce008356dff4d2d
- MD5
- 544bfbc543b572554e48c8eeec79caa5
- SHA-1
- cb2853f4cba53302834ba757325488d8154d3660
- PE imphash
- 79b3362178937bf9559741c46bb9e035
- First seen (VT)
- 6/16/2020, 8:37:11 PM
- Last analysis (VT)
- 12/2/2023, 10:53:11 PM
- First scan (MalwareTips)
- 7/3/2026, 9:51:21 AM
- Last scan (MalwareTips)
- 7/3/2026, 9:51:21 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.