Safe
Single low-trust generic detection on widely distributed, 7-year-old audio software; 17 tier-1 engines silent; Microsoft infrastructure contact.
5a84271e1df1debb93…27be01886dThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The detection is isolated to MaxSecure (low-trust tier) with a generic heuristic label ('Trojan.Malware.300983.susgen') bearing no family consensus. All 17 tier-1 engines—including Kaspersky, BitDefender, ESET, Avast, and Avira—reported the file clean. The file's 7-year prevalence (common_old classification, 234 submissions) and legitimate software profile (Oremo audio tool, portable executable, UPX-packed) are inconsistent with malware. The triggered heuristic on direct-IP contact is negated by the fact that contacted IPs are Microsoft infrastructure, not attacker-controlled C2. No malicious sandbox verdict, no malicious dropped children, and no external-intelligence hits further support a benign classification.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 1/68 malicious (MaxSecure, low-trust); tier1Malicious=0; 17 tier-1 engines silent (Kaspersky, BitDefender, ESET, Avast, Avira, Fortinet, Ikarus, F-Secure, GData, Emsisoft, DrWeb, Avira, Avast, AVG, Kaspersky)
MaxSecure label 'Trojan.Malware.300983.susgen' — generic heuristic with .susgen suffix, no named family, no tier-1 consensus
prevalence.classification=common_old: 204 submitters, 234 submissions since 2019-01-17 — widely distributed, established file
Contacted IPs (13.107.253.41, 13.107.6.158, 184.51.42.107) are Microsoft Azure infrastructure, not malicious C2; no malicious hosts in our cache
Unsigned, no signer history, no brand mismatch; filename 'oremo-3.0-b190106.zip' consistent with Oremo audio synthesis tool; 10 dropped children inspected, 0 malicious
- 17 tier-1 antivirus engines reported clean (Kaspersky, BitDefender, ESET, Avast, Avira, Fortinet, Ikarus, F-Secure, GData, Emsisoft, DrWeb, Avira, Avast, AVG, Kaspersky)
- common_old prevalence: 234 submissions from 204 sources since 2019-01-17
- No malicious sandbox verdict; no malicious dropped children (10 inspected, 0 malicious)
- Contacted IPs are Microsoft Azure infrastructure, not malicious hosts
- Filename and profile consistent with Oremo, a legitimate open-source audio synthesis tool
This file is safe to use. The single low-trust detection is a false positive, contradicted by consensus from 17 tier-1 antivirus engines and 7 years of legitimate prevalence. No further action is needed.
1 contradiction resolved by the scoring engine
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 13.107.253.41
- 13.107.6.158
- 184.51.42.107
- C:\Users\<USER>\AppData\Local\Temp\TCL404B.tmp
- C:\Users\<USER>\AppData\Local\Temp\TCL000006f0\libsnack.dll
- C:\ProgramData\Microsoft\Windows\WER\Temp
- C:\ProgramData\Microsoft\Windows\WER\Temp\5725875c-364f-4edb-961b-090ec4a67779
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue
- C:\Users\<USER>\AppData\Local\Temp\TCL000006f0\libsnack.dll
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER9A81.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER9DAE.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER9EC8.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER9A81.tmp.dmp
- DirectSound Administrator shared thread array (lock
- Local\WERReportingForProcess7052
- Global\AmiProviderMutex_InventoryApplicationFile
- Global\e852d887-28fc-4832-9e92-88c39f238ad8
- Local\MidiMapper_modLongMessage_RefCnt
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 97a180b7c80c26ed8013…8e874bNever scannednever seen before
- cd3bff8b54a6c6241d77…297928Never scannednever seen before
- 353b5561a360fb87872a…513364Never scannednever seen before
- 4ba5cd736be284eb5528…0add51Never scannednever seen before
- 8210ce69192167e3ea05…491983Never scannednever seen before
- a5cb885ca15d03d23076…ea9546Never scannednever seen before
- 2d6b04702fe10234f5a8…de34a7Never scannednever seen before
- 22b3ed84229ba2d5d498…6a2881Never scannednever seen before
- 1d07b88474aa1e6aa261…a29c4aNever scannednever seen before
- ccec504c742af739d6c9…478e79Never scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 3 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence13.107.253.41 · 13.107.6.158 · 184.51.42.107
1 detection across 76 engines
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- oremo-3.0-b190106.zip
- Size
- 10.64 MB
- MIME type
- (unknown)
- Detected type
- ZIP
- SHA-256
- 5a84271e1df1debb93e66067f6fdd582514cfb7333a30ba3d8c1c327be01886d
- MD5
- 2fbd844f2698a15db36fe307691e3395
- SHA-1
- cee1d4c8c25e2ce899fd9c140c9bf5f31145156e
- First seen (VT)
- 1/17/2019, 8:53:53 AM
- Last analysis (VT)
- 3/23/2026, 7:40:05 PM
- First scan (MalwareTips)
- 6/13/2026, 5:53:14 AM
- Last scan (MalwareTips)
- 6/13/2026, 5:53:14 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.