File verdict·Decided by the MT AI Engine
Our call

Safe

Lua script flagged by zero engines across 76 antivirus products; universal clean consensus with no malicious behaviour or external-intelligence hits.

Trust score88High trust
MT AI confidence · 94%
271590.lua
833 B
7885ae3a6e9ec0adfe209dcd483f
Antivirus engines
0 of 76 flagged
Code signing
Unsigned
Age
First seen 1y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

94%Confidence
Very high
Reasoning

This Lua script has achieved universal clean consensus across our antivirus network. Eighteen tier-1 engines (the highest-trust vendors) all report it undetected, with zero malicious or suspicious flags across the entire 76-engine panel. The file's medium prevalence (15 submitters, 17 submissions) is consistent with benign shared code circulating in developer communities. No sandbox execution data shows malicious behaviour, no dropped children or malicious host contacts were observed, and external-intelligence sources (CIRCL, YARAify, MalwareBazaar) returned no hits. The unsigned status and file-type metadata confusion (named .lua but tagged CSV) do not override the overwhelming clean signal.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines.tier1Malicious=0, tier1ReportedClean=18 (Avast, BitDefender, Kaspersky, Microsoft, ESET, Fortinet, Ikarus, McAfee, DrWeb, Emsisoft, F-Secure, GData, Avira, AVG all undetected)

  2. engines.malicious=0, suspicious=0 across all 76 engines; reporting=61/76 — universal clean verdict

  3. signing.verified=false, unsigned file — no signer risk; no signerStats history to contradict

  4. behaviour=null, droppedChildren=null, contactedHosts=null, externalIntel all negative (CIRCL, YARAify, MalwareBazaar) — no runtime or external malice signals

  5. prevalence.classification='medium' (15 submitters, 17 submissions) — consistent with benign shared utility, not rare or novel

Points in its favour
  • 18/18 tier-1 engines undetected (Kaspersky, Microsoft, BitDefender, ESET, Fortinet, Ikarus, McAfee, DrWeb, Emsisoft, F-Secure, GData, Avira, AVG, Avast)
  • 0/76 engines flagged malicious or suspicious
  • No sandbox malicious verdict, no dropped children, no malicious host contacts
  • No external-intelligence hits (CIRCL, YARAify, MalwareBazaar all negative)
  • Medium prevalence (15 submitters, 17 submissions) consistent with benign shared utility
What to do

This file is safe. No further action is needed. If you received a security alert for this hash, it was likely a false positive or metadata-handling artifact.

No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

0 detections across 76 engines

0 malicious0 suspicious76 clean
Tier-118 engines
0flag
Top commercial AVs (low FP rate)
Tier-237 engines
0flag
Mainstream engines with mixed FP rates
Low-trust21 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 76 engines report this file as clean.
Hash 7885ae3a6e9e… cross-referenced against 76 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
15
Moderate upload volume.
Total submissions
17
Includes repeat uploads by the same source.
First seen by VT
1y ago
Mar 6, 2025
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
3/6/2025, 7:31:38 AM
First seen (MalwareBazaar)
Last analysis (VT)
3/6/2025, 7:31:38 AM
Scanned here
6/25/2026, 8:11:35 AM
File name
271590.lua
Size
833 B
MIME type
(unknown)
Detected type
CSV
SHA-256
7885ae3a6e9ec0adfe4ef57a376bc55e0da7fae48b52260ef24438209dcd483f
MD5
4364535d650ba3a23a2980757723c952
SHA-1
a4b2572181deae1f510369c50753be966e0263c5
First seen (VT)
3/6/2025, 7:31:38 AM
Last analysis (VT)
3/6/2025, 7:31:38 AM
First scan (MalwareTips)
6/25/2026, 8:11:35 AM
Last scan (MalwareTips)
6/25/2026, 8:11:35 AM
Behavior tags
csv
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.