Safe
Plain text LICENSE file with zero engine detections and long benign submission history.
7f6839a61ce892b79c…b7fda8b45dThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Zero malicious detections from 62 reporting engines including 17 tier-1 engines eliminates any engine-based threat signal. The file is a plain text LICENSE document that has been submitted 767 times by 672 sources since 2020, placing it firmly in the common_old prevalence class. Sandbox execution recorded only ambient techniques with no malicious verdict and no external host contact. The single CIRCL reference hit lacks a knownMalicious flag, confirming it is a neutral database entry rather than a threat indicator.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines.malicious=0 and engines.tier1Malicious=0 across 62 reporting engines
prevalence.classification=common_old (672 uniqueSources, 767 submissions)
behaviour.offensiveCount=0 and behaviour.hasMaliciousSandboxVerdict=false
externalIntel.circl.knownMalicious=null despite circl.hit=true
- Zero engine detections across all tiers
- Long-established common_old prevalence
- Clean sandbox behaviour with no malicious indicators
Safe to open or distribute; treat as a standard text license file.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- Local\ZonesCacheCounterMutex
- Local\ZonesLockedCacheCounterMutex
1 corroborating signal from researcher-curated sources
0 detections across 76 engines
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- LICENSE.txt
- Size
- 9.3 KB
- MIME type
- (unknown)
- Detected type
- Text
- SHA-256
- 7f6839a61ce892b79c6549e2dc5a81fdbd240a0b260f8881216b45b7fda8b45d
- MD5
- 31c5a77b3c57c8c2e82b9541b00bcd5a
- SHA-1
- 153d4bc14e3a2c1485006f1752e797ca8684d06d
- First seen (VT)
- 9/19/2020, 11:50:19 PM
- Last analysis (VT)
- 2/21/2026, 11:28:40 AM
- First scan (MalwareTips)
- 7/4/2026, 5:55:24 PM
- Last scan (MalwareTips)
- 7/4/2026, 5:55:24 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.