File verdict·Decided by the MT AI Engine
Our call

Suspicious

Single tier-1 backdoor detection without consensus; unsigned file; no behaviour or external corroboration available.

Backdoor.Win64.Gsb
Trust score58Caution
MT AI confidence · 62%
Mod_Pack_x64.zip
1.1 MB
983b3aedb281deed972a235296ab
Antivirus engines
1 of 75 flagged
Code signing
Unsigned
Age
First seen 1 day ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

62%Confidence
Moderate
Reasoning

The sample presents a single tier-1 malicious detection (Kaspersky naming a specific backdoor family) against 16 tier-1 clean reports, yielding no strong family consensus. While Kaspersky is a trusted engine and the label is specific rather than generic heuristic, the absence of agreement from other tier-1 vendors and the complete lack of runtime behaviour data, external YARA rules, or malicious host contact prevent confident malicious classification. The unsigned status and medium prevalence (9 submitters, 10 submissions in 1 day) add uncertainty. This profile — one tier-1 hit, no consensus, no behaviour — sits in the suspicious zone pending additional evidence.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. Kaspersky (tier1) flagged 'Backdoor.Win64.Gsb.bww' — 1/64 reporting malicious

  2. tier1FamilyConsensus.strong=false; only 1 tier-1 engine agrees; 16 tier-1 engines reported clean

  3. Unsigned file with no signer history (signing.verified=null, signerStats.found=false)

  4. No sandbox malicious verdict, no dropped children, no malicious host contact — behaviour unconfirmed

  5. Prevalence=medium (9 submitters, 10 submissions); filename analysis shows looksLikePortable=true

Points in its favour
  • 16 tier-1 engines reported clean — no consensus malicious family
  • No external YARA rules or CIRCL corroboration of malicious status
  • No malicious host contact or dropped children observed
  • Filename and archive structure consistent with modding/utility package
Points against
  • Single tier-1 engine (Kaspersky) flagged as backdoor family
  • Unsigned file with no publisher history or reputation
  • No sandbox execution data to confirm or deny malicious behaviour
  • Medium prevalence (9 submitters) — not rare, but not mainstream
What to do

Treat this file as suspicious pending further investigation. If obtained from an untrusted source, do not execute. If from a known modding community, verify source legitimacy and consider sandbox analysis to clarify the Kaspersky detection.

Threat family attribution

Backdoor.Win64.Gsb corroborated by 1 source

  • MT AI Engine
    Backdoor.Win64.Gsb
No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

1 detection across 75 engines

1 malicious0 suspicious74 clean
Tier-117 engines
1flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust20 engines
0flag
Heuristic / generic-AI engines (high FP rate)
Kaspersky
malicious
Backdoor.Win64.Gsb.bww
Hash 983b3aedb281… cross-referenced against 75 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
9
Moderate upload volume.
Total submissions
10
Includes repeat uploads by the same source.
First seen by VT
0d ago
Jun 27, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
6/27/2026, 1:20:22 PM
First seen (MalwareBazaar)
Last analysis (VT)
6/27/2026, 1:20:22 PM
Scanned here
6/28/2026, 3:54:06 AM
File name
Mod_Pack_x64.zip
Size
1.15 MB
MIME type
(unknown)
Detected type
ZIP
SHA-256
983b3aedb281deed97952841140141c67f9544d382f6ff72330d862a235296ab
MD5
3e90ee4b9fa01f5424925b26609c8cfa
SHA-1
f704bcf936cb93434df50cd384a94e10aa4cb0a0
First seen (VT)
6/27/2026, 1:20:22 PM
Last analysis (VT)
6/27/2026, 1:20:22 PM
First scan (MalwareTips)
6/28/2026, 3:54:06 AM
Last scan (MalwareTips)
6/28/2026, 3:54:06 AM
Behavior tags
zipencrypted
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.