Suspicious
Clean across 65 engines including tier-1 scanners, but brand-new small ZIP lacks runtime data and history.
af4aee5cf040397a9f…790c69a18cThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Strong clean signals from high-coverage engine scans outweigh any concerns initially. Yet the file's extreme newness, tiny size, and ZIP nature introduce uncertainty, as archives can conceal unpackable payloads. Absence of behavior, intel, or precedents prevents full clearance. Overall, mixed profile tilts suspicious pending deeper inspection.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
65/75 engines reporting undetected (17 tier1 clean: Avast, BitDefender, ESET, F-Secure, Fortinet, GData, Ikarus, Kaspersky, Microsoft)
prevalence.classification='rare_new' (1 unique source, firstSeen='2026-04-28')
fileSize=377 bytes ZIP (looksLikePortable=true)
No topDetections with malicious/hacktool labels
No externalIntel.circl.hit, yaraify.hit=false, malwareBazaar.hit=false
- 17 tier1ReportedClean (e.g., BitDefender, ESET, Kaspersky)
- 0 malicious from 65 reporting engines
- No triggeredHeuristics
- No hacktool/adware labels in topDetections
- Clean tier1FamilyConsensus (family=null)
- ageDays=0 (brand new)
- rare_new prevalence (1 submission)
- fileSize=377 bytes (minimal ZIP)
- No behaviour/dynamic analysis
- Unsigned/no signerStats
- No similarHashes precedents
Do not open or execute. Extract contents in a secure sandbox or virtual machine, then rescan all extracted files. Delete if source untrusted.
0 detections across 75 engines
How often this file shows up in the wild
Barely seen in the wild and first surfaced recently. This is the footprint of targeted malware the AV industry hasn't signatured yet — extra scrutiny is warranted.
Forensic fingerprint
- File name
- Mod.-347.zip
- Size
- 377 B
- MIME type
- (unknown)
- Detected type
- ZIP
- SHA-256
- af4aee5cf040397a9fbed35476da0a2af6425cc91e7faf15263410790c69a18c
- MD5
- f2d720473721f40a026e21a9b16a5877
- SHA-1
- 07023f4941c84cf88123afa4e875c5bda720ea5c
- First seen (VT)
- 4/28/2026, 6:22:41 AM
- Last analysis (VT)
- 4/28/2026, 7:06:17 AM
- First scan (MalwareTips)
- 4/28/2026, 7:10:07 AM
- Last scan (MalwareTips)
- 4/28/2026, 7:10:07 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.