Safe
Unsigned binary with zero detections across 65 engines including 15 tier-1 vendors; clean behaviour profile and normal PE structure.
bf44d81c557810933c…35180c7f0dThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The sample exhibits a strong benign profile: zero malicious detections across a broad engine network with 15 tier-1 vendors reporting clean, no tier-1 family consensus, and no offensive MITRE techniques. Behaviour is limited to ambient patterns (system-info discovery, DLL search-order handling) consistent with standard installer or utility software. The file is unsigned and rare (2 submissions since 2021), but the complete absence of detections across high-trust engines and the clean runtime behaviour rule out sophisticated undetected malware. PE structure is normal (entropy 4.64, no packers). No external intelligence corroborates any threat.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/65 malicious; tier1Malicious=0; tier1ReportedClean=15 (Avast, BitDefender, ESET-NOD32, Kaspersky, Fortinet, GData, Emsisoft, F-Secure, Avira, DrWeb)
signing.verified=false, unsigned; no signer history; no brand mismatch detected
behaviour: 2 ambient MITRE (T1082, T1574.002); zero offensive techniques; zero malicious sandbox verdicts; zero malicious contacted hosts
prevalence: rare_old (2 submitters, 2021-10-04); externalIntel all negative (CIRCL, YARAify, MalwareBazaar)
PE analysis: entropy=4.64 (normal), no packers, highEntropyCode=false, likelyPacked=false
- Zero detections across 65 engines including 15 tier-1 vendors
- Clean behaviour profile: only ambient MITRE techniques, no offensive patterns
- Normal PE entropy and structure; no packer signatures
- No external intelligence hits (CIRCL, YARAify, MalwareBazaar)
- No malicious sandbox verdicts, contacted hosts, or dropped children
This file is safe. No malware indicators are present. If you downloaded it from an official source, you may use it with confidence.
0 detections across 73 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Rarely uploaded, but has been around for a while. Often niche legitimate software or old internal tooling; not a strong malware signal on its own.
Forensic fingerprint
- File name
- faangband.exe
- Size
- 2.14 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- bf44d81c557810933c50398904a16eb85b2b57787fcb9e257807cb35180c7f0d
- MD5
- 99144c82497f0ddd610eaea84dc23afd
- SHA-1
- b0303bcd0152dba706e0af71bdcfdce04617f1f9
- PE imphash
- 72a842fb6f05e5bb0d7d87651643103c
- First seen (VT)
- 10/4/2021, 11:57:10 AM
- Last analysis (VT)
- 11/8/2021, 11:23:17 AM
- First scan (MalwareTips)
- 6/29/2026, 8:19:32 PM
- Last scan (MalwareTips)
- 6/29/2026, 8:19:32 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.