File verdict·Decided by the MT AI Engine
Our call

Suspicious

Single tier-1 detection conflicts with 17 silent peer engines and community no-threat verdict; runtime behaviour clean.

Trust score52Caution
MT AI confidence · 62%
Audirvana 3.5.35 macOS.dmg
12.1 MB
c14ab1d2d1ed9c3a196c1bd5ee74
Antivirus engines
2 of 76 flagged
Code signing
Unsigned
Age
First seen 6y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

62%Confidence
Moderate
Reasoning

The file presents a mixed-signal case. Ikarus (tier-1) names a specific family, 'Trojan.OSX.Spy', which normally carries weight. However, this detection stands alone: 17 peer tier-1 engines (Kaspersky, BitDefender, ESET, Avast, Fortinet, etc.) are silent, and Google's generic 'Detected' label provides no family corroboration. The community FileScan.IO analysis reports NO_THREAT with 100% confidence, noting only benign apple.com contact. Behaviour analysis reveals zero offensive MITRE techniques, zero malicious sandbox verdicts, and zero malicious dropped children. The file is old (May 2020) and unsigned, but the complete absence of malicious runtime indicators contradicts a malware classification. The tier-1 disagreement and community verdict suggest Ikarus may be flagging a false positive or an old sample with outdated signatures.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. Ikarus (tier1) flags 'Trojan.OSX.Spy' but 17/18 other tier-1 engines silent (Kaspersky, BitDefender, ESET, Avast, Fortinet, etc.)

  2. Google (tier2) generic 'Detected' label; no named family; 59/61 engines undetected

  3. FileScan.IO community verdict: NO_THREAT confidence 100/100; contacted only apple.com

  4. Behaviour: 0 offensive MITRE, 0 malicious sandbox verdicts, 0 malicious dropped children, no malicious host contact

  5. File age 2211 days (May 2020); filename matches legitimate Audirvana audio player product; medium prevalence (15 submitters)

Points in its favour
  • 17 peer tier-1 engines silent (Kaspersky, BitDefender, ESET, Avast, Fortinet, etc.)
  • Community FileScan.IO analysis: NO_THREAT confidence 100/100
  • Zero offensive MITRE techniques in behaviour analysis
  • Zero malicious sandbox verdicts
  • Filename matches legitimate Audirvana audio player product
Points against
  • Single tier-1 engine (Ikarus) flags a named family (Trojan.OSX.Spy)
  • File is unsigned
  • File is old (May 2020) with potentially outdated detection signatures
  • Generic tier-2 detection (Google) provides no family corroboration
What to do

The conflicting tier-1 signals and strong community no-threat verdict suggest this is likely a false positive. Verify the file source independently; if obtained from the official Audirvana website or a trusted distributor, it is safe to use.

Dropped payload

Files this sample writes at runtime

This file drops 2 children at runtime. None are currently flagged malicious in our cache.

2 unseen
  • 472d9a36d30d876b929045ab75Never scanned
    never seen before
  • 45f8b43453cb19232902c26817Never scanned
    never seen before
No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

2 detections across 76 engines

2 malicious0 suspicious74 clean
Tier-118 engines
1flag
Top commercial AVs (low FP rate)
Tier-240 engines
1flag
Mainstream engines with mixed FP rates
Low-trust18 engines
0flag
Heuristic / generic-AI engines (high FP rate)
Google
malicious
Detected
Ikarus
malicious
Trojan.OSX.Spy
Hash c14ab1d2d1ed… cross-referenced against 76 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
15
Moderate upload volume.
Total submissions
16
Includes repeat uploads by the same source.
First seen by VT
6y ago
May 24, 2020
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
5/24/2020, 5:05:51 AM
First seen (MalwareBazaar)
Last analysis (VT)
10/23/2022, 3:35:58 AM
Scanned here
6/13/2026, 2:59:51 AM
File name
Audirvana 3.5.35 macOS.dmg
Size
12.14 MB
MIME type
(unknown)
Detected type
Macintosh Disk Image
SHA-256
c14ab1d2d1ed9c3a19b708dab560e8eca03aca3b18098fe424a76e6c1bd5ee74
MD5
f27d6138c4356b9a557b44aeb56c2922
SHA-1
77e63601e78460998ec36cbf22632a91b940d2ae
First seen (VT)
5/24/2020, 5:05:51 AM
Last analysis (VT)
10/23/2022, 3:35:58 AM
First scan (MalwareTips)
6/13/2026, 2:59:51 AM
Last scan (MalwareTips)
6/13/2026, 2:59:51 AM
Behavior tags
dmg
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.