Static AI – Suspicious PE: The SentinelOne Detection Explained
By Glenn Lyvers · Updated · 7 min read
Static AI – Suspicious PE is the label SentinelOne’s machine-learning engine puts on a Windows executable it considers possibly malicious. It does not name a virus, and “Suspicious” is the engine’s low-confidence verdict — the high-confidence one says “Malicious” instead. On VirusTotal the row is labelled SentinelOne (Static ML), and a lone hit from it on an otherwise clean report is one of the most common false positives I see.
That does not mean you can ignore it. It means you have to check, and the check is different depending on whether the flagged thing is a file you distribute or a website you run. Here is how to read the label and what to do about it.
What each part of the label means
SentinelOne added its Static AI prevention engine to VirusTotal in 2022. It is the same pre-execution engine their endpoint product uses: it looks at the structure of a file before anything runs — headers, sections, imports, entropy, packing, resources, signatures — and compares that shape against what its model learned from very large sets of known-good and known-bad files. It never watches the file behave. That is what “static” means.
The label itself breaks into three pieces:
| Part | Meaning |
|---|---|
Static AI | The verdict came from the machine-learning model, not from a signature written for a known malware family. |
Suspicious / Malicious | The model’s confidence. Suspicious is the lower band; Malicious is the one it is sure about. |
PE / Archive | What was scanned. PE is a Portable Executable — .exe, .dll, .scr, installers. Archive is a .zip, .rar or similar container. |
So Static AI – Suspicious Archive is the same low-confidence verdict applied to a compressed file, and Static AI – Malicious PE is the engine telling you it is fairly sure. The two deserve very different amounts of worry. If you are seeing other confidence-style labels alongside it, my guide to VirusTotal confidence labels covers the Elastic, Trapmine, Bkav and Acronis equivalents.
Why clean files trip it
A model that judges files by their shape will flag legitimate software that happens to share traits with malware. The usual suspects:
- Packed or compressed executables. UPX and commercial protectors raise entropy and hide imports — exactly what malware authors do.
- Unsigned builds. No Authenticode signature, or a signature from a certificate nobody has seen before.
- Script-to-exe wrappers. AutoHotkey, PyInstaller, Nuitka, Electron and similar bundlers produce executables that look alike whether the script inside is a calculator or a stealer.
- Brand-new binaries. A freshly compiled installer with no history anywhere has nothing to vouch for it.
- Self-extracting archives and installers that download further components.
If your file matches one or more of those and SentinelOne is the only engine (or one of two or three ML-only engines) flagging it, you are very probably looking at a false positive. If signature-based engines agree with it — Kaspersky, ESET, Microsoft, Bitdefender naming an actual family — stop and treat it as real.
Why a website owner is seeing this at all
Most people searching this label are not malware analysts. They run a site, and something on it got scanned. Three situations cover nearly every case I get asked about:
You host a download. Your software, a plugin bundle, a PDF-to-exe brochure, a client installer. If that file is flagged, VirusTotal’s URL report for the download link can inherit the verdict, and some security products start warning on the whole domain.
Something you didn’t upload is being served. This is the one that matters. Hacked sites are routinely used to host payloads — fake browser updates, “invoice.zip” files, cracked-software lures. If a PE or archive you have never seen is sitting in /wp-content/uploads/ or a random folder, the detection is almost certainly correct. My guides on fake browser update malware and PHP files in the uploads folder show where these hide.
A visitor or client scanned a file you sent. Their endpoint runs SentinelOne, the file was quarantined, and now they think you are infected. Here the question is whether the file came from your machine clean — which is worth confirming, because an infostealer on a developer machine can tamper with builds too.
How to tell a real detection from a false positive
Work through this in order and write down what you find; you will need it for the report anyway.
- Get the hash. Run
sha256sum file.exe(orGet-FileHashon Windows) and search it on VirusTotal. Look at the whole report, not just the red rows. - Count the kind of engines, not just the number. Three ML engines saying “suspicious” is weaker evidence than one signature engine naming a family.
- Check provenance. Did you build it, from which source, on which machine? Does the hash match the one your build pipeline produced? A mismatch is a red flag no appeal will fix.
- Check the Behavior tab. If VirusTotal’s sandboxes show it contacting odd domains, dropping files in startup folders or injecting into other processes, the model was right.
- If it came from your website, check the website. Timestamps, unknown files, modified core files. Run a quick pass with my free site scanner, then look deeper using what a hacked site actually looks like.
If the file turns out to be a payload somebody planted on your server, deleting it is not the fix. Whatever uploaded it is still there, and the next file will be along shortly. That is a cleanup job, not an appeal.
Getting it cleared
For a genuine false positive, SentinelOne handles VirusTotal-engine disputes by email, and customers of their endpoint product use a support ticket instead. The exact address, what to include and what to expect are in my SentinelOne false positive removal steps. In short: send the VirusTotal permalink, the SHA-256, the exact label, where the file comes from, and why you are confident it is legitimate. One clear submission beats five vague ones.
Two things make a real difference to how fast it goes. First, sign your executables. A valid code-signing certificate with some history is the single strongest signal against a static ML verdict, and it prevents the next build being flagged too. Second, submit to every engine that flags you, not just SentinelOne. ML-only engines tend to travel in packs; the same file often shows up in Cylance / Arctic Wolf, Acronis (Static ML) and Trapmine at the same time, and each keeps its own list. The vendor removal directory has every route in one place.
After a vendor confirms the change, ask VirusTotal to reanalyze the file so the report reflects the new verdict. Old results stay on the page until somebody triggers a rescan.
Want the warnings gone without the paperwork?
Clearing a flag means cleaning the cause and then working each vendor's own queue. I do both.
Not sure which? Ask me first — I’ll tell you honestly if you can handle it yourself.
The Suspicious Archive variant
Static AI – Suspicious Archive shows up most often on .zip files that contain an executable, a script, or a shortcut (.lnk) — the same shapes phishing kits use. Password-protected archives score badly because nothing inside can be inspected. If you distribute software as a zip, consider shipping a signed installer instead, or at least keep the archive unencrypted so engines can see the signed file inside.
If the archive turned up on your website and you didn’t put it there, treat it exactly like the PE case: it is a lure, and the site is compromised. Archives sitting next to phishing pages are a very common find.
When to stop and hand it over
If the flagged file is yours, clean, and signed, this is a ten-minute email and a few days’ wait. You don’t need me for that. If the file is something you don’t recognise, if it was served from your domain, or if the detection keeps coming back after vendors clear it, the problem is on the server rather than in SentinelOne’s model — and that is where my malware removal service comes in. I find what planted it, remove it and the way back in, and then file the delisting requests with the evidence to back them.
Common questions
What does Static AI - Suspicious PE mean?
It is SentinelOne's machine-learning verdict for a Windows executable that looks possibly malicious based on its structure alone. Suspicious is the engine's lower-confidence band; Malicious is the higher one. It does not identify a specific virus, and on its own it is a common false positive for packed, unsigned or newly compiled software.
Is SentinelOne (Static ML) on VirusTotal reliable?
It is a genuine engine from a major endpoint vendor, but it judges files before they run, so it has a higher false-positive rate on unusual legitimate software than signature engines do. Weigh it alongside the rest of the report. A lone Static ML hit is weak evidence; agreement from signature engines naming a family is strong evidence.
What is the difference between Suspicious PE and Malicious PE?
Confidence. Both come from the same static model. Suspicious PE means the file shares traits with malware but the model is not sure; Malicious PE means it is. A Malicious PE verdict, especially with other engines agreeing, should be treated as a real infection until you have proven otherwise.
How do I report a SentinelOne false positive?
VirusTotal-engine disputes go to SentinelOne by email with the VirusTotal link, the SHA-256 hash, the exact label and evidence that the file is legitimate. SentinelOne endpoint customers raise a support ticket instead. Once they confirm, ask VirusTotal to reanalyze the file so the report updates.
Why is my website flagged if SentinelOne only scans files?
Because a file served from your domain was scanned, and URL reputation often inherits file verdicts. Either you host a download the model dislikes, or someone planted a payload on your server. The second case is common on hacked sites, and deleting the file alone will not stop it returning.
What does Static AI - Suspicious Archive mean?
The same low-confidence machine-learning verdict applied to a compressed file such as a zip. It is often triggered by archives that contain executables, scripts or shortcut files, and by password-protected archives the engine cannot look inside.
More than malware
Most people meet me in an emergency. It isn’t all I do.
I’ve been building and repairing systems since 1995. Whatever brought you here, there’s a good chance I can help with the rest of it too — and you’ll be dealing with the same person either way.
Hacked, but not WordPress?
Joomla, Drupal, Magento, Shopify, PrestaShop, Laravel, Node, IIS and plain HTML — cleaned the same way, priced the same way.
Take a look →Custom builds & AI systems
Plugins, custom applications, website chatbots and automation — built to do exactly what you need, maintained by the person who wrote them.
Take a look →Servers, speed, SEO & accessibility
Migrations, faster load times, technical SEO and accessibility fixes. Measured improvements, with the numbers to show you.
Take a look →Better web hosting
Fast, secure hosting with SSL and backups included at no extra charge. Clear pricing, no long-term contracts, no surprises.
Take a look →Classes & free tools
Rather learn to handle it yourself? I teach this, and I give away the tools I built for my own cleanups.
Take a look →Something else broken?
Half my work is untangling what someone else started, gave up on, or broke. Describe it in plain words and I’ll tell you honestly.
Take a look →Tell me what’s wrong. I’ll tell you what it takes.
No queue, no call centre, no sales pitch — one person who answers, quotes honestly, and does the work.