VirusTotal Detection Labels: High Confidence, ML Score & More

By · Updated · 7 min read

Some VirusTotal detections name a malware family. Others only tell you how confident an engine’s machine-learning model is that something is bad — labels like Malicious (high Confidence), Malicious.Moderate.ML.Score, W32.AIDetectMalware or PUP.HighConfidence. Those confidence labels are where most false positives come from, and reading them correctly is the difference between a five-minute appeal and a week of chasing the wrong problem.

Here is what each common one means, which engine produces it, and how much weight I give it when I’m deciding whether a site or file is actually infected.

Two kinds of detection

Every row on a VirusTotal report is one of two broad kinds, and the label usually tells you which.

Family or signature detections name something: Trojan.JS.Redirector, PHP.Webshell, JS:Includer-BGT. Someone wrote a rule for a known threat and your file matched it. When several of these agree, you have a real problem.

Generic or model detections describe a score or a category: “malicious”, “suspicious”, “unsafe”, “ML”, “AI”, “HighConfidence”, “Static”. A trained model looked at the shape of the file and made a judgement without matching anything specific. These engines catch brand-new malware that no signature exists for yet — and they also flag legitimate software that happens to look unusual.

Neither kind is worthless. But a report with one model-based hit out of ninety-odd engines is a very different situation from a report where five signature engines name the same family.

The labels people ask me about

LabelEngineWhat it meansWeight on its own
Malicious (high Confidence)ElasticElastic’s malware model is confident the file is bad.Moderate — check the rest of the report
Malicious (moderate Confidence)ElasticThe same model, less sure. Frequently hits installers and packed tools.Low
Malicious.Moderate.ML.Score / Suspicious.Low.ML.ScoreTrapmineA machine-learning score band, not a family.Low
W32.AIDetectMalwareBkav ProBkav’s AI-based generic detection for Windows files.Low — a frequent false positive
PUP.HighConfidenceBabable, among others“Potentially unwanted program”, with high model confidence. Often hits debug-signed Android apps.Low
Static AI – Suspicious PESentinelOne (Static ML)Low-confidence pre-execution ML verdict on an executable.Low
Static AI – Malicious PESentinelOne (Static ML)The same engine, high confidence.Moderate
UnsafeCylance / Arctic WolfThe AI model classifies the file as unsafe.Low to moderate
Acronis (Static ML) hitAcronisA static machine-learning verdict.Low
Suspicious / Phishing / Malicious (URL)GridinsoftURL reputation verdicts of increasing severity.Low to high, depending on verdict

“Weight on its own” is my working rule of thumb, not a vendor statement. Any of these becomes serious the moment other engines — especially signature engines — agree with it. The SentinelOne pair has its own write-up in Static AI – Suspicious PE explained, and the Gridinsoft verdicts in Gridinsoft Suspicious vs Phishing vs Malicious.

How to read a report properly

When someone sends me a VirusTotal link, this is what I look at, in this order.

  1. File or URL? The URL tab reflects reputation lists and crawls of an address. The File tab reflects scans of the bytes. A URL flag on your domain and a file flag on your installer are different problems with different fixes.
  2. Which engines, not how many. Two model engines saying “suspicious” is weaker than one well-known signature engine naming a family.
  3. Do the names agree? If three engines each say something different and generic, that is noise. If they converge on the same family, that is signal.
  4. When was it last analysed? The date sits at the top of the report. A flag from three months ago may be stale, especially on a URL that has since been cleaned.
  5. Details, Relations and Behavior tabs. For files: signature status, packer, contacted domains. For URLs: redirects, the final landing URL, and files served. A redirect chain ending on a spam domain answers the question on its own.

What this means if the flag is on your website

For site owners, the relevant scan is almost always the URL one, and URL engines are mostly reputation lists rather than models. Model-based file labels reach your domain in two ways: you host a download that got flagged, or something you didn’t put there is being served. The second is a hacked site, full stop — attackers love using other people’s servers to host payloads for fake browser updates and ClickFix fake CAPTCHAs.

So before appealing anything, check the site. Load it on a phone, from a search result, in a private window — conditional malware hides from logged-in owners. Run my free site scanner and look for recently modified files. If you only ever check with a free scanner, read why free scanners miss backdoors before you conclude you’re clean.

Clearing a confidence-label false positive

If you’ve done the checks and you’re confident the verdict is wrong:

  • Report to each engine separately. There is no central VirusTotal appeal; each vendor maintains its own verdicts. The routes differ — Elastic uses a form, Trapmine and Bkav take email. Current details are in my pages for Elastic, Trapmine, Bkav, Acronis, SentinelOne, Cylance / Arctic Wolf, Babable and Gridinsoft.
  • Include the evidence once. VirusTotal permalink, SHA-256 for files, the exact label, where the file or URL comes from, and what you checked.
  • Trigger a reanalysis afterwards. Old verdicts stay on the report until somebody clicks Reanalyze. Your visitors will keep screenshotting the stale version otherwise.
  • For software you ship, sign it. Code signing with a certificate that has history is the most effective single thing against model-based false positives.

When the label is right

Model engines are right more often than people hope. If the flagged item came from your web server and you don’t recognise it, if the URL scan shows a redirect you never set up, or if the same flag comes back days after being cleared, stop filing appeals. Those are signs of an active compromise, and a site that keeps getting reinfected has a backdoor nobody has found yet.

That’s the point where my malware removal service earns its fee: I find the infection and the way in, clean both, and then work through the vendor list with evidence that holds up — instead of you sending hopeful emails to a dozen security companies about a site that is still serving malware.

Common questions

What does Malicious (high Confidence) mean on VirusTotal?

It is Elastic's machine-learning verdict saying its model is confident the file is malicious. It does not name a malware family. On its own it is moderate evidence; if signature engines agree, treat it as real. If Elastic is alone and the file is a legitimate, signed program, it is likely a false positive worth reporting to Elastic.

What is Malicious.Moderate.ML.Score?

A Trapmine label. It reports a machine-learning score band rather than a specific threat. Moderate is a middle band; Suspicious.Low.ML.Score is lower. Trapmine hits on their own are weak evidence and a common source of false positives on legitimate installers and tools.

Is W32.AIDetectMalware a virus?

It is not the name of a specific virus. It is Bkav Pro's AI-based generic detection for Windows files, and it is one of the more frequent false-positive labels on VirusTotal. Check whether other engines agree and where the file came from before assuming infection.

What does PUP.HighConfidence mean?

PUP stands for potentially unwanted program, and HighConfidence is the model's confidence band. It is reported by smaller engines such as Babable and has been seen flagging debug-signed Android apps. It rarely indicates real malware on its own.

How many VirusTotal detections mean a file is really malicious?

There is no magic number. What matters is which engines flag it and whether they agree. One or two machine-learning engines with generic labels is weak evidence. Several established signature engines naming the same family is strong evidence, even if the total is small.

How do I get a VirusTotal detection removed?

VirusTotal does not remove verdicts itself. Report the false positive to each vendor that flags you through its own route, then use Reanalyze on the VirusTotal report once they have updated. Make sure the file or site is genuinely clean first, or the reports will be refused.