VirusTotal Detection Labels: High Confidence, ML Score & More
By Glenn Lyvers · Updated · 7 min read
Some VirusTotal detections name a malware family. Others only tell you how confident an engine’s machine-learning model is that something is bad — labels like Malicious (high Confidence), Malicious.Moderate.ML.Score, W32.AIDetectMalware or PUP.HighConfidence. Those confidence labels are where most false positives come from, and reading them correctly is the difference between a five-minute appeal and a week of chasing the wrong problem.
Here is what each common one means, which engine produces it, and how much weight I give it when I’m deciding whether a site or file is actually infected.
Two kinds of detection
Every row on a VirusTotal report is one of two broad kinds, and the label usually tells you which.
Family or signature detections name something: Trojan.JS.Redirector, PHP.Webshell, JS:Includer-BGT. Someone wrote a rule for a known threat and your file matched it. When several of these agree, you have a real problem.
Generic or model detections describe a score or a category: “malicious”, “suspicious”, “unsafe”, “ML”, “AI”, “HighConfidence”, “Static”. A trained model looked at the shape of the file and made a judgement without matching anything specific. These engines catch brand-new malware that no signature exists for yet — and they also flag legitimate software that happens to look unusual.
Neither kind is worthless. But a report with one model-based hit out of ninety-odd engines is a very different situation from a report where five signature engines name the same family.
The labels people ask me about
| Label | Engine | What it means | Weight on its own |
|---|---|---|---|
Malicious (high Confidence) | Elastic | Elastic’s malware model is confident the file is bad. | Moderate — check the rest of the report |
Malicious (moderate Confidence) | Elastic | The same model, less sure. Frequently hits installers and packed tools. | Low |
Malicious.Moderate.ML.Score / Suspicious.Low.ML.Score | Trapmine | A machine-learning score band, not a family. | Low |
W32.AIDetectMalware | Bkav Pro | Bkav’s AI-based generic detection for Windows files. | Low — a frequent false positive |
PUP.HighConfidence | Babable, among others | “Potentially unwanted program”, with high model confidence. Often hits debug-signed Android apps. | Low |
Static AI – Suspicious PE | SentinelOne (Static ML) | Low-confidence pre-execution ML verdict on an executable. | Low |
Static AI – Malicious PE | SentinelOne (Static ML) | The same engine, high confidence. | Moderate |
Unsafe | Cylance / Arctic Wolf | The AI model classifies the file as unsafe. | Low to moderate |
| Acronis (Static ML) hit | Acronis | A static machine-learning verdict. | Low |
Suspicious / Phishing / Malicious (URL) | Gridinsoft | URL reputation verdicts of increasing severity. | Low to high, depending on verdict |
“Weight on its own” is my working rule of thumb, not a vendor statement. Any of these becomes serious the moment other engines — especially signature engines — agree with it. The SentinelOne pair has its own write-up in Static AI – Suspicious PE explained, and the Gridinsoft verdicts in Gridinsoft Suspicious vs Phishing vs Malicious.
How to read a report properly
When someone sends me a VirusTotal link, this is what I look at, in this order.
- File or URL? The URL tab reflects reputation lists and crawls of an address. The File tab reflects scans of the bytes. A URL flag on your domain and a file flag on your installer are different problems with different fixes.
- Which engines, not how many. Two model engines saying “suspicious” is weaker than one well-known signature engine naming a family.
- Do the names agree? If three engines each say something different and generic, that is noise. If they converge on the same family, that is signal.
- When was it last analysed? The date sits at the top of the report. A flag from three months ago may be stale, especially on a URL that has since been cleaned.
- Details, Relations and Behavior tabs. For files: signature status, packer, contacted domains. For URLs: redirects, the final landing URL, and files served. A redirect chain ending on a spam domain answers the question on its own.
What this means if the flag is on your website
For site owners, the relevant scan is almost always the URL one, and URL engines are mostly reputation lists rather than models. Model-based file labels reach your domain in two ways: you host a download that got flagged, or something you didn’t put there is being served. The second is a hacked site, full stop — attackers love using other people’s servers to host payloads for fake browser updates and ClickFix fake CAPTCHAs.
So before appealing anything, check the site. Load it on a phone, from a search result, in a private window — conditional malware hides from logged-in owners. Run my free site scanner and look for recently modified files. If you only ever check with a free scanner, read why free scanners miss backdoors before you conclude you’re clean.
Clearing a confidence-label false positive
If you’ve done the checks and you’re confident the verdict is wrong:
- Report to each engine separately. There is no central VirusTotal appeal; each vendor maintains its own verdicts. The routes differ — Elastic uses a form, Trapmine and Bkav take email. Current details are in my pages for Elastic, Trapmine, Bkav, Acronis, SentinelOne, Cylance / Arctic Wolf, Babable and Gridinsoft.
- Include the evidence once. VirusTotal permalink, SHA-256 for files, the exact label, where the file or URL comes from, and what you checked.
- Trigger a reanalysis afterwards. Old verdicts stay on the report until somebody clicks Reanalyze. Your visitors will keep screenshotting the stale version otherwise.
- For software you ship, sign it. Code signing with a certificate that has history is the most effective single thing against model-based false positives.
Want the warnings gone without the paperwork?
Clearing a flag means cleaning the cause and then working each vendor's own queue. I do both.
Not sure which? Ask me first — I’ll tell you honestly if you can handle it yourself.
When the label is right
Model engines are right more often than people hope. If the flagged item came from your web server and you don’t recognise it, if the URL scan shows a redirect you never set up, or if the same flag comes back days after being cleared, stop filing appeals. Those are signs of an active compromise, and a site that keeps getting reinfected has a backdoor nobody has found yet.
That’s the point where my malware removal service earns its fee: I find the infection and the way in, clean both, and then work through the vendor list with evidence that holds up — instead of you sending hopeful emails to a dozen security companies about a site that is still serving malware.
Common questions
What does Malicious (high Confidence) mean on VirusTotal?
It is Elastic's machine-learning verdict saying its model is confident the file is malicious. It does not name a malware family. On its own it is moderate evidence; if signature engines agree, treat it as real. If Elastic is alone and the file is a legitimate, signed program, it is likely a false positive worth reporting to Elastic.
What is Malicious.Moderate.ML.Score?
A Trapmine label. It reports a machine-learning score band rather than a specific threat. Moderate is a middle band; Suspicious.Low.ML.Score is lower. Trapmine hits on their own are weak evidence and a common source of false positives on legitimate installers and tools.
Is W32.AIDetectMalware a virus?
It is not the name of a specific virus. It is Bkav Pro's AI-based generic detection for Windows files, and it is one of the more frequent false-positive labels on VirusTotal. Check whether other engines agree and where the file came from before assuming infection.
What does PUP.HighConfidence mean?
PUP stands for potentially unwanted program, and HighConfidence is the model's confidence band. It is reported by smaller engines such as Babable and has been seen flagging debug-signed Android apps. It rarely indicates real malware on its own.
How many VirusTotal detections mean a file is really malicious?
There is no magic number. What matters is which engines flag it and whether they agree. One or two machine-learning engines with generic labels is weak evidence. Several established signature engines naming the same family is strong evidence, even if the total is small.
How do I get a VirusTotal detection removed?
VirusTotal does not remove verdicts itself. Report the false positive to each vendor that flags you through its own route, then use Reanalyze on the VirusTotal report once they have updated. Make sure the file or site is genuinely clean first, or the reports will be refused.
More than malware
Most people meet me in an emergency. It isn’t all I do.
I’ve been building and repairing systems since 1995. Whatever brought you here, there’s a good chance I can help with the rest of it too — and you’ll be dealing with the same person either way.
Hacked, but not WordPress?
Joomla, Drupal, Magento, Shopify, PrestaShop, Laravel, Node, IIS and plain HTML — cleaned the same way, priced the same way.
Take a look →Custom builds & AI systems
Plugins, custom applications, website chatbots and automation — built to do exactly what you need, maintained by the person who wrote them.
Take a look →Servers, speed, SEO & accessibility
Migrations, faster load times, technical SEO and accessibility fixes. Measured improvements, with the numbers to show you.
Take a look →Better web hosting
Fast, secure hosting with SSL and backups included at no extra charge. Clear pricing, no long-term contracts, no surprises.
Take a look →Classes & free tools
Rather learn to handle it yourself? I teach this, and I give away the tools I built for my own cleanups.
Take a look →Something else broken?
Half my work is untangling what someone else started, gave up on, or broke. Describe it in plain words and I’ll tell you honestly.
Take a look →Tell me what’s wrong. I’ll tell you what it takes.
No queue, no call centre, no sales pitch — one person who answers, quotes honestly, and does the work.