Scan result codes and explanations

These are the possible values returned for file scans. These values appear in scan_all_result_i and scan_all_result_a:

This article explains how to obtain the possible scan results: How can I run tests to see the different scan results on MetaDefender Core?

CodeScan resultRelationDescription
0No Threat DetectedMetascan engineNo threat detection or the file is empty.
1InfectedMetascan engineOne or more threats have been found.
2SuspiciousMetascan engineClassified as a potential threat without a specific identification.
3FailedMetascan engine / MetaDefender CoreThe scan failed due to the system or application error.
7AllowlistedMetaDefender CoreThe scan is skipped for good because one of file characteristics meet certain pre-configured conditions (based on hash / file type / file name etc.).
8BlocklistedMetaDefender CoreThe scan is skipped for bad because one of file characteristics meet certain pre-configured conditions (based on hash / file type / file name etc.).
9Exceeded Archive DepthArchive Extraction engineReached archive handling limit for archive depth level (Max recursion level).
10Not ScannedMetascan engine

The scan is not performed by Metascan engines either due to engine updates or other engine-specific failure reasons.

If Metascan is disabled, this will be the final result.

12Encrypted ArchiveArchive Extraction engineThe scan is not performed because the file type is detected as an encrypted (password-protected) archive but without having a correct password to decrypt.
13Exceeded Archive SizeArchive Extraction engineReached archive handling limit for archive size limit (Max total size of extracted files).
14Exceeded Archive File NumberArchive Extraction engineReached archive handling limit for archive file size limit (maximum number of files extracted).
15Password Protected DocumentArchive Extraction engineA document that is protected by a password [e.g., Office documents or PDFs that require a password to view its contents] but without having correct password to decrypt.
16Exceeded Archive TimeoutArchive Extraction engineThe archive extraction process on a certain archive file reached the given timeout value (Archive analysis timeout).
17MismatchFile type analysis engineThe file extension is not a part of the allowed extensions associated with the true file type.
18Potentially Vulnerable FileFile-Based Vulnerability AssessmentA Potentially Vulnerable File is a file associated with vulnerable components or applications identified by OPSWAT’s File-Based Vulnerability Assessment technology.
19CancelledMetaDefender CoreThe scan is canceled because the client terminated the connection or explicitly submitted a cancellation request.
20Sensitive Data FoundProactive DLPSensitive Data Found file detected by Proactive DLP refers to a file that contains information classified as sensitive according to predefined criteria set by the organization's data security policies.
21Yara Rule MatchedYARA engineFile content matched at least one of the pre-defined YARA rules.
22Potentially UnwantedMetascan enginePotentially unwanted application (PUA) classified by Metascan AV engines.
23Unsupported File TypeMetascan engineThe engine does not support scanning this file type. Certain Metascan AV engines such as AI-based engines only scan specific file types such as executable files or documents. https://docs.opswat.com/mdcore/metascan-engines/supported-file-type-for-ai-engines.
24Extraction FailedArchive Extraction engineArchive extraction failed due to some reasons which could be found under the archive processing section (e.g. insufficient disk space, file content data error, etc.).
26Suspicious Verdict by SandboxAdaptive SandboxWhen Adaptive Sandbox labels a file with a "Suspicious" verdict, it means that the file exhibited behaviors or characteristics that are commonly associated with malware or other malicious activity but are not conclusively harmful.
27Likely Malicious Verdict by SandboxAdaptive SandboxAdaptive Sandbox has identified behaviors or characteristics in the file that strongly suggest it is harmful, but the evidence is not entirely conclusive to label it as definitely malicious.
28Malicious Verdict by SandboxAdaptive SandboxAdaptive Sandbox has definitively determined that the file is harmful.
29Blocked Verdict by SandboxAdaptive SandboxThis indicates that the Adaptive Sandbox has determined that this file is dangerous and needs to be blocked by the Core. This verdict appears when a file is blocked but does not fall under any predefined verdicts mentioned above. The result also depends on the configuration of the Adaptive Sandbox.
30Blocked Verdict by Deep CDRDeep CDRIt indicates that a file was blocked based on a decision by the Deep CDR engine. This occurs when the user has enabled the file blocking feature in the Deep CDR configuration. For example, users can enable the option to block files if Office documents contain hyperlinks, embedded objects, QR codes, etc.
31Global Timeout ExceededMetaDefender CoreThe global processing timeout takes precedence over any engine timeout and is disabled by default. Certain scans may be terminated when enabled if they exceed the pre-defined global processing timeout.
32Vulnerable Verdict by SBOMSBOMThis indicates that software components contain known vulnerabilities that could potentially be exploited and therefore may require attention or remediation. Please note that this case may also include a License Risk Found. You should check the SBOM details for more information.
33Non-vulnerable Verdict by SBOMSBOMThis indicates that software components have been evaluated and found to be free of security weaknesses based on the current vulnerability data.
34Blocked Verdict by SBOMSBOMThis indicates that the SBOM has determined that software components have security weaknesses or risks and need to be blocked by the Core. This verdict appears when the item is blocked but does not fall under any of the predefined verdicts. The result also depends on the configuration for the SBOM.
38Known BadReputation engine

The Reputation engine found the file as a known (recognizable) harmful one.

For more details, the Reputation Engine cross-references file hashes with a database of known malicious files and utilizes advanced analysis to quickly address false positives. For further information, please refer to this link: Metadefender Core v5.9.0: Powerful New Engines for Proactive Threat Detection. Please note that the Reputation Engine is not enabled by default.

39Known GoodReputation engine

The Reputation engine found the file as a known good one.

For more details, the Reputation Engine cross-references file hashes with a database of known malicious files and utilizes advanced analysis to quickly address false positives. For further information, please refer to this link: Metadefender Core v5.9.0: Powerful New Engines for Proactive Threat Detection. Please note that the Reputation Engine is not enabled by default.

40UnknownReputation engineReputation engine does not come to final conclusion to determine if the file is harmful or not (inconclusive).
41Allowed Verdict by COOCountry of OriginBased on the current configuration, the Country of Origin engine indicates that the file comes from an allowed source.
42Blocked Verdict by COOCountry of OriginBased on the current configuration, the Country of Origin engine indicates that the file comes from an unallowed source.
45License Risk Verdict by SBOMSBOMThis indicates that the software components present one or more license risks. Please note that this case may have Vulnerabilities Found, but they do not meet the pre-configured threshold to impact the decision to block the file. You should check the SBOM details for more information.
46Blocked Verdict by File TypeFile type analysis engineOther scenarios, apart from Mismatch, where a file is flagged as blocked by the FileType engine. This is dependent on the specific configuration of the FileType engine.
47Multipart Upload Timed OutMetaDefender CoreCases where multipart uploading is used to upload processed files to MetaDefender Core, and this upload action times out.
48SanitizedDeep CDRWhen the Block files if sanitized successfully setting is enabled in the Deep CDR workflow settings, and the file is successfully sanitized, the file will be blocked. This verdict has the lowest priority compared to other block verdicts.
49InSights Indicator MatchesInSights Threat IntelligenceThis indicates that InSights Threat Intelligence has detected malicious domains and IP addresses in the file.
50No Indicator Matches in InSightsInSights Threat IntelligenceThis indicates that InSights Threat Intelligence has detected no malicious domains and IP addresses in the file.
51Exceeded Limited Sandbox File SizeAdaptive SandboxWhen the Block files that exceed the file size threshold setting is enabled in the Adaptive Sandbox workflow settings, the file will be blocked if its size exceeds the configured threshold.
52Blocked Verdict by Archive ExtractionArchive Extraction engineThe file has been blocked based on the recommendation from the Archive Extraction engine. The reason for the block is detailed in the Archive Extraction scan result.
53Blocked Verdict by Archive CompressionArchive Compression engineThe file has been blocked based on the recommendation from the Archive Compression engine. The reason for the block is detailed in the Archive Compression scan result.
54Sandbox Execution Limit ReachedAdaptive SandboxWhen the Block files if execution limit reached setting is enabled in the Adaptive Sandbox workflow settings, the file will be blocked if the license execution limit is reached.
255In ProgressMetaDefender CoreThe scan is still in progress, not yet finished.
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard