CLEAN — psmachine.dll
CLEAN — psmachine.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 1 of 52 detection engines flagged it.
Identification
- SHA-256:
244ec7a3a808e9b5206451da5a307c18baa805ec192f560268da3427623da790 - SHA-1:
a86ca52156df5ce8dc6b0d865edf60443593c942 - MD5:
a9fe3bd5fd46bcaaee0dae268c1272c0 - imphash:
9482728532237b5a4ac630c167e51669 - ssdeep:
6144:ibGPz2+Ut2dSyC/g5dqY7esbIAOYPCKbEkCjX:iybbUt2dS7/jWqKEX - TLSH:
T171473B4916082B63D2768EA02DB0FF2E05F3B4F42AFD68181643D93E71A3CC75561AB5 - Submitted as: psmachine.dll
- File type: pe · Size: 347992 bytes
- Verdict: clean (25/100)
Detections (1 of 52 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.microsoft.com
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
Embedded domains
- logging.cc
- www.microsoft.com
- crl.microsoft.com
- corp.microsoft.com
Registry keys
- HKLM\Software\Microsoft\Windows\CurrentVersion\MicrosoftEdge
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft
- HKLM\Software\Microsoft\EdgeUpdateDev\
- HKLM\Software\Policies\Microsoft\EdgeUpdate\
- HKLM\SOFTWARE\Policies\Microsoft\Copilot
File paths
- X:\:`:d:h:l:p:t:x:
- L:\:`:p:t:x:
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report