CLEAN — ucrtbase.dll
CLEAN — ucrtbase.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 2 of 55 detection engines flagged it.
Identification
- SHA-256:
4c5b8e529854cedfa8f46cd6906952400cdbbf25efc4cf37dda2c42d8e96ddcb - SHA-1:
1062942b1bdfc8d7c8a941c152df69216010d780 - MD5:
ed82e9c6c4f7a475d7fd6ebabf3fab2a - imphash:
57abd1fde351971a01e912069e11b44c - ssdeep:
24576:WhEbImsFPf/JtGlA3wubyZ9dgruOqy38V89DamxvSZX0ypkXvE:WhgImsFPfRklAVyBgr599hX8 - TLSH:
T1A6527C1642173261F07AB594ACE04EECE862F57CB075490DA707EC9EA0CAD73A3F1295 - Submitted as: ucrtbase.dll
- File type: pe · Size: 997056 bytes
- Verdict: clean (25/100)
Detections (2 of 55 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: flagged
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://www.microsoft.com/windows0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_2010-07-06.crt0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
Embedded domains
- crl.microsoft.com
- www.microsoft.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report