CLEAN — psuser.dll
CLEAN — psuser.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 1 of 55 detection engines flagged it.
Identification
- SHA-256:
663753ac5286cdb44990a65c6612768a708b70c29425ea2399e69d2aba742547 - SHA-1:
5c6cb13d95bb393d210ff060ccee6c70fb1bbe02 - MD5:
ba9d0ae6eceae6549ce657bb7b8d505c - imphash:
9482728532237b5a4ac630c167e51669 - ssdeep:
6144:FbGPzu+Ut2dSyC/g5dqY7esfIAOSuCKlEkCj0:FybjUt2dS7/XwjKS - TLSH:
T1D7473B4916082B63D2768EA02DB0FF2E05F3B4F42AFD68181643D93E71A3CC75561AB5 - Submitted as: psuser.dll
- File type: pe · Size: 347992 bytes
- Verdict: clean (25/100)
Detections (1 of 55 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.microsoft.com
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
Embedded domains
- logging.cc
- www.microsoft.com
- crl.microsoft.com
- corp.microsoft.com
Registry keys
- HKLM\Software\Microsoft\Windows\CurrentVersion\MicrosoftEdge
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft
- HKLM\Software\Microsoft\EdgeUpdateDev\
- HKLM\Software\Policies\Microsoft\EdgeUpdate\
- HKLM\SOFTWARE\Policies\Microsoft\Copilot
File paths
- X:\:`:d:h:l:p:t:x:
- L:\:`:p:t:x:
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report