CLEAN — concrt140.dll
CLEAN — concrt140.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 2 of 55 detection engines flagged it.
Identification
- SHA-256:
8032b43bdd2f18ce7eb131e7cd542967081bea9490df08681bf805ce4f4d3aab - SHA-1:
7b32055335b37d734b1ab518dcae874352cd6d5c - MD5:
65f2e5a61f39996c4df8ae70723ab1f7 - imphash:
f938d80f72ce94d517fc5d8a6cfb6d50 - ssdeep:
6144:apyDXuXmqHSXuphaD1yZ8nOov2s1Scu82F8+nWzgdKQhmV:apyClp+eEu82Qz6a - TLSH:
T156473B4145233162ECF6E9A41C908DFEA492F47E2175888D6347CD8D91DBE33F6B21A2 - Submitted as: concrt140.dll
- File type: pe · Size: 344712 bytes
- Verdict: clean (25/100)
Detections (2 of 55 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: flagged
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
Embedded domains
- crl.microsoft.com
- www.microsoft.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report