SUSPICIOUS — glib-2.0-0.dll
SUSPICIOUS — glib-2.0-0.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (40/100), attributed to the AntiDebug family. 1 of 55 detection engines flagged it.
Identification
- SHA-256:
cbdc399946efc0c477a93268f11c71cd770b0f49fe627647ba77e06acd0e0998 - SHA-1:
b43dec7f94275051ce962bd057cd61d80f997c4f - MD5:
f57f9e16505e1349f6e23373677ba391 - imphash:
8166f56e75cd3252600a5b5371599cdf - ssdeep:
24576:XW73T47naePi5DRnmyymxhRcsj9al8vafi978nM8wEqBGQafehQ6vdJItR4nea0:XWTT47na8i5lnmLmxhRcsjc2OW8M8wE - TLSH:
T175565A364A4329E2E8FA9C089C514A9C8027F4FC602DDC496167DC0F45A6E33A5FDD6B - Submitted as: glib-2.0-0.dll
- File type: pe · Size: 1354752 bytes
- Verdict: suspicious (40/100) · Family: AntiDebug
Detections (1 of 55 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
Why this verdict
The suspicious score of 40/100 is the fusion of 2 weighted signals:
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://freedesktop.org, http://www.freedesktop.org/standards/desktop-bookmarks, http://www.freedesktop.org/standards/shared-mime-info - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://freedesktop.org
- http://www.freedesktop.org/standards/desktop-bookmarks
- http://www.freedesktop.org/standards/shared-mime-info
- https://microsoft.com/windows/
- https://docs.microsoft.com/
- https://support.microsoft.com/
- https://support.microsoft.com/contactus/
- https://privacy.microsoft.com/
Embedded domains
- freedesktop.org
- www.freedesktop.org
- microsoft.com
- docs.microsoft.com
- support.microsoft.com
- privacy.microsoft.com
Embedded IP addresses
- 5.6.7.8
- 9.10.11.12
- 13.14.15.16
- 17.18.19.20
File paths
- F:\vcpkg-2026.03.18\buildtrees\glib\src\glib-2-78518e5b8a.clean\glib\gutilsprivate.h
- F:\vcpkg-2026.03.18\buildtrees\glib\src\glib-2-78518e5b8a.clean\glib\gthread-win32.c
- F:\vcpkg-2026.03.18\buildtrees\glib\x64-windows-rel\glib\glib-2.0-0.pdb
More AntiDebug samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report