SUSPICIOUS — da29455a64858fda773319c32c0a6cd40edbe8042ed005aa2befb8a4f0fb0522.dll
SUSPICIOUS — da29455a64858fda773319c32c0a6cd40edbe8042ed005aa2befb8a4f0fb0522.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
da29455a64858fda773319c32c0a6cd40edbe8042ed005aa2befb8a4f0fb0522 - SHA-1:
48038f060a5042ff44a2d9a9be46368ecc8436fd - MD5:
94216eb90ca53fbb175f0ee6adbfb663 - imphash:
dae02f32a21e03ce65412f6e56942daa - ssdeep:
24576:VDhFj+Ifz3zvnXj/zXzvAAkGz8mvgtX79S+2bfh+RfmT01krTFiH4SqfKPTsUTH:VDhJkGYYpT0+TFiH7efP - TLSH:
T19158BFD74206B260E9F0F960B86042DC7023F059F2B60CCC5687E56D62E9DEFB1B6256 - Submitted as: da29455a64858fda773319c32c0a6cd40edbe8042ed005aa2befb8a4f0fb0522.dll
- File type: pe · Size: 1729024 bytes
- Verdict: suspicious (44/100)
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (3 of 55 engines)
- capa (capabilities): capability:execution/powershell
- Microsoft Defender: flagged
- Kaspersky (KVRT): not-a-virus:HEUR:RemoteAdmin.MSIL.ConnectWise.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 44/100 is the fusion of 2 weighted signals:
- execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- X:\:b:f:l:p:
- X:\:`:d:h:l:p:t:x:
- T:\:d:l:t:
- T:\:d:
- C:\builds\cc\cwcontrol\Product\Windows\obj\Release\net20\ScreenConnect.Windows.pdb
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report