CLEAN — ProtobufLite.dll
CLEAN — ProtobufLite.dll is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (21/100). 0 of 55 detection engines flagged it.
Identification
- SHA-256:
eaa699671e0a071456be13635ac0d8947e0ec3166148b615df30ecb25d6eaade - SHA-1:
5d135c42795830646651cb896f003d4f182cf9bf - MD5:
bd2bfea485f6e735a116bfae8434047e - imphash:
d06ea05df0f09a6ca671f5b9e35fc497 - ssdeep:
12288:BQ+HkBKub6C+FSinPEHzZupc2xge4NcD:bHWb6C+IiPEHzZuKBef - TLSH:
T1D44E7C32422F1B70F1BB544C7DEE699C916FA828F06E08491926ECD9A94CF27FF11185 - Submitted as: ProtobufLite.dll
- File type: pe · Size: 649136 bytes
- Verdict: clean (21/100)
Detections (0 of 55 engines)
No engine flagged this sample.
Why this verdict
The clean score of 21/100 is the fusion of 1 weighted signal:
- Embedded network infrastructure: http://pki.eset.com/crt/csca2020.crt05, http://pki.eset.com/crl/csca2020.crl0I, http://pki.eset.com/csp0 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.digicert.com/CPS0
- http://pki.eset.com/crt/csca2020.crt05
- http://pki.eset.com/crl/csca2020.crl0I
- http://pki.eset.com/csp0
- http://pki.eset.com/crt/rootca2020.crt07
- http://pki.eset.com/crl/rootca2020.crl0
- http://pki.eset.com/crt/tsca2020.crt05
- http://pki.eset.com/crl/tsca2020.crl0
Embedded domains
- type.googleapis.com
- type.googleprod.com
- cord.cc
- mutex.cc
- cacerts.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- crl.microsoft.com
- pki.eset.com
File paths
- D:\bbw\_\WindowsSecurity-Compile\_\src\Shared\ThirdParty\protobuf\third_party\abseil-cpp\absl\base\internal\low_level_alloc.cc
- D:\bbw\_\WindowsSecurity-Compile\_\src\Shared\ThirdParty\protobuf\third_party\abseil-cpp\absl\strings\cord.cc
- D:\bbw\_\WindowsSecurity-Compile\_\src\Shared\ThirdParty\protobuf\third_party\abseil-cpp\absl\strings\internal\cord_rep_btree.cc
- D:\bbw\_\WindowsSecurity-Compile\_\src\Shared\ThirdParty\protobuf\third_party\abseil-cpp\absl\synchronization\internal\win32_waiter.cc
- D:\bbw\_\WindowsSecurity-Compile\_\src\Shared\ThirdParty\protobuf\third_party\abseil-cpp\absl\synchronization\mutex.cc
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report