Is POCO safe?
No engine detected the signed CD PROJEKT DLL, and its established prevalence, uneventful sandbox result, and signer-matched history strongly support legitimate software.
All 74 antivirus engines returned no detection, including 17 tier-1 engines, and the DLL carries a verified CD PROJEKT S.A. signature. It has circulated through 297 sources, produced no offensive behavior in one sandbox, and matches five prior benign signer-based decisions.
24117db72d127900e4…c346510c87ec1aRecommended next actions
Before opening
Open it only when its sender or download source is one you independently trust.
If you already opened it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 74 antivirus engines returned no detection, including 17 tier-1 engines, and the DLL carries a verified CD PROJEKT S.A. signature. It has circulated through 297 sources, produced no offensive behavior in one sandbox, and matches five prior benign signer-based decisions.
The strongest evidence is complete detection silence: 0 of 74 engines flagged the file, with all 17 participating tier-1 engines reporting no detection. Its signature verifies to CD PROJEKT S.A., and there is no detected conflict between the claimed brand and signer. The sample is established software seen from 297 sources across 336 submissions rather than a rare recent arrival. One completed sandbox produced no malicious verdict or offensive-only technique, although its ambient activity included system inspection and DLL execution. Five signer-matched files received prior benign decisions, and neither static PE analysis nor researcher intelligence supplied a corroborating malware indicator.
What We Detected
None of the 74 antivirus engines flagged this Win32 DLL. The file has a verified signature from CD PROJEKT S.A., no detected brand mismatch, and an established history covering 297 sources and 336 submissions.
Threat Behavior
One completed sandbox observed DLL loading, system-information checks, obfuscation-related indicators, and environment-awareness techniques, but none were categorized as offensive-only behavior and the sandbox issued no malicious verdict. No persistence indicators, dropped file hashes, or network contacts were recorded. A complete contacted-host reputation cross-check was not available, though there were no observed hosts to inspect.
What To Do Now
The evidence is consistent with a legitimate CD PROJEKT software component. Keep endpoint protection enabled and obtain the DLL through the official game installation or update channel; investigate further if its location, signature, or surrounding files differ from the expected installation.
Where this verdict could be wrong2 caveats
- signing.signerStats.totalSamples=1 is too small to establish a strong independent publisher history, although five signer-matched prior decisions provide additional support.
- contactedHosts=null, so no completed host-reputation cross-check is available; the sandbox recorded no contacted domains, IPs, or URLs.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 engines reported a malicious or suspicious result.
- All 17 tier-1 engines reported no detection.
- The signature verifies to 'CD PROJEKT S.A.' with no brand mismatch.
- The file is established across 297 sources and 336 submissions.
- Five signer-matched historical samples received prior 'safe' decisions.
- The sandbox recorded environment-awareness technique T1497.
- The sandbox recorded obfuscated-files technique T1027 and software-discovery activity T1518.001, though neither was offensive-only here.
- signing.signerStats.totalSamples=1 provides limited historical depth for the certificate.
- contactedHosts=null means no saved host-reputation cross-check is available.
Use the DLL only as part of an expected CD PROJEKT installation obtained through its official distribution channel. Keep endpoint protection enabled and verify the signature again if the file was downloaded separately.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 8MITRE ATT&CK techniques
- 8spawned processes
- 0network contacts
- 2filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
POCO
24117db72d127900e4daef2597b8441c486bcaffe2acddb209c346510c87ec1a
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\PocoXML.dll",#1
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\PocoXML.dll"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Connect
\Device\ConDrv\\Connect
04Isolated runtime analysis
4 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- \Device\ConDrv\\Connect
- \Sessions\1\BaseNamedObjects\Local\SessionImmersiveColorMutex
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 74engines flagged
- 297sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 297 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
The file has a valid code signature from CD PROJEKT S.A..
ProvenanceObservedSourceCode-signing metadataObserved at - 04
Scanned file: POCO — 24117db72d127900e4daef2597b8441c486bcaffe2acddb209c346510c87ec1a
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\PocoXML.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\PocoXML.dll"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Connect — \Device\ConDrv\\Connect
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- POCO
- Format
- Win32 DLL
- Code signing
- Signature valid: CD PROJEKT S.A.
- Size
- 767.1 KB
- Last analyzed
- Sep 23, 2026, 4:44 AM UTC
24117db72d127900e4daef2597b8441c486bcaffe2acddb209c346510c87ec1aSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open it only when its sender or download source is one you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is POCO safe?
What is POCO?
How many antivirus engines detected POCO?
Is POCO digitally signed?
What is the SHA-256 hash of POCO?
Is it safe to open POCO?
How up to date is this analysis of POCO?
Community
Member reviews and reports for this exact file hash.