File verdict·Decided by the MT AI Engine
Our call

Suspicious

Unsigned DLL with process-injection behaviour flagged by two tier-1 engines but limited family consensus.

Trust score45Caution
solaris 26.3X.dll
361.5 KB
446d92a50fdb78a29aad6386c3e0
Antivirus engines
7 of 74 flagged
Code signing
Unsigned
Age
First seen 23 days ago
MT AI Engine · Verdict analysis

The reasoning behind this verdict

The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.

65%Confidence
High
Reasoning

The file is an unsigned 64-bit DLL submitted 23 days ago that exhibits debug-evasion and long-sleep tags. Engines returned 7 malicious detections including two tier-1 results, but the tier-1 family consensus is weak and only one engine. Behaviour analysis recorded T1055 process injection and the corresponding heuristic fired, yet sandbox verdicts stayed clean and no malicious hosts or dropped children were observed. Community annotations conflict, with three malicious FileScan.IO reports against one clean assessment. The combination of limited tier-1 agreement, unsigned status, and offensive technique without external corroboration places the sample in the suspicious band.

Key signals · 4

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines.tier1Malicious=2 (Microsoft, Symantec) with tier1FamilyConsensus.family=attribute

  2. behaviour.offensiveTechniques includes T1055; triggeredHeuristics[0].rule=MalwareTips.Synth.ProcessInjection

  3. signing.verified=false (unsigned); prevalence.classification=common_new

  4. communityComments show 3 FileScan.IO malicious verdicts vs 1 clean threat.rip report

Points in its favour
  • Majority of tier-1 engines (15/17) reported clean
  • No malicious contacted hosts or dropped children
  • No external intelligence corroboration
Points against
  • Unsigned DLL
  • Process injection (T1055) observed
  • Debug-evasion and long-sleep tags
  • Two tier-1 malicious detections
Recommended action

Treat as suspicious pending additional sandbox runs; avoid execution until further behavioural data is available.

What this file does

What it attempted when executed in an isolated sandbox

  • High concern: Hides inside another running program to evade antivirus.

  • High concern: Records what you type — keylogger behaviour.

  • High concern: Tries to disable or bypass your security software.

  • High concern: Hijacks how Windows loads programs so it runs automatically.

  • High concern: Loads hidden code straight into memory to dodge scanners.

  • Moderate concern: Obfuscates or packs its code to avoid detection.

  • Moderate concern: Lists running programs — often to find security tools.

Translated from the file's technical behaviour during analysis. It never ran on your device.

What to do now

We couldn't fully clear this file. Treat it with caution.

  1. Don't run it unless you're certain it came from a source you trust.

  2. Check where you got it — an email attachment or a random download link is a red flag.

  3. If you're unsure, delete it. You can always re-download a clean copy from the official source.

  4. If you're still unsure, scan it again in a day or two — detections often catch up on newer files.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
20

Adversary techniques mapped to the MITRE ATT&CK framework.

T1010T1012T1027· Obfuscated codeT1027.002· Obfuscated codeT1033· Reads user infoT1055· Process injectionT1056· KeyloggingT1056.001· KeyloggingT1057· Lists programsT1082· System reconT1083· Scans your filesT1129· Loads modulesT1218.011T1497· Sandbox evasionT1518.001· Checks your AVT1542.003T1562.001· Disables securityT1574· Execution hijackT1614T1620· In-memory loading
Spawned processes
7
$(unnamed)
"C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\solaris.dll",#1
$(unnamed)
C:\Windows\system32\WerFault.exe -u -p 6072 -s 616
$(unnamed)
C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\solaris.dll"
$(unnamed)
C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
$(unnamed)
C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\solaris.dll",#1
$(unnamed)
C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\solaris.dll",#1
$(unnamed)
C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 7096 -s 452
Filesystem & mutexes
12
Files written10
  • C:\ProgramData\Microsoft\Windows\WER\Temp
  • C:\ProgramData\Microsoft\Windows\WER\Temp\2413a2e8-bfca-4282-b009-b3b4d3bf6c92
  • C:\ProgramData\Microsoft\Windows\WER\ReportQueue
  • C:\ProgramData\Microsoft\Windows\WER\Temp\043c7acb-2a62-4526-8fc6-616d201ab5cd
  • C:\ProgramData\Microsoft\Windows\WER\ReportArchive
+5 more
Mutexes created2
  • \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess7096
  • \Sessions\1\BaseNamedObjects\InventorySynchronizationInventoryApplicationFileMutex4216
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA & heuristic rule matches

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

1 synthesis
MITRE ATT&CK profile
Defense evasion× 1
MalwareTips synthesis rules
Our own detection rules, applied to the scan data and sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    "C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\solaris.dll",#1
Antivirus engine breakdown

7 detections across 74 engines

7 malicious0 suspicious67 clean
Tier-117 engines
2flag
Top commercial AVs (low FP rate)
Tier-240 engines
1flag
Mainstream engines with mixed FP rates
Low-trust17 engines
4flag
Heuristic / generic-AI engines (high FP rate)
APEX
malicious
Malicious
Bkav
malicious
W32.Malware.A8965F5E
CrowdStrike
malicious
win/malicious_confidence_100% (D)
Cynet
malicious
Malicious (score: 100)
McAfeeD
malicious
ti!446D92A50FDB
Microsoft
malicious
Trojan:Win32/Wacatac.B!ml
Symantec
malicious
ML.Attribute.HighConfidence
Hash 446d92a50fdb… cross-referenced against 74 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

Unpacked
Section entropy6 sections
.text
6.48
.rdata
5.15
.data
2.65
.pdata
5.54
.fptable
0.00
.reloc
5.15
0.0Packed threshold 7.28.0
Prevalence

How widely this file has been seen

Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.

Common & new
Unique uploaders
152
Hundreds of people have uploaded this — common.
Total submissions
180
Includes repeat uploads by the same source.
First seen
23d ago
Jun 28, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
6/28/2026, 9:20:17 PM
First seen (MalwareBazaar)
Last analysis (VT)
7/20/2026, 11:51:59 PM
Scanned here
7/21/2026, 5:13:48 PM
File name
solaris 26.3X.dll
Size
361.5 KB
MIME type
(unknown)
Detected type
Win32 DLL
SHA-256
446d92a50fdb78a29a5d2bf213ac5a24d8fe3b1bb4e8dbb4135c74ad6386c3e0
MD5
eb82b9d2b84cc712cdad3ddfcd128c12
SHA-1
3a0cbbb85979f52e366cb1345bae384007aaa284
PE imphash
b91dc6bb0eac3fcc0501c449c59c38fb
First seen (VT)
6/28/2026, 9:20:17 PM
Last analysis (VT)
7/20/2026, 11:51:59 PM
First scan (MalwareTips)
7/21/2026, 5:13:48 PM
Last scan (MalwareTips)
7/21/2026, 5:13:48 PM
Behavior tags
pedlldetect-debug-environment64bitslong-sleepschecks-user-input
Frequently asked

Safety FAQ

Common questions about solaris 26.3X.dll, answered from the scan data above.

  • solaris 26.3X.dll is suspicious — treat it as unsafe until you're sure. 7 of 74 antivirus engines flag it, which isn't a strong consensus but is enough to be cautious. Don't run it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
  • solaris 26.3X.dll is a Windows executable program, about 362 KB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
  • 7 of 74 antivirus engines flagged solaris 26.3X.dll, 7 of them as outright malicious. A small number of detections can include false positives, so we weigh which engines flagged it and what else the file does, not just the raw count.
  • Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
  • To remove solaris 26.3X.dll: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original solaris 26.3X.dll file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
  • solaris 26.3X.dll is classified as a trojan — malware disguised as something harmless to trick you into running it. Knowing the family matters because it tells you the likely impact — data theft, remote control, file encryption, or unwanted ads — and guides the cleanup.
  • The SHA-256 hash of solaris 26.3X.dll is 446d92a50fdb78a29a5d2bf213ac5a24d8fe3b1bb4e8dbb4135c74ad6386c3e0, and its MD5 is eb82b9d2b84cc712cdad3ddfcd128c12. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on July 21, 2026. Because a file's hash never changes, the identity of solaris 26.3X.dll is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.