Our call: Is MoonSharp.Interpreter.dll safe?Unknown
Unsigned .NET DLL with zero engine detections but only one submission and no runtime data.
- No completed runtime observation is available for this file.Derived · Runtime coverage
- 0 of 75 antivirus engines flagged the file.Observed · Antivirus analysis
- The hash has been submitted 1 time from 1 source.Derived · Saved report facts
5eee2f74079cb48018…c27df254baRecommended next actions
Before using
Treat the file as unverified and avoid using it until more evidence is available.
If you already used it
Run a full device scan. Do not delete or replace the component manually. Quarantine it with your antivirus or repair the parent software from its official source.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
No completed runtime observation is available for this file.
Verdict inputView chapterProvenanceDerivedSourceRuntime coverageObserved at - 02
0 of 75 antivirus engines flagged the file.
ProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 1 time from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
No antivirus engine flagged the file, yet the sample is brand new, unsigned, and has never been sandboxed. The combination of zero detections and extremely limited history leaves the risk level indeterminate.
All 75 engines returned clean results, including 16 tier-1 engines, so there is no malicious consensus. However, the file is unsigned, appeared for the first time today, and has no sandbox observations. Similar past files of the same type produced mixed verdicts, reinforcing that coverage is too thin to decide safety or malice.
What We Detected
Zero detections across 75 engines; the DLL is unsigned and submitted for the first time today. Static analysis shows one MITRE technique (T1620) but no packer or high-entropy code.
Threat Behavior
No sandbox execution occurred, so runtime behaviour is unknown. No dropped children, contacted hosts, or external-intel hits were recorded.
What To Do Now
Do not treat the file as trusted until it receives broader analysis or sandbox coverage. Keep endpoint protection enabled and avoid running unsigned binaries from unverified sources.
Where this verdict could be wrong3 caveats
- T1620 (Reflective Code Loading) is listed in offensiveTechniques, but without sandbox execution this remains a static-only signal and could be legitimate .NET reflection usage.
- rare_new prevalence means the file has almost no track record; absence of detections could simply reflect lack of exposure rather than confirmed cleanliness.
- similarHashes contains one 'suspicious' verdict on a different filetype match, showing mixed historical outcomes for the same file type.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 engines flagged malicious
- No external intelligence hits
- Unsigned DLL
- First seen today (rare_new)
- Static-only T1620 reference
Keep the file quarantined or avoid execution until additional sandbox or prevalence data becomes available.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. That limits reputation evidence, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- MoonSharp.Interpreter.dll
- Format
- Win32 DLL
- Code signing
- No verified publisher
- Size
- 361.0 KB
- Last analyzed
- Aug 1, 2026, 1:33 PM UTC
5eee2f74079cb48018a5f9b1a55d3856c283858fb6a04c6a70adccc27df254baSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
There isn't enough information to give this file a clear rating.
Be cautious — an unknown rating is not the same as a clean bill of health.
Use it only as part of software obtained from the developer's official site or another source you independently trust.
When in doubt, don't use it — or scan it again later once it's more widely seen.