File verdict·MT AI Engine assessment
Our call

Safe

Unsigned 18 kB DLL with zero engine detections and clean sandbox behaviour.

Trust score82Moderate trust
winhttp.dll
18.0 KB
5f63675b27263c44622fa4296e6e
Antivirus engines
0 of 74 flagged
Code signing
Unsigned
Age
First seen 1 day ago
MT AI Engine · Verdict analysis

The reasoning behind this verdict

This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.

78%Confidence
High
Reasoning

All 74 engines returned clean results, including 16 tier-1 engines. The file is unsigned and only one day old, yet the sandbox recorded only ambient techniques and no malicious verdict. The single triggered heuristic (DirectIpC2) is medium severity and can occur with legitimate software. Medium prevalence across five sources further supports a benign classification.

Analyst conclusion

No antivirus engine flagged the file. The only notable signal is a medium-severity heuristic for direct-IP contact without DNS, which is inconclusive on its own. Sandbox execution produced no malicious indicators and no children were malicious.

Detailed assessment

What We Detected

74 engines scanned the 18 kB Win32 DLL; none returned a malicious or suspicious result. The file is unsigned and first appeared one day ago.

Threat Behavior

Sandbox execution showed 14 ambient MITRE techniques and zero offensive techniques. One external IP was contacted directly without DNS resolution, triggering a medium-severity heuristic, but no malicious verdict was issued and no malicious children were dropped.

What To Do Now

The file can be treated as clean for most purposes. If it must run in a high-security environment, monitor the direct-IP connection or request the original source for verification.

Key signals · 2

The strongest scan facts behind the verdict, preserved with their exact names and counts.

  1. 0 of 74 antivirus engines flagged the file.

  2. The hash has been submitted 6 times from 5 sources.

Points in its favour
  • Zero engine detections across 74 scanners
  • Clean sandbox verdict
  • No malicious dropped children
Points against
  • Unsigned DLL
  • Direct IP contact without DNS (medium heuristic)
Recommended action

The sample shows no malicious indicators from engines or sandbox; treat as safe unless additional context suggests otherwise.

What to do now

This file looks safe based on everything we checked.

  1. This file is safe to use.

  2. Good habit: only download files from the official website or an app store.

  3. Keep your antivirus and Windows updates switched on so you stay protected.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
14

Adversary techniques mapped to the MITRE ATT&CK framework.

T1027· Obfuscated codeT1027.005· Obfuscated codeT1033· Reads user infoT1036T1059· Runs commandsT1070· Covers its tracksT1070.006· Covers its tracksT1071· Application protocolT1082· System reconT1129· Loads modulesT1218.011T1497· Sandbox evasionT1518.001· Checks your AVT1574· Execution hijack
Spawned processes
10
$(unnamed)
"C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\winhttp.dll",#1
$(unnamed)
C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\winhttp.dll"
$(unnamed)
C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
$(unnamed)
C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\winhttp.dll",#1
$(unnamed)
C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\winhttp.dll",#1
$(unnamed)
C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\winhttp.dll,DllMain
$(unnamed)
C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\winhttp.dll,WinHttpAddRequestHeaders
$(unnamed)
C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\winhttp.dll,WinHttpCloseHandle
+2 more processes captured.
Network activity
1
IP addresses1
  • 162.159.36.2
Filesystem & mutexes
7
Files written7
  • C:\Users\<USER>\AppData\Local\Microsoft\Windows\AdobeGCInvoker\winhttp.dll
  • C:\Users\<USER>\AppData\Local\Microsoft\Windows\AdobeGCInvoker\AdobeGCInvoker.exe
  • C:\Users\<USER>\AppData\Local\Microsoft\Windows\AdobeGCInvoker\Adobe.Acrobat.Dependencies.manifest
  • C:\Users\user\AppData\Local\Microsoft\Windows\AdobeGCInvoker\
  • C:\Users\user\AppData\Local\Microsoft\Windows\AdobeGCInvoker\winhttp.dll
+2 more
Dropped payload

Files this sample writes at runtime

This file drops 2 children at runtime. None are currently flagged malicious in our cache.

2 unseen
  • 5f63675b27263c446278296e6eNever scanned
    never seen before
  • 255a65d30841ab4082bdc12309Never scanned
    never seen before
No researcher-database hits
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Rule-based evidence

Signatures and behavior heuristics

Behavioral heuristics matched patterns associated with malware. Corroborating evidence determines how much weight they carry.

1 heuristic
MITRE ATT&CK profile
C2× 1
Behavior heuristics
Deterministic patterns derived from scan data and observed runtime behavior
  • DirectIpC2medium

    Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    162.159.36.2
Antivirus engine breakdown

0 detections across 74 engines

0 malicious0 suspicious74 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-240 engines
0flag
Mainstream engines with mixed FP rates
Low-trust17 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 74 engines report this file as clean.
Hash 5f63675b2726… cross-referenced against 74 AV engines via our AV network.
PE forensics

Section entropy & packers

No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.

Unpacked
Section entropy6 sections
.text
6.23
.rdata
4.27
.data
0.52
.pdata
2.42
.rsrc
3.12
.reloc
0.54
0.0Packed threshold 7.28.0
Prevalence

How widely this file has been seen

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
5
Moderate upload volume.
Total submissions
6
Includes repeat uploads by the same source.
First seen
1d ago
Jul 22, 2026
Prevalence quadrant
Rare · New
Needs evidence-led scrutiny
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Often established software
File identity

Forensic fingerprint

File biography
First seen (VT)
Jul 22, 2026, 12:01 PM UTC
First seen (MalwareBazaar)
Last analysis (VT)
Jul 22, 2026, 12:01 PM UTC
Scanned here
Jul 23, 2026, 12:46 PM UTC
File name
winhttp.dll
Size
18.0 KB
MIME type
(unknown)
Detected type
Win32 DLL
SHA-256
5f63675b27263c446278bac88dc24345106b44294da8c20adfaa012fa4296e6e
MD5
eb4ce706240023cda8317b50043af383
SHA-1
b7c309770f9097f05a532babd11d432b0eb5cff2
PE imphash
73d729634b70f5e80a6b5d0b43005322
First seen (VT)
Jul 22, 2026, 12:01 PM UTC
Last analysis (VT)
Jul 22, 2026, 12:01 PM UTC
First scan (MalwareTips)
Jul 23, 2026, 12:46 PM UTC
Last scan (MalwareTips)
Jul 23, 2026, 12:46 PM UTC
Behavior tags
pedll64bitsdetect-debug-environmentidle
Frequently asked

Safety FAQ

Common questions about winhttp.dll, answered from the scan data above.

  • winhttp.dll appears safe. 74 of 74 antivirus engines report it clean. As a habit, only run files you downloaded from the official source, since attackers sometimes distribute trojanised copies of legitimate software under the same name.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Unknown files are temporarily processed and submitted to VirusTotal. MalwareTips does not retain the binary after processing. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.