Is dlllist.txt safe?
No antivirus engine detected this tiny text file, and its long-established prevalence, completed sandbox observation, and fully checked network contacts show no harmful indicators.
None of 76 antivirus engines flagged the 30-byte text file, including all 17 participating tier-1 engines. It has circulated broadly since 2020, while the completed sandbox observation found no offensive techniques or adverse conclusion and the complete host check found no known harmful contacts.
64eccecdadc11f3ff7…f2f428c5f24fe3Recommended next actions
Before opening
Open it only when its sender or download source is one you independently trust.
If you already opened it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
None of 76 antivirus engines flagged the 30-byte text file, including all 17 participating tier-1 engines. It has circulated broadly since 2020, while the completed sandbox observation found no offensive techniques or adverse conclusion and the complete host check found no known harmful contacts.
The sample is a 30-byte text file rather than executable code, and code signing is not applicable to this format. None of 76 antivirus engines reported a detection, with all 17 participating tier-1 engines remaining silent. One completed sandbox observation recorded two ambient techniques but no offensive techniques, persistence, dropped payloads, or adverse sandbox conclusion. All three observed domains were covered by the host-reputation check, which returned no malicious or suspicious entries. Its 953-source history and 1,064 submissions since 2020 further reduce concern, and no external intelligence source supplied a malware match.
What We Detected
The sample is a 30-byte text file named dlllist.txt. None of 76 antivirus engines flagged it, including all 17 participating tier-1 engines, and no engine supplied a threat-family label.
Threat Behavior
One completed sandbox observation recorded two ambient techniques associated with command-shell execution, but no offensive techniques, persistence indicators, dropped payloads, or adverse sandbox conclusion. The reputation check covered all three observed domains and found no known malicious or suspicious hosts. No YARA rules or external malware-feed matches were present.
What To Do Now
No remediation is indicated by the available evidence. Keep endpoint protection enabled and rescan if the file changes, arrives with unexpected executable content, or is accompanied by scripts from an untrusted source.
Where this verdict could be wrong2 caveats
- The sandbox recorded two ambient techniques and command-shell activity, but no offensive techniques, persistence indicators, malicious child files, or adverse sandbox conclusion.
- Reputation is 0, although the long history and 1,064 submissions provide substantially stronger prevalence context.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/76 antivirus engines reported a detection.
- All 17 participating tier-1 engines reported no detection.
- One sandbox observation found zero offensive techniques and no adverse conclusion.
- All 3 observed domains were inspected with no malicious or suspicious host matches.
- The sample has 1,064 submissions from 953 sources dating to 2020.
- Sandbox process records include command-shell and batch-file execution context.
- The file's reputation score is 0 despite its extensive submission history.
No special action is needed for this exact hash based on the available evidence. Keep endpoint protection enabled and avoid running any unrelated batch scripts received from untrusted sources.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 76 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Complete3 contacted hosts were cross-checked.
YARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 2MITRE ATT&CK techniques
- 4spawned processes
- 3network contacts
- 1filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
- windows.msn.com-ion.edgesuite.net
- a1672.dscr.akamai.net
- \Device\ConDrv\\Connect
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 76engines flagged
- 953sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 76 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 953 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
The hash has been submitted 1,064 times from 953 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: dlllist.txt — 64eccecdadc11f3ff70d407997cd6075f6920d4fa38da9b068f2f428c5f24fe3
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\<USER>\Desktop\run.bat"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\cmd.exe /K "C:\Users\<USER>\Desktop\run.bat"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Connect — \Device\ConDrv\\Connect
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Contacted host: edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: windows.msn.com-ion.edgesuite.net — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 76 engines flagged this file
View all 76 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- dlllist.txt
- Format
- Text
- Code signing
- Not applicable to this file type
- Size
- 30 B
- Last analyzed
- Oct 8, 2026, 2:20 AM UTC
64eccecdadc11f3ff70d407997cd6075f6920d4fa38da9b068f2f428c5f24fe3Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open it only when its sender or download source is one you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is dlllist.txt safe?
What is dlllist.txt?
How many antivirus engines detected dlllist.txt?
What is the SHA-256 hash of dlllist.txt?
Is it safe to open dlllist.txt?
How up to date is this analysis of dlllist.txt?
Community
Member reviews and reports for this exact file hash.