Safe
Widely distributed audio library with 17 tier-1 engines clean, no malicious sandbox verdict, and consistent community NO_THREAT verdicts despite heuristic sandbox observations.
b266f223cb08279b8d…ffbe753ddbThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file exhibits a clean profile across all major antivirus engines (Avast, BitDefender, Kaspersky, ESET, Fortinet, Emsisoft, Ikarus, DrWeb, F-Secure, GData, Avira, AVG) with zero tier-1 malicious detections. Its prevalence as a common_old file with nearly 3,000 unique submitters and 3,850 submissions over 7+ years indicates widespread, established distribution. Community analysis from FileScan.IO consistently reports NO_THREAT or INFORMATIONAL verdicts with 100% confidence. The sandbox heuristics (process injection, direct-IP C2) are observations from test-environment execution, not confirmed malicious behaviour; no malicious sandbox verdict, no malicious dropped children, and no malicious contacted hosts were recorded. The YARA rule match (pe_detect_tls_callbacks) is a structural detection, not a malware family signature. The file is consistent with a legitimate library.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines.tier1Malicious=0; tier1ReportedClean=17 (Avast, BitDefender, Kaspersky, ESET, Fortinet, Emsisoft, Ikarus, DrWeb, F-Secure, GData, Avira, AVG) — all major AV engines silent or clean
prevalence.classification=common_old; 2,879 unique submitters, 3,850 submissions since 2019-02-15 — widely distributed, long-established file
communityComments: 3 FileScan.IO analyses report NO_THREAT or INFORMATIONAL verdicts with 100% confidence
behaviour.hasMaliciousSandboxVerdict=false; droppedChildren.hasMaliciousChild=false; contactedHosts.maliciousHosts=none — no confirmed malicious runtime artifacts
yaraify.ruleCount=1 (pe_detect_tls_callbacks) — TLS callback detection rule, not malware family; MalwareBazaar.hit=false; CIRCL.hit=false
- 17 tier-1 antivirus engines report clean or undetected
- 2,879 unique submitters, 3,850 submissions since 2019 — widely distributed, long-established
- Community analysis (FileScan.IO) confirms NO_THREAT verdict with 100% confidence
- No malicious sandbox verdict, no malicious dropped children, no malicious contacted hosts
- Consistent with legitimate open-source audio library (libsoundio)
This file is safe. No action is required. The heuristic sandbox observations are consistent with legitimate library functionality in a test environment rather than active malware.
pe detect tls callbacks corroborated by 1 source
- 1 YARA rulepe_detect_tls_callbacks
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 204.79.197.203
- 20.189.173.22
- 13.89.179.12
- 20.42.65.92
- 20.189.173.20
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_rundll32.exe_rea_1e8dc90b09ebae8ffc9ebfdf8ae9b75731582fb_b7758387_0d01f5e1
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_rundll32.exe_rea_1e8dc90b09ebae8ffc9ebfdf8ae9b75731582fb_b7758387_0d01f5e1\Report.wer
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_rundll32.exe_rea_3b8f2b417e8b58448a49f9a384cbc42cc2bc411d_b7758387_1a49c1f0
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_rundll32.exe_rea_3b8f2b417e8b58448a49f9a384cbc42cc2bc411d_b7758387_1a49c1f0\Report.wer
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_rundll32.exe_rea_6afcd3b460963e6ca0d93cd3f62d931b3260ba43_b7758387_1a59b425
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER163E.tmp.csv
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER164E.tmp.txt
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER268C.tmp.csv
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER269C.tmp.txt
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER32E2.tmp.csv
- \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess6692
- \Sessions\1\BaseNamedObjects\Global\a74f167d-7535-4531-b2f3-3d90357d8b5f
- \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess2372
- \Sessions\1\BaseNamedObjects\Global\6e600947-0eff-4742-b612-03120bba08e8
- \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess5520
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 70f1b92b8440a361bedc…03a9a8Never scannednever seen before
- 257b5af66f81b59ef27f…4f9935Never scannednever seen before
- 2ab05ff2e69d97d2de90…e24e24Never scannednever seen before
- cc6bb6ea82848c294c19…45bdcbNever scannednever seen before
- 0f71f1627589c850d73d…154320Never scannednever seen before
- b000fd50ed69a745f98f…de7a50Never scannednever seen before
- 716d68d2b2ef10a37bb7…f574abNever scannednever seen before
- 98d27273ca924c116ced…ef42aaNever scannednever seen before
- 98d954fce20e0d622c1e…1b03c2Never scannednever seen before
- 8f39fae9cf9e866f9a90…d6c34dNever scannednever seen before
1 corroborating signal from researcher-curated sources
- pe_detect_tls_callbacks
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
- pe_detect_tls_callbacks
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
Evidence"C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\readme.dll",#1Sample contacted 5 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence204.79.197.203 · 20.189.173.22 · 13.89.179.12
0 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- libsoundio.dll
- Size
- 83.5 KB
- MIME type
- (unknown)
- Detected type
- Win32 DLL
- SHA-256
- b266f223cb08279b8dd09e08538fc9468255d904b609c28775dbaeffbe753ddb
- MD5
- b492d241dbae5fd322b1779226a3f0a9
- SHA-1
- 95a6e6de7f452ed7cb7bc02730cde999f27cca53
- PE imphash
- bc0846853d37b1d8af9019939a993f80
- First seen (VT)
- 2/15/2019, 10:06:55 AM
- Last analysis (VT)
- 6/10/2026, 12:16:38 AM
- First scan (MalwareTips)
- 6/10/2026, 9:28:16 AM
- Last scan (MalwareTips)
- 6/10/2026, 9:28:16 AM
- Community reputation
- +11trusted
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.