Is freetype.dll safe?
No antivirus engine detected this verified CD PROJEKT DLL, and five signer-matched files support legitimacy despite one uncorroborated process-injection heuristic.
The DLL carries a valid CD PROJEKT S.A. signature, and none of 74 antivirus engines flagged it. A sandbox mapped activity to process-injection and defense-impairment techniques, but it issued no malware finding, while five signer-matched files have consistent benign histories.
bec244f9a51aa75d7c…1ecdb5bb218712Recommended next actions
Before using
Use it only as part of software obtained from the developer's official site or another source you independently trust.
If you already used it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The DLL carries a valid CD PROJEKT S.A. signature, and none of 74 antivirus engines flagged it. A sandbox mapped activity to process-injection and defense-impairment techniques, but it issued no malware finding, while five signer-matched files have consistent benign histories.
None of 74 antivirus engines reported a detection, including all 17 participating tier-1 engines. The file has a verified CD PROJEKT S.A. signature, no detected brand conflict, and no packing indicators. Five prior files matched by signer were assessed as benign, materially strengthening the publisher context. One completed sandbox mapped activity to T1055 and T1562.001, but it produced no malicious sandbox verdict, recorded no persistence, and did not identify a malicious child. Host-reputation coverage was not saved, so no complete network-reputation conclusion can be drawn, though the sandbox recorded no network contacts.
What We Detected
None of 74 antivirus engines flagged the DLL, and all 17 participating tier-1 engines reported no detection. The file is signed with a verified certificate belonging to CD PROJEKT S.A., with no detected conflict between the claimed brand and signer. Five other files matched by this signer also received prior benign assessments.
Threat Behavior
One completed sandbox run mapped activity to T1055 and T1562.001, including a process-injection heuristic. This deserves attention, but the sandbox produced no malicious verdict, recorded no persistence indicators or network contacts, and no inspected child was identified as malicious. The six child files nevertheless lack individual verdicts, and no complete contacted-host reputation result is available.
What To Do Now
Keep endpoint protection enabled and obtain the DLL through the official game installation or trusted distribution channel. If its signature becomes invalid, its hash differs after an unexpected replacement, or it appears outside the expected application directory, quarantine it and rescan the surrounding installation.
Where this verdict could be wrong4 caveats
- The completed sandbox mapped activity to T1055 and T1562.001, including a process-injection heuristic; this is meaningful counter-evidence but lacks engine, sandbox-verdict, or family corroboration.
- signing.signerStats.totalSamples=1 provides limited direct historical depth, although five signer-matched similar files were previously assessed as safe.
- contactedHosts=null, so no completed host-reputation cross-check is available; the sandbox itself recorded no contacted domains, IPs, or URLs.
- All six inspected dropped-child hashes have unknown individual verdicts, despite droppedChildren.hasMaliciousChild=false.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 antivirus engines reported a detection.
- All 17 participating tier-1 engines reported no detection.
- The CD PROJEKT S.A. digital signature is verified.
- Five signer-matched similar files have prior safe verdicts.
- No packing, malicious sandbox verdict, persistence, or malicious child was identified.
- Runtime telemetry mapped activity to MITRE T1055 and T1562.001.
- The process-injection synthesis heuristic fired at high severity.
- Direct signer statistics contain only one historical sample.
- Six dropped-child hashes lack individual verdicts.
- No complete contacted-host reputation cross-check is available.
Keep security protection enabled and use this DLL only when it comes from the official CD PROJEKT installation or update channel. Recheck the signature and installation integrity if the file appeared unexpectedly.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 12MITRE ATT&CK techniques
- 15spawned processes
- 0network contacts
- 31filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
freetype.dll
bec244f9a51aa75d7c3eea239270d3306bd37689d854842d461ecdb5bb218712
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\freetype.dll",#1
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\system32\WerFault.exe -u -p 2844 -s 500
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Temp
C:\ProgramData\Microsoft\Windows\WER\Temp
04Isolated runtime analysis - Written fileObserved
036987f7-d012-494f-b0bb-3c13375fa9b3
C:\ProgramData\Microsoft\Windows\WER\Temp\036987f7-d012-494f-b0bb-3c13375fa9b3
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\ProgramData\Microsoft\Windows\WER\Temp
- C:\ProgramData\Microsoft\Windows\WER\Temp\036987f7-d012-494f-b0bb-3c13375fa9b3
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue
- C:\ProgramData\Microsoft\Windows\WER\Temp\bdca723b-4295-4070-86c4-857f90832ab5
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERC67C.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERD031.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERD275.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERC67C.tmp.dmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERD031.tmp.WERInternalMetadata.xml
- Local\WERReportingForProcess2844
- Global\AmiProviderMutex_InventoryApplicationFile
- Global\3ed00096-85f8-4887-9b1f-f821a8f7e08f
- \Sessions\1\BaseNamedObjects\Local\SessionImmersiveColorMutex
- \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess3468
Files this sample writes at runtime
This file drops 6 children at runtime. None are currently flagged malicious in our cache.
- 6e25c96965ab44b3bb5b…107229Never scannednever seen before
- 6be999ae18a049a89b6b…8fc15dNever scannednever seen before
- 49ddc2a820ad8193e3b8…cd0b4eNever scannednever seen before
- a52fad0043c3777b2cd0…7fc867Never scannednever seen before
- dca1a99466036df1dab6…39ce48Never scannednever seen before
- b46f98519c46a7c292cc…0ab6b9Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 0 / 74engines flagged
- 93sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The file has a valid code signature from CD PROJEKT S.A..
ProvenanceObservedSourceCode-signing metadataObserved at - 03
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 04
Scanned file: freetype.dll — bec244f9a51aa75d7c3eea239270d3306bd37689d854842d461ecdb5bb218712
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\freetype.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\WerFault.exe -u -p 2844 -s 500
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Temp — C:\ProgramData\Microsoft\Windows\WER\Temp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: 036987f7-d012-494f-b0bb-3c13375fa9b3 — C:\ProgramData\Microsoft\Windows\WER\Temp\036987f7-d012-494f-b0bb-3c13375fa9b3
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\freetype.dll",#1
0 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- freetype.dll
- Format
- Win32 DLL
- Code signing
- Signature valid: CD PROJEKT S.A.
- Size
- 812.6 KB
- Last analyzed
- Sep 23, 2026, 5:18 AM UTC
bec244f9a51aa75d7c3eea239270d3306bd37689d854842d461ecdb5bb218712Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Use it only as part of software obtained from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is freetype.dll safe?
What is freetype.dll?
How many antivirus engines detected freetype.dll?
Is freetype.dll digitally signed?
What is the SHA-256 hash of freetype.dll?
Is it safe to use freetype.dll?
How up to date is this analysis of freetype.dll?
Community
Member reviews and reports for this exact file hash.