Safe
Unsigned SDL3.dll library with zero malicious engine detections, normal PE structure, and benign ambient behaviour; DirectIpC2 heuristic triggered by Cloudflare DNS contact.
c8d2e2455061ba913e…e4edba732aThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The evidence strongly indicates this is a legitimate open-source library rather than malware. No tier-1 engine consensus for malice exists; tier-1 engines either report clean or timeout. The filename and imphash align with SDL3, a widely-used multimedia library. Behaviour analysis shows zero offensive MITRE techniques and only ambient techniques common in legitimate DLLs. The DirectIpC2 heuristic, while flagged, is explained by contact to Cloudflare's public DNS infrastructure—a benign service, not a hidden C2 server. Medium prevalence across 332 submitters over 62 days is consistent with a legitimate library distributed in development environments. No malicious sandbox verdicts, no malicious dropped children, and no malicious contacted hosts further support a safe classification.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/49 malicious; tier1Malicious=0; tier1ReportedClean=8 (Avira, F-Secure, Fortinet, Ikarus, ESET-NOD32, Kaspersky, BitDefender, Emsisoft)
signing.verified=false; filename 'SDL3.dll' matches Simple DirectMedia Layer, a legitimate open-source multimedia library
behaviour: 0 offensive MITRE techniques; 4 ambient (T1056, T1218.011, T1497, T1518.001) — standard for DLLs and installers
triggeredHeuristics: DirectIpC2 fired but contacted IP 162.159.36.2 is Cloudflare public DNS, not malicious C2
prevalence: medium (332 submitters, 363 submissions); no malicious sandbox verdicts, no malicious dropped children, no malicious contacted hosts
- Zero malicious engine detections across 49 reporting engines
- 8 tier-1 engines reported clean or timed out (no tier-1 malicious consensus)
- Normal PE entropy and structure; no packers or high-entropy code sections
- Zero offensive MITRE techniques; only ambient techniques common in legitimate DLLs
- Medium prevalence (332 submitters, 363 submissions) consistent with legitimate library distribution
- Unsigned DLL — no publisher identity to verify authenticity
- DirectIpC2 heuristic triggered — contacted external IP without DNS resolution (though IP is Cloudflare public DNS, not malicious)
- Sandbox evasion technique detected (T1497) — common in legitimate software but also used by malware
This file is safe. SDL3.dll is a legitimate open-source multimedia library. Verify the download source against the official SDL3 project repository if you have concerns about authenticity, but no security action is required for this file.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- \Device\ConDrv\\Connect
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence162.159.36.2
0 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- SDL3.dll
- Size
- 2.57 MB
- MIME type
- (unknown)
- Detected type
- Win32 DLL
- SHA-256
- c8d2e2455061ba913e6ff26ed6d766d4458dd58f127078b384d3eae4edba732a
- MD5
- 96153d45c3f65c6ed07e2893b0d76070
- SHA-1
- cddde3b81c64c69f0c59fd4698cee7206cc6fbc6
- PE imphash
- da3a4825cf733767f472d7672219ff7d
- First seen (VT)
- 4/9/2026, 1:49:27 PM
- Last analysis (VT)
- 5/12/2026, 9:18:24 PM
- First scan (MalwareTips)
- 6/10/2026, 9:42:35 AM
- Last scan (MalwareTips)
- 6/10/2026, 9:42:35 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.