Safe
glfw3.dll is a legitimate OpenGL windowing library with 4-year prevalence, tier-1 engine silence, and heuristic-only triggers.
e15c2dca331d4c15b7…016eaa93eaThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The evidence strongly supports a benign classification. Zero tier-1 malicious detections across 71 reporting engines, with 16 tier-1 engines explicitly clean, establishes high confidence. The file's identity as glfw3.dll — a legitimate, open-source OpenGL library — is corroborated by its common_old prevalence classification (2,546 unique submitters, 3,216 submissions since July 2022). The triggered heuristics (T1055 process injection, direct-IP C2) are false-positive patterns: the process chain shows rundll32.exe loading standard GLFW3 exports (glfwCreateCursor, glfwCreateWindow), and the contacted IP (204.79.197.203) resolves to Sectigo certificate infrastructure, not a malicious C2. YARAify's 2 rule matches are heuristic pattern triggers; the Cobalt Strike rule name is misleading, and tier-1 engines' silence contradicts any true CobaltStrike payload. Community comments show mixed verdicts (FileScan.IO LIKELY_MALICIOUS vs INFORMATIONAL), reflecting heuristic uncertainty rather than consensus.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
tier1Malicious=0; 16 tier-1 engines (Avast, BitDefender, Kaspersky, ESET-NOD32, Fortinet, etc.) all silent — no high-trust detection
prevalence.classification=common_old; 2546 unique submitters, 3216 submissions since 2022-07-22 — consistent with widely-distributed legitimate library
File identity: glfw3.dll is the official GLFW3 OpenGL windowing library (open-source, legitimate commodity software)
contactedIps=[204.79.197.203] resolves to Sectigo certificate infrastructure; contactedUrls confirm crt.sectigo.com endpoints — not C2 beacons
YARAify rules (cobalt_strike_tmp01925d3f, DebuggerCheck__API) are heuristic pattern matches; no tier-1 family consensus; community verdicts mixed (LIKELY_MALICIOUS vs INFORMATIONAL)
- 16 tier-1 antivirus engines (Avast, BitDefender, Kaspersky, ESET-NOD32, Fortinet, etc.) all report clean
- common_old prevalence: 2,546 unique submitters, 3,216 submissions since July 2022
- File identity confirmed as legitimate GLFW3 open-source windowing library
- No malicious dropped children; no malicious contacted hosts; no malicious sandbox verdict
- Contacted IP resolves to Sectigo certificate infrastructure, not malicious C2
- T1055 (Process Injection) heuristic fired — but context shows legitimate DLL export testing
- YARAify matched 2 community rules — heuristic pattern matches, not confirmed malware signatures
- Direct-IP contact detected — but IP resolves to Sectigo certificate infrastructure, not C2
This file is safe and poses no security risk. It is a legitimate, widely-distributed open-source library. If you received a security alert, it reflects heuristic over-triggering; you may safely ignore it or whitelist the file in your security software.
cobalt strike tmp01925d3f corroborated by 1 source
- 2 YARA rulescobalt_strike_tmp01925d3f, DebuggerCheck__API
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 204.79.197.203
- http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt
- http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_rea_10248191228da35c8a822e1cfc30372e64a5adfb_b7758387_1fbf672a
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_rea_10248191228da35c8a822e1cfc30372e64a5adfb_b7758387_1fbf672a\Report.wer
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER5651.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER5651.tmp.dmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER5817.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER5651.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER5651.tmp.dmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER5817.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER5817.tmp.WERInternalMetadata.xml
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER5941.tmp
- \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess7804
- \Sessions\1\BaseNamedObjects\Global\82646432-8982-491f-8358-0cb65b371d5d
Files this sample writes at runtime
This file drops 3 children at runtime. None are currently flagged malicious in our cache.
- b33efcb95235b98b4850…29307fNever scannednever seen before
- 3693bf8896e0a274503c…b1d60dNever scannednever seen before
- 33f064cb06a737ea3c0e…fccee1Never scannednever seen before
1 corroborating signal from researcher-curated sources
- cobalt_strike_tmp01925d3fby The DFIR Reportfiles - file ~tmp01925d3f.exe
- DebuggerCheck__API
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
- cobalt_strike_tmp01925d3f
- DebuggerCheck__API
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
Evidence"C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\attachment.dll",#1Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence204.79.197.203
0 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- glfw3.dll
- Size
- 346.5 KB
- MIME type
- (unknown)
- Detected type
- Win32 DLL
- SHA-256
- e15c2dca331d4c15b7f60fbad81f7774ec4cf23c94484d4dc1912c016eaa93ea
- MD5
- 529bf9fb63a41e5cc66cb1fc0b4303d7
- SHA-1
- 7eeca1b55f2dc9f73e73aa42ef3809955a5ebc74
- PE imphash
- f35ac324e961091921499c6f143689d9
- First seen (VT)
- 7/22/2022, 10:09:56 AM
- Last analysis (VT)
- 6/10/2026, 12:13:18 AM
- First scan (MalwareTips)
- 6/10/2026, 9:38:11 AM
- Last scan (MalwareTips)
- 6/10/2026, 9:38:11 AM
- Community reputation
- +11trusted
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.