File verdict·Decided by the MT AI Engine
Our call

Safe

Microsoft-signed libHarfBuzzSharp.dll with 384-day prevalence, zero malicious detections across 71 engines, and clean signer history.

Verified · Microsoft Corporation
Trust score88High trust
MT AI confidence · 92%
libHarfBuzzSharp.dll
1.7 MB
eb76238c9e8e41d44b0f0fc14a7d
Antivirus engines
0 of 75 flagged
Code signing
Signed by Microsoft Corporation
Age
First seen 1y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

92%Confidence
Very high
Reasoning

The evidence strongly supports a safe verdict. Zero malicious detections across 71 engines, including 16 high-trust vendors (Kaspersky, BitDefender, ESET-NOD32, Fortinet, Avira, F-Secure, GData, Emsisoft, DrWeb, Avast, AVG), establishes baseline safety. The file is legitimately signed by Microsoft Corporation with a verified certificate and a clean signer history (2/2 prior samples safe). Prevalence data shows 2,148 unique submitters and 2,561 total submissions over 384 days, indicating this is an established, widely-used library. The two triggered heuristics are false positives: the 'process injection' alert reflects rundll32.exe loading the DLL via standard export ordinal (#1), which is benign testing behavior, not malware smuggling code into a target process. The 'direct-IP C2' alert cites Cloudflare's public DNS resolver (162.159.36.2), not a malicious command server. No malicious sandbox verdict was recorded, no malicious children were dropped, and no malicious hosts were contacted. A prior MalwareTips verdict on a similar file (same signer, Microsoft Corporation) was verdicted safe with ai:benign_signed_installer reasoning.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. 0/71 engines malicious; tier1Malicious=0; 16 tier-1 engines (Kaspersky, BitDefender, ESET-NOD32, Fortinet, Avira, F-Secure, GData, Emsisoft, DrWeb, Avast, AVG) all silent

  2. signing.verified=true, signer='Microsoft Corporation', trustedPublisher.matched=true; signerStats 2/2 safe (100% safeRate)

  3. prevalence.classification='common_old' — 2148 submitters, 2561 submissions over 384 days; established commodity file

  4. behaviour: T1055 and T1562.001 triggered by sandbox rundll32 harness, not malware injection; hasMaliciousSandboxVerdict=false; contacted IP 162.159.36.2 is Cloudflare DNS, not C2

  5. similarHashes: 1 prior verdict (signer=Microsoft) verdicted 'safe' with ai:benign_signed_installer; droppedChildren 0/10 malicious

Points in its favour
  • Signed by Microsoft Corporation with verified Authenticode certificate
  • Zero malicious detections across 71 engines; 16 tier-1 vendors all clean
  • 2,561 submissions from 2,148 sources over 384 days with no reputation damage
  • No malicious sandbox verdict; no malicious dropped children; no malicious contacted hosts
  • Prior MalwareTips verdict on similar file (same signer) was safe
What to do

This file is safe. No action is required. The heuristic alerts are false positives triggered by sandbox testing behavior and should be disregarded.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
17

Adversary techniques mapped to the MITRE ATT&CK framework.

T1012T1027T1027.002T1027.005T1055T1057T1071T1082T1083T1095T1129T1218.011T1497T1518.001T1542.003T1562.001T1574.002
Spawned processes
15
$(unnamed)
"C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\libharfbuzzsharp.dll",#1
$(unnamed)
C:\Windows\system32\WerFault.exe -u -p 6628 -s 540
$(unnamed)
C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\libharfbuzzsharp.dll"
$(unnamed)
C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
$(unnamed)
C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\libharfbuzzsharp.dll",#1
$(unnamed)
C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\libharfbuzzsharp.dll",#1
$(unnamed)
C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 4476 -s 376
$(unnamed)
C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\libharfbuzzsharp.dll,hb_aat_layout_feature_type_get_name_id
+7 more processes captured.
Network activity
1
IP addresses1
  • 162.159.36.2
Filesystem & mutexes
31
Files written15
  • C:\ProgramData\Microsoft\Windows\WER\Temp
  • C:\ProgramData\Microsoft\Windows\WER\Temp\80307abc-c441-4f2f-8b97-dc2589e3b632
  • C:\ProgramData\Microsoft\Windows\WER\ReportQueue
  • C:\ProgramData\Microsoft\Windows\WER\Temp\8c5a3114-f5fd-4ba6-856a-523e5b23ed52
  • C:\ProgramData\Microsoft\Windows\WER\ReportArchive
+10 more
Files deleted6
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WERC469.tmp
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WERCBAD.tmp
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WERCD25.tmp
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WERC469.tmp.dmp
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WERCBAD.tmp.WERInternalMetadata.xml
+1 more
Mutexes created10
  • Local\WERReportingForProcess6628
  • Global\AmiProviderMutex_InventoryApplicationFile
  • Global\5d821f5f-0f90-4d6e-81eb-649092548fcf
  • \Sessions\1\BaseNamedObjects\Local\SessionImmersiveColorMutex
  • \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess4476
+5 more
Dropped payload

Files this sample writes at runtime

This file drops 10 children at runtime. None are currently flagged malicious in our cache.

10 unseen
  • fb6f9761d0c44e0b1442b51b06Never scanned
    never seen before
  • 0a9bf95d07e50066ab4821569aNever scanned
    never seen before
  • 1a667aa6692c2a8fbce5b43901Never scanned
    never seen before
  • 3b6a7b149e414539b365bca9cbNever scanned
    never seen before
  • 6c8f67571cc893181ba6c46ae9Never scanned
    never seen before
  • ec175d46e7552f97d9cd98a633Never scanned
    never seen before
  • 3b7d176e3acd50997527f88550Never scanned
    never seen before
  • eb5b4cfb7d91745ad196825b90Never scanned
    never seen before
  • b78c1b98a380339644015490dbNever scanned
    never seen before
  • 031503d3fca114389788985df3Never scanned
    never seen before
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

2 synthesis
MITRE ATT&CK profile
Defense evasion× 1C2× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    "C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\libharfbuzzsharp.dll",#1
  • DirectIpC2medium

    Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    162.159.36.2
Antivirus engine breakdown

0 detections across 75 engines

0 malicious0 suspicious75 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust20 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 75 engines report this file as clean.
Hash eb76238c9e8e… cross-referenced against 75 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

ent 7.50Unpacked
Section entropy7 sections
.text
6.58
.rdata
5.99
.data
2.70
.pdata
6.18
_RDATA
2.68
.rsrc
4.72
.reloc
5.12
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.

Common & old
Unique uploaders
2,148
Hundreds of people have uploaded this — common.
Total submissions
2,561
Includes repeat uploads by the same source.
First seen by VT
1y ago
May 22, 2025
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
here
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
5/22/2025, 4:17:08 AM
First seen (MalwareBazaar)
Last analysis (VT)
6/6/2026, 7:17:15 PM
Scanned here
6/10/2026, 9:39:45 AM
File name
libHarfBuzzSharp.dll
Size
1.72 MB
MIME type
(unknown)
Detected type
Win32 DLL
SHA-256
eb76238c9e8e41d44b5a5b18167c4c5b39ca5db4277af5dbe92d730f0fc14a7d
MD5
e0c86bbd88d6b8f5643c1ab1c050a4ee
SHA-1
f6c72b1fd89d0f9e3d7825a0450ae0c0af092c5a
PE imphash
ec7fff8f58c3f1ed14aaf7c661442137
First seen (VT)
5/22/2025, 4:17:08 AM
Last analysis (VT)
6/6/2026, 7:17:15 PM
First scan (MalwareTips)
6/10/2026, 9:39:45 AM
Last scan (MalwareTips)
6/10/2026, 9:39:45 AM
Code signer
Microsoft Corporationverified
Behavior tags
64bitssignedoverlaypedlldetect-debug-environment
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.