Safe
Microsoft-signed libHarfBuzzSharp.dll with 384-day prevalence, zero malicious detections across 71 engines, and clean signer history.
eb76238c9e8e41d44b…0f0fc14a7dThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The evidence strongly supports a safe verdict. Zero malicious detections across 71 engines, including 16 high-trust vendors (Kaspersky, BitDefender, ESET-NOD32, Fortinet, Avira, F-Secure, GData, Emsisoft, DrWeb, Avast, AVG), establishes baseline safety. The file is legitimately signed by Microsoft Corporation with a verified certificate and a clean signer history (2/2 prior samples safe). Prevalence data shows 2,148 unique submitters and 2,561 total submissions over 384 days, indicating this is an established, widely-used library. The two triggered heuristics are false positives: the 'process injection' alert reflects rundll32.exe loading the DLL via standard export ordinal (#1), which is benign testing behavior, not malware smuggling code into a target process. The 'direct-IP C2' alert cites Cloudflare's public DNS resolver (162.159.36.2), not a malicious command server. No malicious sandbox verdict was recorded, no malicious children were dropped, and no malicious hosts were contacted. A prior MalwareTips verdict on a similar file (same signer, Microsoft Corporation) was verdicted safe with ai:benign_signed_installer reasoning.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
0/71 engines malicious; tier1Malicious=0; 16 tier-1 engines (Kaspersky, BitDefender, ESET-NOD32, Fortinet, Avira, F-Secure, GData, Emsisoft, DrWeb, Avast, AVG) all silent
signing.verified=true, signer='Microsoft Corporation', trustedPublisher.matched=true; signerStats 2/2 safe (100% safeRate)
prevalence.classification='common_old' — 2148 submitters, 2561 submissions over 384 days; established commodity file
behaviour: T1055 and T1562.001 triggered by sandbox rundll32 harness, not malware injection; hasMaliciousSandboxVerdict=false; contacted IP 162.159.36.2 is Cloudflare DNS, not C2
similarHashes: 1 prior verdict (signer=Microsoft) verdicted 'safe' with ai:benign_signed_installer; droppedChildren 0/10 malicious
- Signed by Microsoft Corporation with verified Authenticode certificate
- Zero malicious detections across 71 engines; 16 tier-1 vendors all clean
- 2,561 submissions from 2,148 sources over 384 days with no reputation damage
- No malicious sandbox verdict; no malicious dropped children; no malicious contacted hosts
- Prior MalwareTips verdict on similar file (same signer) was safe
This file is safe. No action is required. The heuristic alerts are false positives triggered by sandbox testing behavior and should be disregarded.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\ProgramData\Microsoft\Windows\WER\Temp
- C:\ProgramData\Microsoft\Windows\WER\Temp\80307abc-c441-4f2f-8b97-dc2589e3b632
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue
- C:\ProgramData\Microsoft\Windows\WER\Temp\8c5a3114-f5fd-4ba6-856a-523e5b23ed52
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERC469.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERCBAD.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERCD25.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERC469.tmp.dmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERCBAD.tmp.WERInternalMetadata.xml
- Local\WERReportingForProcess6628
- Global\AmiProviderMutex_InventoryApplicationFile
- Global\5d821f5f-0f90-4d6e-81eb-649092548fcf
- \Sessions\1\BaseNamedObjects\Local\SessionImmersiveColorMutex
- \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess4476
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- fb6f9761d0c44e0b1442…b51b06Never scannednever seen before
- 0a9bf95d07e50066ab48…21569aNever scannednever seen before
- 1a667aa6692c2a8fbce5…b43901Never scannednever seen before
- 3b6a7b149e414539b365…bca9cbNever scannednever seen before
- 6c8f67571cc893181ba6…c46ae9Never scannednever seen before
- ec175d46e7552f97d9cd…98a633Never scannednever seen before
- 3b7d176e3acd50997527…f88550Never scannednever seen before
- eb5b4cfb7d91745ad196…825b90Never scannednever seen before
- b78c1b98a38033964401…5490dbNever scannednever seen before
- 031503d3fca114389788…985df3Never scannednever seen before
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
Evidence"C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\libharfbuzzsharp.dll",#1Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence162.159.36.2
0 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- libHarfBuzzSharp.dll
- Size
- 1.72 MB
- MIME type
- (unknown)
- Detected type
- Win32 DLL
- SHA-256
- eb76238c9e8e41d44b5a5b18167c4c5b39ca5db4277af5dbe92d730f0fc14a7d
- MD5
- e0c86bbd88d6b8f5643c1ab1c050a4ee
- SHA-1
- f6c72b1fd89d0f9e3d7825a0450ae0c0af092c5a
- PE imphash
- ec7fff8f58c3f1ed14aaf7c661442137
- First seen (VT)
- 5/22/2025, 4:17:08 AM
- Last analysis (VT)
- 6/6/2026, 7:17:15 PM
- First scan (MalwareTips)
- 6/10/2026, 9:39:45 AM
- Last scan (MalwareTips)
- 6/10/2026, 9:39:45 AM
- Code signer
- Microsoft Corporationverified
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.