WWanHC.dll

MD5 Hash: e6fa7acc9b6ead4b72a28bef0351ac19
SHA256 Hash: 7d8be6ecfe719e78e1cdaad4e076d4b19b5fa5d4f91a183bc1dc0a35e6326166
File size: 56320 bytes (55 KB.)
Last analysis: 11 Jul, 2019 07:27:40

Analysis MD5: e6fa7acc9b6ead4b72a28bef0351ac19

Analysis of the file classifies it as a class A (Safe). The file is safe to use. The trust index of this analysis is 54 % (moderate).We would like to receive a copy of this file for further analysis..

A
B
C
D+
D
D-
E+
E
E-
F

Description

WWanHC.dll is part of WWanHC plugin developed by Microsoft Corporation. This file is an important and required part of the Windows Operating system

Filename: WWanHC.dll (WWanHC plugin)
Threat analysis: Safe
Analysis trust:
54%
Recent activity:
First seen: 29 Mar, 2019
Last seen: 29 Mar, 2019
Last analysis: 11 Jul, 2019
Possible infection: Clean

WWanHC.dll WWanHC plugin

Application: Besturingssysteem Microsoft® Windows®
Developer: Microsoft Corporation
Stability:
75%
File version: 10.0.17134.1
File size: 56320 bytes (55 KB.)
Recent activity:
Historic activity:
MD5 hash: e6fa7acc9b6ead4b72a28bef0351ac19
SHA1 hash: 1199edd7d561cbc3631fec4dde139ce4eabfba68
SHA256 hash: 7d8be6ecfe719e78e1cdaad4e076d4b19b5fa5d4f91a183bc1dc0a35e6326166
C

File entropy

File entropy match: File code

This file contains (executable) code.

File signature

Dynamic Link Library

Dynamic-link library, or DLL, is Microsoft's implementation of the shared library concept in the Microsoft Windows and OS/2 operating systems.

The determination of a file type is done with a signature or magic-numbers. Files are identified using by comparing the first set of bytes in the file header. Using this method type of files are recognised no matter the extension used. This information is useful to for example recognise executable files cloaked as images or movies.


A

Fuzzy hash a.k.a. Context Triggered Piecewise Hashing

SSDEEP

Context Triggered Piecewise Hashing, also called Fuzzy Hashing, can match inputs that have homologies. Such inputs have sequences of identical bytes in the same order, although bytes in between these sequences may be different in both content and length. Comparing a fuzzyhash is a good way to detect morphing malware. Malware which include random code in every copy to change its properties. Agics uses ssdeep to make create a fuzzyhash.

SSDEEP: 768:2OElUY4gxyQvkxOipRK3K7aZTXEnH9KA0jOK6fyO/UYengHZIhJTP3M:7E+reyQvk90FxX40L6fNingHZIbTP3M

No match found


A

Online virus scanners

Detection ration:

2 %
A

VirusShare.com

Not available on virusshare.com

VirusShare.com is a repository of malware samples to provide security researchers, incident responders, forensic analysts, and the morbidly curious access to samples of live malicious code. Presence of the sample on this site indicates that the file is (Once considered) being malicious.
Website: virusshare.com
B

National Software Reference Library

Not on the nsrl list

The NSRL contains a collection of digital signatures of known, traceable software applications. There are application hash values in the hash set which may be considered malicious, i.e. steganography tools and hacking scripts.
Website: www.nsrl.nist.gov

A

Statistic analysis

Statistic analysis of the file

Deviates from other files with the same name (imitation)
The certificate can not be determined
This is a very common file
Normal code
B

Neural network analysis

Analysis: Low risk

A neural network is a type of artificial intelligence. It recognized patterns nog clear for a human viewer. Our neural network is surprisingly accurate in recognizing dangerous files. The value below is the predicted chance the file is malicious.

11%11 %

?

User feedback

Read feedback on this file from other users. Help other users by providing feedback yourself.

You can earn reputation points !

You are currently not logged in. Login, or Create an account

Feedback users:

There has been no user feedback provided yet.
You are not logged in. Only registered users can provide feedback. Login and help other users.

Login Create an account