GridinSoft Threat Intelligence
SAntivirusShell64_v102228.dll file report
Why it matters
Evidence available for this file
No final classification is available yet.
First seen 2021-05-06 20:59:52 (5 years ago); latest analysis 2024-04-11 23:05:57 (2 years ago).
Signed by Digital Communications Inc. The signature is reported as valid, but signed files can still be bundled or abused.
ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.
Recommended action
What to do next
- Use the hash and metadata below to verify the exact file identity.
- Review publisher, signature, paths, and PE details for inconsistencies.
- Run a local scan if the file appears unexpectedly or starts with Windows.
File context
SAntivirusShell64_v102228.dll is a Windows file recorded in the ThreatInfo database. It is associated with Сorp DCom . The reported company name is Сorp DCom . The current detection status is Undefined, based on the latest analysis from 2024-04-11 23:05:57 (2 years ago).
ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.
File Details
| Product Name: | Сorp DCom |
| Company Name: | Сorp DCom |
| MD5: | 9644dc2b51e834ec7f18264132ee27c0 |
| Size: | 183 KB |
| First Published: | 2021-05-06 20:59:52 (5 years ago) |
| Latest Published: | 2024-04-11 23:05:57 (2 years ago) |
| Status: | Undefined (on last analysis) | |
| Analysis Date: | 2024-04-11 23:05:57 (2 years ago) |
Overview
| Signed By: | Digital Communications Inc |
| Status: | Valid |
The signature on SAntivirusShell64_v102228.dll is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.
Common Places:
| %programfiles%\digital communications |
| %commonappdata%\santivirus |
ThreatInfo has observed SAntivirusShell64_v102228.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.
Geographic signal
Observed country distribution
ThreatInfo has seen SAntivirusShell64_v102228.dll across 11 countries. Use this signal to compare local evidence with where the sample is most often reported.
The strongest geographic signal for this file is Philippines with 13.3% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.
OS Version:
The most common operating system signal for SAntivirusShell64_v102228.dll is Windows 10 with 68.8% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.
Analysis
SAntivirusShell64_v102228.dll is identified as pe for 64-bit systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.
PE Sections:
Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.
1ae110cb1d29728d753a219a11fc118e
726dcc221e572298d1191a02bea8064c
5fb207aa20dfd571e9a7c43de5e766e2
3ebf77f53e70a585aba0bc120afeae41
0afc365f640ec80ed3889d858a8977ff
78ab99119008f683ee4a54bfd1610621
b4f8bca2c7019b75ae3c84473ac1a35f
2d87fe1b5bf1825e103a13aa68ded6e3
1f8b6493cb5c4ad2daef9a50ba5236e3
116996e2d15176f467b184672eba5360
d9ebce1d9733193a863bc076db70f9e2
cbfe65e97e30967d811b246bdbd02e8a
36f6c60bcf4adbc46e073c069ed45e39
5f11d1bbb386df4cce85ab9d3c8a0291
ed8dc2c7e00e8d646a944bfc3b8bafbc
1537dd1c3b46b9fe6d8cacbe6940af0a
59f33e08623526a4a0aa8cecdd057197
c058a62c03127831b35166a1a706b780
f18d3b0f2c42b66d08ca10d5b78215a8
5316aaae07cd241a0b953d4d724a69e0
cb061016ccad9af1f7c00614f8f0ecdf
2c0a3d707d8c3e682888242f94a0d7a5
1f354d76203061bfdd5a53dae48d5435
b0701be232db651e502cb6874e274862
6b22fc6a9fa7d9f44ca744aa140420fa
PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.
Report conclusion
This file is still under review
ThreatInfo has not assigned a final verdict yet. Compare the file hash, location, signature, and publisher before trusting the file on a production system.