sqlite3.dll file report

MD5 a7eb9b964f90ea00cf72bf95cfd158d2
Latest seen 2024-12-07 23:05:03 (a year ago)
First seen 2024-12-07 23:05:03 (a year ago)
Size 1 MB
Product SQLite

Why it matters

Evidence available for this file

Detection

No final classification is available yet.

Timeline

First seen 2024-12-07 23:05:03 (a year ago); latest analysis 2024-12-07 23:05:03 (a year ago).

Publisher context

Company metadata: SQLite Development Team. Product metadata: SQLite.

Digital signature

Signed by LizardSystems (Vitali Ivanovich Zagorovski, IP). The signature is reported as valid, but signed files can still be bundled or abused.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Use the hash and metadata below to verify the exact file identity.
  2. Review publisher, signature, paths, and PE details for inconsistencies.
  3. Run a local scan if the file appears unexpectedly or starts with Windows.

sqlite3.dll is a Windows file recorded in the ThreatInfo database. It is associated with SQLite. The reported company name is SQLite Development Team. The current detection status is Undefined, based on the latest analysis from 2024-12-07 23:05:03 (a year ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

Product Name: SQLite
Company Name: SQLite Development Team
MD5: a7eb9b964f90ea00cf72bf95cfd158d2
Size: 1 MB
First Published: 2024-12-07 23:05:03 (a year ago)
Latest Published: 2024-12-07 23:05:03 (a year ago)
Status: Undefined (on last analysis)
Analysis Date: 2024-12-07 23:05:03 (a year ago)

The signature on sqlite3.dll is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%localappdata%

ThreatInfo has observed sqlite3.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is United States with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for sqlite3.dll is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

sqlite3.dll is identified as pe for 32 systems. The subsystem is Windows CUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x61e00000
Entry Address: 0x00001400

PE Sections:

Name Size of data MD5
.text 730624 0a5bcc3986bb4572ee58ccd7ab2dbcbe
.data 10240 bfcee22adea648b096222c315a243859
.rdata 83456 94a51dff97bb5dfd60bcebf3fcd2a11a
.bss 0 d41d8cd98f00b204e9800998ecf8427e
.edata 11264 b874946ffada6c84f8ce58af060c6780
.idata 3584 babe1772ea552a620c9f422179d8118d
.CRT 512 aab4be610b108f34c27d874b31fb9463
.tls 512 c96e597f35f28ef79f86b2b585e50d3f
.rsrc 1536 4d6ee1bf78f870ada8a02a4241038f9c
.reloc 15872 e3e809ff9dfba568e7ad6877d8f979bc
/4 1536 0eed780578ce3973945e0e304d1028a4
/19 51712 491eceafbc0d27f20848c2db70f2eb03
/31 10240 2acd32ceee2eabb1b41b2156475cf2bf
/45 11776 8b66b76a47aadbadd39685872569e27f
/57 3072 6cfdb8e4956cf3e5cd0fd0bdd07627c9
/70 1024 2030959f875392ef618b84f7bea8535a
/81 15360 51642d84ad89c5891f7418af580540c7
/92 1024 12f4aae57e6ac90fc06369b130799fcf

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: