Is photocraft-0.3.0-windows-x64.msi safe?
No antivirus engine detected malware, but unverified runtime interpretations involving process injection, LSASS, and direct-IP traffic warrant caution with this newly observed installer.
All 75 antivirus engines avoided a malware finding, and the MSI has a verified signature from Learning Machines Inc. However, its publisher lacks established history, while one sandbox run produced heuristic indications involving process injection, LSASS, service activity, and direct-IP connections whose reputation was not checked completely.
2b3e1bfdacfb597c1c…d1c823d77e9db6Recommended next actions
Before installing
Do not install it until the source and publisher can be verified independently.
If you already installed it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Download a fresh installer from the developer's official site or an official app store.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 75 antivirus engines avoided a malware finding, and the MSI has a verified signature from Learning Machines Inc. However, its publisher lacks established history, while one sandbox run produced heuristic indications involving process injection, LSASS, service activity, and direct-IP connections whose reputation was not checked completely.
The strongest reassuring signal is that 0 of 75 engines flagged the file, including no findings from 17 tier-1 engines. The installer is signed and verified by Learning Machines Inc, although that signer is neither curated nor supported by historical sample statistics. One completed sandbox run did not issue a malicious finding, but derived heuristics mapped activity to T1055 and T1543.003 and highlighted LSASS-related process activity. The saved evidence does not establish an actual LSASS memory read, injection operation, or malicious service installation, so those heuristic findings are not conclusive. Several direct IP connections were recorded, and no complete host-reputation result is available. These mixed signals justify caution rather than treating the runtime alerts as proof of malware.
What We Detected
None of 75 antivirus engines flagged the MSI, and all 17 reporting tier-1 engines were undetected. The package carries a verified signature from Learning Machines Inc, but that publisher has no stored signer history and is not on the curated trusted-publisher list.
Threat Behavior
One completed sandbox run did not produce a malicious verdict. Derived heuristics nevertheless mapped activity to process injection (T1055) and service creation or modification (T1543.003), and highlighted LSASS-related activity. The retained evidence identifies system processes but does not demonstrate a memory read, concrete injection action, or malicious persistence. The sample also contacted several IP addresses directly; because contactedHosts is unavailable, no complete reputation result exists for those contacts.
What To Do Now
Confirm that the installer came from the developer's official release channel and verify the Learning Machines Inc signature locally before running it. Keep endpoint protection enabled, and use an isolated environment if the publisher or download source cannot be independently confirmed.
Where this verdict could be wrong4 caveats
- The verified 'Learning Machines Inc' signature and 0/75 engine detections weigh toward benign software, but signing.signerStats.found=false leaves the publisher without established history.
- The completed sandbox labeled the run clean, although a single run may not exercise every code path.
- The T1055 and credential-dumping heuristics may overinterpret ordinary system processes because the saved evidence does not demonstrate an LSASS memory read or a concrete injection action.
- The installer reached several IP addresses, but contactedHosts=null means their reputation was not completely assessed.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 antivirus engines reported a malicious or suspicious result
- All 17 reporting tier-1 engines were undetected
- Code signature for Learning Machines Inc verified successfully
- The completed sandbox produced no malicious verdict
- 289 unique sources submitted the file 301 times
- Newly observed file with only one day of history
- No established sample history for signer Learning Machines Inc
- Runtime heuristic mapped activity to T1055 process injection
- Runtime heuristic highlighted LSASS-related process activity
- Direct-IP connections lack a complete host-reputation check
- No similar-hash history or researcher-rule corroboration
Use the installer only after confirming its official source and verifying the Learning Machines Inc signature. Keep endpoint protection enabled and isolate execution if provenance remains uncertain.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial4 runtime contacts were observed without a completed reputation cross-check.
YARA
Complete3 signature or behavior rules matched.
External intel
PartialIndependent reference checks were attempted but are incomplete.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 8MITRE ATT&CK techniques
- 9spawned processes
- 4network contacts
- 13filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Used removable-media replication behaviour that can spread files between devices.
High concern: Created or modified a system service, which can keep code running.
Note: Reads your Windows user-account details.
Note: Collects details about your system.
Note: Connected to 4 servers during sandbox analysis.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
photocraft-0.3.0-windows-x64.msi
2b3e1bfdacfb597c1cab783c9ed14ed59854cc4bf11f333973d1c823d77e9db6
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\system32\msiexec.exe" /I "C:\Users\<USER>\Desktop\photocraft-0.3.0-windows-x64.msi" /qb ACCEPTEULA=1 LicenseAccepted=1
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\system32\services.exe
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Download-1.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
04Isolated runtime analysis - Written fileObserved
photocraft-cli.exe
C:\Program Files\PhotoCraft\photocraft-cli.exe
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
8.8.8.8
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
199.232.210.172
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 8.8.8.8
- 199.232.210.172
- 204.79.197.203
- 23.34.126.68
- F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\Blob
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress\(Default)
- HKEY_CLASSES_ROOT\Photocraft.Document\shell\open\command\(Default)
- HKEY_CLASSES_ROOT\Photocraft.PhotoshopDocument\shell\open\command\(Default)
- HKEY_CLASSES_ROOT\Photocraft.Image\shell\open\command\(Default)
- HKEY_CLASSES_ROOT\Applications\photocraft.exe\shell\open\command\(Default)
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
- C:\Program Files\PhotoCraft\photocraft-cli.exe
- C:\Program Files\PhotoCraft\photocraft.exe
- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoCraft.lnk
- C:\MSIa55bd.tmp
- C:\MSIa55bd.tmp
- Global\_MSIExecute
- \Sessions\1\BaseNamedObjects\Global\_MSIExecute
- \BaseNamedObjects\Local\SM0:6596:304:WilStaging_02
- \BaseNamedObjects\Local\SM0:6596:120:WilError_03
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 3rule hits recorded
- 0 / 75engines flagged
- 289sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
0 of 75 antivirus engines flagged the file.
ProvenanceObservedSourceAntivirus analysisObserved at - 03
The file has a valid code signature from Learning Machines Inc.
ProvenanceObservedSourceCode-signing metadataObserved at - 04
Scanned file: photocraft-0.3.0-windows-x64.msi — 2b3e1bfdacfb597c1cab783c9ed14ed59854cc4bf11f333973d1c823d77e9db6
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\system32\msiexec.exe" /I "C:\Users\<USER>\Desktop\photocraft-0.3.0-windows-x64.msi" /qb ACCEPTEULA=1 LicenseAccepted=1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\services.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Download-1.tmp — C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: photocraft-cli.exe — C:\Program Files\PhotoCraft\photocraft-cli.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 8.8.8.8 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: 199.232.210.172 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeThe sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence199.232.210.172 · 204.79.197.203 · 23.34.126.68
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.
Fingerprint and provenance
- File name
- photocraft-0.3.0-windows-x64.msi
- Format
- Windows Installer
- Code signing
- Signature valid: Learning Machines Inc
- Size
- 51.4 MB
- Last analyzed
- Oct 8, 2026, 11:23 AM UTC
2b3e1bfdacfb597c1cab783c9ed14ed59854cc4bf11f333973d1c823d77e9db6Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't install it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Download a fresh installer from the developer's official site or an official app store.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is photocraft-0.3.0-windows-x64.msi safe, or is it malware?
What is photocraft-0.3.0-windows-x64.msi?
How many antivirus engines detected photocraft-0.3.0-windows-x64.msi?
I already downloaded and installed photocraft-0.3.0-windows-x64.msi — what should I do?
How do I remove photocraft-0.3.0-windows-x64.msi?
Is photocraft-0.3.0-windows-x64.msi digitally signed?
What is the SHA-256 hash of photocraft-0.3.0-windows-x64.msi?
How up to date is this analysis of photocraft-0.3.0-windows-x64.msi?
Community
Member reviews and reports for this exact file hash.