Is REDGalaxy.dll safe?
No engine detected this established, correctly signed CD PROJEKT library, while matching publisher samples consistently received clean historical assessments.
All 74 antivirus engines returned no malicious or suspicious detection, including 16 tier-1 engines, and the signature from CD PROJEKT S.A. verifies correctly. Although one sandbox mapped several offensive-capable techniques and observed direct-IP traffic, it produced no malicious runtime verdict, and five closely related publisher samples have clean histories.
a3f774f5c037e51cf8…fe596da74486d2Recommended next actions
Before using
Use it only as part of software obtained from the developer's official site or another source you independently trust.
If you already used it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 74 antivirus engines returned no malicious or suspicious detection, including 16 tier-1 engines, and the signature from CD PROJEKT S.A. verifies correctly. Although one sandbox mapped several offensive-capable techniques and observed direct-IP traffic, it produced no malicious runtime verdict, and five closely related publisher samples have clean histories.
The strongest evidence is complete detection silence: 0 of 74 engines flagged the DLL, including no tier-1 detections. Its digital signature verifies as CD PROJEKT S.A., with no detected conflict between the claimed brand and signer. The file is established across 120 sources, and five related samples from the same signer previously received clean assessments, including one matching both imphash and signer. One sandbox mapped T1055, T1560, and T1562.001 and observed a direct IP connection, but did not issue a malicious verdict or identify a malicious child. Because the contacted-host reputation check is unavailable, the no complete contacted-host reputation result was available, but this limitation does not outweigh the broad independent evidence.
What We Detected
No malicious or suspicious result appeared among 74 antivirus engines, and 16 tier-1 engines reported no detection. The DLL carries a verified signature from CD PROJEKT S.A., with no detected brand mismatch. It has also circulated for 374 days across 120 sources and 134 submissions.
Threat Behavior
One completed sandbox run mapped activity to T1055, T1560, and T1562.001 and recorded a connection to 135.233.45.223. These techniques can be security-relevant, but the sandbox did not issue a malicious verdict, no persistence indicators were recorded, and none of three inspected children was identified as malicious. A complete reputation check for the contacted IP is unavailable.
What To Do Now
Use the DLL only when it comes from an official CD PROJEKT installation or trusted update channel. If it appeared unexpectedly or outside its normal application directory, verify the signature and reinstall the associated software from its official source while keeping endpoint protection enabled.
Where this verdict could be wrong3 caveats
- behaviour.offensiveTechniques records T1055, T1560, and T1562.001, including a possible process-injection mapping.
- triggeredHeuristics includes MalwareTips.Synth.DirectIpC2 for contactedIps[0] '135.233.45.223'; contactedHosts=null means its reputation was not completely checked.
- The three dropped children were inspected but remain unknown rather than affirmatively benign.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 engines reported a malicious or suspicious result.
- Verified digital signature from CD PROJEKT S.A.
- Five of five similar signed samples previously received clean assessments.
- Established prevalence across 120 sources and 134 submissions.
- No malicious sandbox verdict or identified malicious child.
- Runtime mapping includes offensive-capable techniques T1055, T1560, and T1562.001.
- Direct connection to 135.233.45.223 lacks a completed host-reputation cross-check.
- Three dropped children remain unclassified, although none is currently identified as malicious.
Allow it when obtained with official CD PROJEKT software and the verified signature remains intact. Investigate unexpected copies or unusual installation paths, and keep endpoint protection enabled.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 runtime contact was observed without a completed reputation cross-check.
YARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 11MITRE ATT&CK techniques
- 15spawned processes
- 1network contacts
- 2filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
REDGalaxy.dll
a3f774f5c037e51cf87ab839599f532af6a06ac662b3fb280cfe596da74486d2
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\REDGalaxy64.dll",#1
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\REDGalaxy64.dll"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Connect
\Device\ConDrv\\Connect
04Isolated runtime analysis - Dropped fileDerived
59c25a125ee41df1345c4088f4534d178dde090593d041934b443b95000339df
No child-file verdict was available.
05Dropped-file analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
135.233.45.223
Contact observed during runtime.
06Isolated runtime analysis
6 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 135.233.45.223
- \Device\ConDrv\\Connect
- \Sessions\1\BaseNamedObjects\Local\SessionImmersiveColorMutex
Files this sample writes at runtime
This file drops 3 children at runtime. None are currently flagged malicious in our cache.
- 59c25a125ee41df1345c…0339dfNever scannednever seen before
- 9568d8e1efcc67881f6e…d5004cNever scannednever seen before
- f8b79de75501f244e150…eb92afNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 2rule hits recorded
- 0 / 74engines flagged
- 120sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 120 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
The file has a valid code signature from CD PROJEKT S.A..
ProvenanceObservedSourceCode-signing metadataObserved at - 04
Scanned file: REDGalaxy.dll — a3f774f5c037e51cf87ab839599f532af6a06ac662b3fb280cfe596da74486d2
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\REDGalaxy64.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\REDGalaxy64.dll"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Connect — \Device\ConDrv\\Connect
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Dropped file: 59c25a125ee41df1345c4088f4534d178dde090593d041934b443b95000339df — No child-file verdict was available.
ProvenanceDerivedSourceDropped-file analysisObserved at - 09
Contacted host: 135.233.45.223 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\REDGalaxy64.dll",#1The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence135.233.45.223
0 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- REDGalaxy.dll
- Format
- Win32 DLL
- Code signing
- Signature valid: CD PROJEKT S.A.
- Size
- 13.6 MB
- Last analyzed
- Sep 23, 2026, 5:27 AM UTC
a3f774f5c037e51cf87ab839599f532af6a06ac662b3fb280cfe596da74486d2Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Use it only as part of software obtained from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is REDGalaxy.dll safe?
What is REDGalaxy.dll?
How many antivirus engines detected REDGalaxy.dll?
Is REDGalaxy.dll digitally signed?
What is the SHA-256 hash of REDGalaxy.dll?
Is it safe to use REDGalaxy.dll?
How up to date is this analysis of REDGalaxy.dll?
Community
Member reviews and reports for this exact file hash.