File verdict·Decided by the MT AI Engine
Our call

Suspicious

Unsigned 5 KB .NET installer shows process-injection and direct-IP C2 behaviour yet zero AV detections.

Trust score45Caution
dotnetinstaller.exe
5.5 KB
dc6f18f38ad199ceb941bfb16ef9
Antivirus engines
0 of 74 flagged
Code signing
Unsigned
Age
First seen 17y ago
MT AI Engine · Verdict analysis

The reasoning behind this verdict

The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.

55%Confidence
Moderate
Reasoning

Zero malicious detections across 70 reporting engines, including 17 tier-1, rules out strong malware consensus. However, the file is unsigned, exhibits three offensive MITRE techniques (T1055, T1562.001, T1620), and triggered two high/medium heuristics for process injection and direct-IP C2. Similar-hash RAG is split, with one malicious imphash match and a CIRCL reference to malshare.com. Prevalence is high and old, yet the behavioural signals and adversarial comment flag keep the file in mixed-signals territory.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines: 0/74 malicious, tier1Malicious=0

  2. behaviour.offensiveTechniques: T1055, T1562.001, T1620

  3. triggeredHeuristics: MalwareTips.Synth.ProcessInjection (high), MalwareTips.Synth.DirectIpC2 (medium)

  4. externalIntel.circl.knownMalicious=malshare.com

  5. similarHashes[4].verdict=malicious (matchKind=imphash)

Points in its favour
  • Zero detections across 70 engines
  • Common_old prevalence (448 submissions)
  • Joe Sandbox clean verdict
Points against
  • Unsigned binary
  • Process injection (T1055) observed
  • Direct-IP C2 without DNS
  • CIRCL hit on malshare.com
  • Adversarial comment flag present
Recommended action

Treat as suspicious pending further behavioural analysis or updated engine coverage; avoid execution until additional context is available.

What this file does

What it attempted when executed in an isolated sandbox

  • High concern: Hides inside another running program to evade antivirus.

  • High concern: Talks to a remote server to take commands or send out your data.

  • High concern: Tries to disable or bypass your security software.

  • High concern: Loads hidden code straight into memory to dodge scanners.

  • Moderate concern: Checks whether it's being watched in a sandbox before acting.

  • Note: Collects details about your system.

Translated from the file's technical behaviour during analysis. It never ran on your device.

What to do now

We couldn't fully clear this file. Treat it with caution.

  1. Don't run it unless you're certain it came from a source you trust.

  2. Check where you got it — an email attachment or a random download link is a red flag.

  3. If you're unsure, delete it. You can always re-download a clean copy from the official source.

  4. If you're still unsure, scan it again in a day or two — detections often catch up on newer files.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
7

Adversary techniques mapped to the MITRE ATT&CK framework.

T1036T1055· Process injectionT1071· Remote server (C2)T1082· System reconT1497· Sandbox evasionT1562.001· Disables securityT1620· In-memory loading
Spawned processes
14
$(unnamed)
"C:\Users\<USER>\AppData\Local\Temp\file.exe"
$(unnamed)
"C:\Windows\system32\fondue.exe" /enable-feature:NetFx3 /caller-name:mscoreei.dll
$(unnamed)
"C:\Windows\sysnative\FonDUE.EXE" /enable-feature:NetFx3 /caller-name:mscoreei.dll
$(unnamed)
"C:\Windows\system32\OptionalFeatures.EXE" /enable-feature:NetFx3 /caller-name:mscoreei.dll
$(unnamed)
C:\Windows\system32\services.exe
$(unnamed)
C:\Windows\system32\svchost.exe -k DcomLaunch -p
$(unnamed)
C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
$(unnamed)
C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
+6 more processes captured.
Network activity
17
IP addresses11
  • 151.139.31.76
  • a83f:8110:7300:6b00:7600:6f00:6c00:7500
  • 20.99.133.109
  • 192.229.211.108
  • 23.216.81.152
  • 192.168.0.33
  • 192.168.0.29
  • 20.69.140.28
  • 23.196.193.245
  • 23.55.140.42
+1 more
URLs6
  • http://151.139.31.76/filestreamingservice/files/61ece5c0-b56e-46c8-9f21-205d42502371/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
  • http://151.139.31.76/filestreamingservice/files/cdd505a5-b16f-4c68-a000-442b3d554622?P1=1716457515&P2=404&P3=2&P4=Puw2SyvEQBOZ9ipecJs+d6/haBvPw7Z0LaZLUNdN9CmSq3OWZkD/mvtq3zUzfyv0QoTmehVZ72PLR/ctsYDzWQ==&cacheHostOrigin=tlu.dl.delivery.mp.microsoft.com
  • http://151.139.31.76/filestreamingservice/files/cdd505a5-b16f-4c68-a000-442b3d554622/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
  • http://151.139.31.76/filestreamingservice/files/61ece5c0-b56e-46c8-9f21-205d42502371?P1=1716457555&P2=404&P3=2&P4=GeWFUnxBqtAYaRbmGFEEZdv3aNjv/NYAJe3IylVB3letd7ZRGOvTuKAOrUX5hijwdlXZ4K6vLR7edRRYKK/qLA==&cacheHostOrigin=tlu.dl.delivery.mp.microsoft.com
  • http://151.139.31.76/filestreamingservice/files/e0d94aa6-d6c1-47f5-8b3a-06050b8d0f94/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
  • http://151.139.31.76/filestreamingservice/files/e0d94aa6-d6c1-47f5-8b3a-06050b8d0f94?P1=1716458728&P2=404&P3=2&P4=nJPZRiaeZzuJ9OoOjlsyh1PyqJT+QMpJlCbZJwEPUnrIKK1v7uIB2QXjC44PpRH+fMGykROL586AT0fuNirvEA==&cacheHostOrigin=tlu.dl.delivery.mp.microsoft.com
Filesystem & mutexes
17
Files written4
  • C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\file.exe.log
  • C:\Users\user\AppData\Roaming
  • \Device\ConDrv\\Connect
  • C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\executable.exe.log
Files deleted7
  • C:\Windows\System32\spp\store\2.0\cache\cache.dat
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER21BB.tmp.WERInternalMetadata.xml
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER21DC.tmp.WERInternalMetadata.xml
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER2296.tmp.csv
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER22C7.tmp.txt
+2 more
Mutexes created6
  • CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
  • CTF.Compart.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
  • CTF.Asm.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
  • CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
  • CTF.TMD.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
+1 more
Dropped payload

Files this sample writes at runtime

This file drops 6 children at runtime. None are currently flagged malicious in our cache.

6 unseen
  • 91917667236d097f90a02a7787Never scanned
    never seen before
  • 4d95e550b47c0122b96c269379Never scanned
    never seen before
  • 0b890468db86011444aebcc399Never scanned
    never seen before
  • ba2e116461fdd97763fee78649Never scanned
    never seen before
  • 6782702f5bb297c1c7f8853df3Never scanned
    never seen before
  • 7a23c6e7ccd8811ecdf0fa9432Never scanned
    never seen before
External threat intelligence

1 corroborating signal from researcher-curated sources

CIRCL hashlookup HIT·indexed as known-malicious·trust 30/100View on CIRCL
nsrl_legacyResident Evil 3 Nemesis· DotNetInstaller.exe
Also flagged as malicious by malshare.com. The reference-DB hit is not a clean signal on its own — the verdict defers to VT, AI, and the abuse.ch sources.
Cross-referenced against MalwareBazaar (abuse.ch), YARAify, and the CIRCL hashlookup reference DB.
Signature matches

YARA & heuristic rule matches

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

2 synthesis
MITRE ATT&CK profile
Defense evasion× 1C2× 1
MalwareTips synthesis rules
Our own detection rules, applied to the scan data and sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    C:\Windows\system32\svchost.exe -k DcomLaunch -p
  • DirectIpC2medium

    Sample contacted 9 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    151.139.31.76 · a83f:8110:7300:6b00:7600:6f00:6c00:7500 · 20.99.133.109
Antivirus engine breakdown

0 detections across 74 engines

0 malicious0 suspicious74 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-240 engines
0flag
Mainstream engines with mixed FP rates
Low-trust17 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 74 engines report this file as clean.
Hash dc6f18f38ad1… cross-referenced against 74 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

Unpacked
Section entropy3 sections
.text
4.64
.rsrc
2.69
.reloc
0.08
0.0Packed threshold 7.28.0
Prevalence

How widely this file has been seen

Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.

Common & old
Unique uploaders
120
Hundreds of people have uploaded this — common.
Total submissions
448
Includes repeat uploads by the same source.
First seen
17y ago
Mar 7, 2009
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
here
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
3/7/2009, 8:19:16 PM
First seen (MalwareBazaar)
Last analysis (VT)
7/3/2026, 9:18:51 PM
Scanned here
7/19/2026, 7:54:48 AM
File name
dotnetinstaller.exe
Size
5.5 KB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
dc6f18f38ad199ceb9f7be94316aeb46b156bcb040059b5f60acde41bfb16ef9
MD5
19d3dc3c2159c407800d69089ba8ce3d
SHA-1
636c1ce473252ab09fdc6d1d95658530dd413da8
PE imphash
f34d5f2d4577ed6d9ceec516c1f5a744
First seen (VT)
3/7/2009, 8:19:16 PM
Last analysis (VT)
7/3/2026, 9:18:51 PM
First scan (MalwareTips)
7/19/2026, 7:54:48 AM
Last scan (MalwareTips)
7/19/2026, 7:54:48 AM
Community reputation
+33trusted
Behavior tags
assemblyknown-distributorpeexedetect-debug-environmentlong-sleepsnsrlruntime-modulesdirect-cpu-clock-access
Frequently asked

Safety FAQ

Common questions about dotnetinstaller.exe, answered from the scan data above.

  • dotnetinstaller.exe is suspicious — treat it as unsafe until you're sure. 0 of 74 antivirus engines flag it, which isn't a strong consensus but is enough to be cautious. Don't run it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
  • dotnetinstaller.exe is a Windows executable program, about 6 KB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
  • None — all 74 antivirus engines we queried report dotnetinstaller.exe as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
  • Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
  • To remove dotnetinstaller.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original dotnetinstaller.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
  • The SHA-256 hash of dotnetinstaller.exe is dc6f18f38ad199ceb9f7be94316aeb46b156bcb040059b5f60acde41bfb16ef9, and its MD5 is 19d3dc3c2159c407800d69089ba8ce3d. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on July 19, 2026. Because a file's hash never changes, the identity of dotnetinstaller.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.