Is DHSInstaller-en.msi safe?
No antivirus engine detected this signed installer, but one sandbox associated its activity with process injection, defense impairment, and possible LSASS access.
All 75 antivirus engines were detection-free, and the MSI carries a verified signature. However, one sandbox mapped activity to T1055 and T1562.001 and surfaced possible LSASS interaction, while the signer has no established history, so execution warrants caution until the installer’s source and publisher are independently confirmed.
f2ac5776c5e8c2238d…78dceb2c74ce98Recommended next actions
Before installing
Do not install it until the source and publisher can be verified independently.
If you already installed it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Download a fresh installer from the developer's official site or an official app store.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 75 antivirus engines were detection-free, and the MSI carries a verified signature. However, one sandbox mapped activity to T1055 and T1562.001 and surfaced possible LSASS interaction, while the signer has no established history, so execution warrants caution until the installer’s source and publisher are independently confirmed.
The strongest reassuring evidence is that 0 of 75 engines detected the file, including all 17 reporting tier-1 engines. The MSI is signed and its signature verifies, but the publisher is not on the curated trusted list and has no historical sample record. One completed sandbox run mapped activity to process injection and defense impairment, with an additional heuristic associating observed process activity with LSASS. That run did not issue a malicious sandbox verdict, record persistence, or identify dropped payload hashes. The sole observed domain received no malicious or suspicious cache classification, and researcher intelligence produced no hits. These mixed findings favor caution rather than treating either the clean engine result or the behavioral mappings as conclusive alone.
What We Detected
None of 75 antivirus engines detected the MSI, including 17 reporting tier-1 engines. The package has a verified digital signature from byteland software solutions stefan matz e.K., although no established signer history or curated trusted-publisher match is available.
Threat Behavior
One completed sandbox run mapped activity to MITRE T1055 (Process Injection) and T1562.001 (Impair Defenses), and a heuristic associated process activity with LSASS. These are meaningful warning signs, but the saved evidence does not establish the exact injection method or prove credential-memory access. The sandbox did not return a malicious verdict, record persistence, or identify dropped payload hashes. Its only observed domain, nexusrules.officeapps.live.com, was fully checked against the available host cache and had no malicious or suspicious classification.
What To Do Now
Confirm the download came directly from the publisher or an authorized distribution channel and verify the signature details before running it. Keep endpoint protection enabled; if the origin cannot be verified, quarantine the installer and request confirmation from the software vendor.
Where this verdict could be wrong3 caveats
- The complete 0/75 detection result, including 17 tier-1 engines without detections, weighs strongly against a conventional known-malware interpretation.
- The MSI has a verified signature, but signing.trustedPublisher.matched=false and no signer history is available to establish the publisher's prior safety.
- The only sandbox verdict was clean, and no dropped file hashes or persistence indicators were recorded; this weakens the offensive-technique interpretation.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 antivirus engines reported a malicious or suspicious result.
- All 17 reporting tier-1 engines returned no detection.
- The MSI signature is verified and no brand mismatch was detected.
- The sandbox did not issue a malicious verdict or record persistence.
- The sole observed host was fully inspected with no cached malicious or suspicious result.
- One sandbox mapped runtime activity to T1055 process injection.
- Runtime evidence also mapped activity to T1562.001 defense impairment.
- A credential-dumper heuristic associated observed process activity with lsass.exe.
- The verified signer has no historical sample record and no curated trusted-publisher match.
Verify that the installer came from the publisher’s official channel before execution, and keep endpoint protection enabled. If its origin or signing identity cannot be confirmed, quarantine it pending vendor validation.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Complete1 contacted host was cross-checked.
YARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 7MITRE ATT&CK techniques
- 9spawned processes
- 1network contacts
- 10filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Used removable-media replication behaviour that can spread files between devices.
High concern: Attempted to impair or bypass security controls.
Note: Reads your Windows user-account details.
Note: Collects details about your system.
Note: Connected to 1 server during sandbox analysis.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
DHSInstaller-en.msi
f2ac5776c5e8c2238d4ac6b8765d6f76a2edbf68abd695032278dceb2c74ce98
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\system32\msiexec.exe" /I "C:\Users\<USER>\Desktop\DHSInstaller-en.msi" /qb ACCEPTEULA=1 LicenseAccepted=1
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\system32\services.exe
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Download-1.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
04Isolated runtime analysis - Written fileObserved
MSI460f8.LOG
C:\Users\<USER>\AppData\Local\Temp\MSI460f8.LOG
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
nexusrules.officeapps.live.com
Contact observed during runtime.
06Isolated runtime analysis
6 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- nexusrules.officeapps.live.com
- F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\Blob
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\Blob
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
- C:\Users\<USER>\AppData\Local\Temp\MSI460f8.LOG
- C:\MSI7870b.tmp
- C:\ProgramData
- C:\ProgramData\Microsoft\Windows\Templates
- C:\MSI7870b.tmp
- Global\_MSIExecute
- Global\MSILOG_acbd76bf1dd2dd6GOL.8f064ISM_pmeT_lacoL_ataDppA_eruza_sresU_:C
- \BaseNamedObjects\Local\SM0:6968:304:WilStaging_02
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 2rule hits recorded
- 0 / 75engines flagged
- 3sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
0 of 75 antivirus engines flagged the file.
ProvenanceObservedSourceAntivirus analysisObserved at - 03
The file has a valid code signature from byteland software solutions stefan matz e.K..
ProvenanceObservedSourceCode-signing metadataObserved at - 04
Scanned file: DHSInstaller-en.msi — f2ac5776c5e8c2238d4ac6b8765d6f76a2edbf68abd695032278dceb2c74ce98
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\system32\msiexec.exe" /I "C:\Users\<USER>\Desktop\DHSInstaller-en.msi" /qb ACCEPTEULA=1 LicenseAccepted=1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\services.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Download-1.tmp — C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: MSI460f8.LOG — C:\Users\<USER>\AppData\Local\Temp\MSI460f8.LOG
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: nexusrules.officeapps.live.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exe
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- DHSInstaller-en.msi
- Format
- Windows Installer
- Code signing
- Signature valid: byteland software solutions stefan matz e.K.
- Size
- 40.4 MB
- Last analyzed
- Sep 30, 2026, 7:39 PM UTC
f2ac5776c5e8c2238d4ac6b8765d6f76a2edbf68abd695032278dceb2c74ce98Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't install it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Download a fresh installer from the developer's official site or an official app store.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is DHSInstaller-en.msi safe, or is it malware?
What is DHSInstaller-en.msi?
How many antivirus engines detected DHSInstaller-en.msi?
I already downloaded and installed DHSInstaller-en.msi — what should I do?
How do I remove DHSInstaller-en.msi?
Is DHSInstaller-en.msi digitally signed?
What is the SHA-256 hash of DHSInstaller-en.msi?
How up to date is this analysis of DHSInstaller-en.msi?
Community
Member reviews and reports for this exact file hash.