Is WisprFlowInstaller.dll safe?
Signed installer with zero engine detections and medium prevalence across 54 sources.
All 75 engines returned clean. The file is signed by 'Wispr AI' and shows installer behaviour with no malicious sandbox verdict or known-bad children. One contacted host is flagged suspicious but no complete contacted-host reputation result was available.
f7e114a361af2d6efa…81954eeca4a8eeRecommended next actions
Before using
Use it only as part of software obtained from the developer's official site or another source you independently trust.
If you already used it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 75 engines returned clean. The file is signed by 'Wispr AI' and shows installer behaviour with no malicious sandbox verdict or known-bad children. One contacted host is flagged suspicious but no complete contacted-host reputation result was available.
Zero malicious detections across 75 reporting engines and no tier-1 flags indicate the file is not recognised as malware. Signing is verified but the publisher has no prior history in our records. Observed MITRE techniques and direct-IP traffic are consistent with legitimate Electron/Squirrel installers. Medium prevalence and absence of malicious dropped children or sandbox verdicts support a safe classification.
What We Detected
75 engines scanned the sample; none flagged it malicious. The file is a signed 64-bit PE with verified signature from 'Wispr AI'. Sandbox execution recorded process creation, file writes, and network activity typical of an Electron-based installer using Squirrel.
Threat Behavior
Four MITRE techniques (T1055, T1485, T1486, T1543) were mapped from runtime evidence, but no sandbox flagged the activity as malicious. Contacted hosts include one suspicious domain (raw.githubusercontent.com) and several IPs; none appear in our malicious-host cache. Ten dropped children were inspected and none classified malicious.
What To Do Now
Keep endpoint protection enabled. The file can be executed if obtained from the official Wispr Flow distribution channel. Monitor for unexpected behaviour and report anomalies through normal support channels.
Where this verdict could be wrong1 caveat
- contactedHosts shows one suspicious host (raw.githubusercontent.com) and behaviour shows direct-IP traffic plus MITRE T1055/T1485/T1486/T1543, but no tier-1 detections or malicious sandbox verdict.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Zero detections across 75 engines
- Verified digital signature
- Medium prevalence from 54 sources
- No malicious dropped children
- New signer with no historical samples
- Direct-IP network traffic observed
- One contacted host flagged suspicious
The sample shows no malicious indicators and can be treated as a legitimate installer when sourced from official channels.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial4 of 17 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 25MITRE ATT&CK techniques
- 8spawned processes
- 18network contacts
- 29filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
WisprFlowInstaller.dll
f7e114a361af2d6efad2b660e7d13cb7cf7163fbfec168784781954eeca4a8ee
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\WisprFlow\app-1.6.447\Squirrel.exe" --updateSelf=C:\Users\<USER>\AppData\Local\SquirrelTemp\Update.exe
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\WisprFlow\app-1.6.447\Wispr Flow.exe" --squirrel-install 1.6.447
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Squirrel-UpdateSelf.log
C:\Users\<USER>\AppData\Local\WisprFlow\app-1.6.447\Squirrel-UpdateSelf.log
04Isolated runtime analysis - Written fileObserved
Update.exe
C:\Users\<USER>\AppData\Local\WisprFlow\Update.exe
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostDerived
raw.githubusercontent.com
Saved reputation verdict: suspicious.
06Contacted-host cross-check - Contacted hostObserved
104.26.5.130
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 104.26.5.130
- 34.200.203.208
- 34.160.81.0
- 16.15.36.134
- 50.18.104.48
- 54.225.70.138
- 185.199.111.133
- 8.8.8.8
- 104.26.4.130
- 23.15.3.154
- https://dl.wisprflow.com/wispr-flow/win32/latest.json
- https://dl.wisprflow.com/wispr-flow/win32/x64/Wispr%20Flow%20Setup-v1.6.447.exe
- https://us.i.posthog.com/capture/
- https://o4506267787395072.ingest.sentry.io/api/4506268508422144/envelope/
- https://raw.githubusercontent.com/electron/electron/main/shell/browser/resources/win/electron.ico
- C:\Users\<USER>\AppData\Local\WisprFlow\app-1.6.447\Squirrel-UpdateSelf.log
- C:\Users\<USER>\AppData\Local\WisprFlow\Update.exe
- C:\Users\<USER>\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\Squirrel.exe.log
- \Device\ConDrv\Connect
- C:\Users\<USER>\AppData\Local\Temp\WisprFlowSetup-347dd5362cd04269b63acbcfe3c73b1b.exe
- C:\Users\<USER>\AppData\Local\Temp\WisprFlowSetup-347dd5362cd04269b63acbcfe3c73b1b.exe
- C:\Users\<USER>\AppData\Local\SquirrelTemp\background.gif
- C:\Users\<USER>\AppData\Local\SquirrelTemp\RELEASES
- C:\Users\<USER>\AppData\Local\SquirrelTemp\setupIcon.ico
- C:\Users\<USER>\AppData\Local\SquirrelTemp\Update.exe
- Global\WisprFlowInstaller
- cversions.3.m
- \Sessions\1\BaseNamedObjects\Global\WisprFlowInstaller
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- dee5b710ca72425cd4d1…24208fNever scannednever seen before
- 1e70708b70756914f4f1…880f33Never scannednever seen before
- c0992ae19d143e94e106…f2c799Never scannednever seen before
- d990f4ced39e31a1149d…94c16bNever scannednever seen before
- da3f122d19f811a0ee68…fde700Never scannednever seen before
- 83e2d22e2caf95780d16…ee5d53Never scannednever seen before
- b084a873d9d4d558e74f…f9f85aNever scannednever seen before
- cae2837b053a34e807e7…1a2968Never scannednever seen before
- fade08034183e6703f64…f9e972Never scannednever seen before
- 1a2c9397f6fdfc6bd6ac…8add98Never scannednever seen before
Servers this file contacts
This file contacts 1 host we've flagged suspicious in our own URL scanner.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 2rule hits recorded
- 0 / 75engines flagged
- 54sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The file has a valid code signature from Wispr AI.
ProvenanceObservedSourceCode-signing metadataObserved at - 03
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 04
Scanned file: WisprFlowInstaller.dll — f7e114a361af2d6efad2b660e7d13cb7cf7163fbfec168784781954eeca4a8ee
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\WisprFlow\app-1.6.447\Squirrel.exe" --updateSelf=C:\Users\<USER>\AppData\Local\SquirrelTemp\Update.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Users\<USER>\AppData\Local\WisprFlow\app-1.6.447\Wispr Flow.exe" --squirrel-install 1.6.447
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Squirrel-UpdateSelf.log — C:\Users\<USER>\AppData\Local\WisprFlow\app-1.6.447\Squirrel-UpdateSelf.log
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: Update.exe — C:\Users\<USER>\AppData\Local\WisprFlow\Update.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: raw.githubusercontent.com — Saved reputation verdict: suspicious.
ProvenanceDerivedSourceContacted-host cross-checkObserved at - 10
Contacted host: 104.26.5.130 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\Explorer.EXEThe sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence104.26.5.130 · 34.200.203.208 · 34.160.81.0
0 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- WisprFlowInstaller.dll
- Format
- Win32 EXE
- Code signing
- Signature valid: Wispr AI
- Size
- 5.9 MB
- Last analyzed
- Aug 29, 2026, 10:55 AM UTC
f7e114a361af2d6efad2b660e7d13cb7cf7163fbfec168784781954eeca4a8eeSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Use it only as part of software obtained from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is WisprFlowInstaller.dll safe?
What is WisprFlowInstaller.dll?
How many antivirus engines detected WisprFlowInstaller.dll?
Is WisprFlowInstaller.dll digitally signed?
What is the SHA-256 hash of WisprFlowInstaller.dll?
Is it safe to use WisprFlowInstaller.dll?
How up to date is this analysis of WisprFlowInstaller.dll?
Community
Member reviews and reports for this exact file hash.