Classification: Malicious
dnSpy.exe is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02. Detected by 1 antivirus engines.
Detection summary
- 1 antivirus detections (1% detection ratio)
- 0 IDS alerts
- 7 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Suspicious Sample |
Triage |
2026-09-02 12:11:14 |
2026-09-02 12:11:14 |
anomalous-activity
|
|
| Generic Malware |
Hybrid-Analysis |
2023-10-25 16:45:04 |
2023-10-25 16:45:04 |
|
|
Tags
adware
persistence
ransomware
spyware
Sample information
- Filenames
- dnSpy.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 182272 bytes
- MD5
6e2e86e49d9f0faa7107f00d4d856a86
- SHA-1
0cb7e7d7482f7316a93dfb490df749517d7a06c2
- SHA-256
937de02ba7a3522404b82fa09acece6a3063c40df760ba4fc6a3344083d5eb12
- First indexed
- 2022-01-16 02:49:19
- Last updated
- 2026-09-02 12:59:45
Antivirus detections
| Engine | Detection |
| Malwarebytes | MachineLearning/Anomalous.97% |
Process list
| Name | Command line |
| dnSpy.exe | |
| WerFault.exe | -u -p 7672 -s 508 |
| WerFault.exe | -u -p 7672 -s 532 |
| WerFault.exe | -u -p 7672 -s 532 |
| WerFault.exe | -pss -s 448 -p 7672 -ip 7672 |
| WerFault.exe | -pss -s 504 -p 7672 -ip 7672 |
| dnSpy.exe | |