AddInProcess.exe
- File Path:
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe
- Description: AddInProcess.exe
- Comments: Flavor=Retail
Hashes
Type |
Hash |
MD5 |
929EA1AF28AFEA2A3311FD4297425C94 |
SHA1 |
2CA2E292B28CCA675DDF11EB1604208A724B59A0 |
SHA256 |
F0C5491DC3851DA576F0755319669C98809D82276B3E680350CD8E3F404F78F0 |
SHA384 |
6C16B85272AE123DC72A92AAF33DDC92FCADE3A62C9BAAAFA18169244C611B3C3FD744BF500E99DCF4C3FD0D43678454 |
SHA512 |
3DE842F1E5B4903F532709FF0A2BC5C2203B92960BF9B8CF963ED25B1D9B93B246C7D52259BCED44A7EA6B2757768F863913EE2BCE3C6E99CCE7082F07915FE0 |
SSDEEP |
384:HvfIQRb67dOwRIeKJ9Yl6dnPU3SERztmbqCJstdMardz/JikPZ+6sPZZcWemn5fy:H3IX7dQ6Iq8eM/lG9TfqWh8fwL |
IMP |
F34D5F2D4577ED6D9CEEC516C1F5A744 |
PESHA1 |
D14D37097D399D09637CC352B7D038E1D28F807D |
PE256 |
5398E568D353CEEE75CB27CE9B020564466C613AB703D4F6FF58CF1F8A3808E9 |
Runtime Data
Loaded Modules:
Path |
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe |
C:\Windows\System32\KERNEL32.dll |
C:\Windows\System32\KERNELBASE.dll |
C:\Windows\SYSTEM32\MSCOREE.DLL |
C:\Windows\SYSTEM32\ntdll.dll |
Signature
- Status: Signature verified.
- Serial:
330000023241FB59996DCC4DFF000000000232
- Thumbprint:
FF82BC38E1DA5E596DF374C53E3617F7EDA36B06
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Original Filename: AddInProcess.exe
- Product Name: Microsoft .NET Framework
- Company Name: Microsoft Corporation
- File Version: 4.8.4084.0 built by: NET48REL1
- Product Version: 4.8.4084.0
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
- Machine Type: 32-bit
File Scan
- VirusTotal Detections: 0/75
- VirusTotal Link: https://www.virustotal.com/gui/file/f0c5491dc3851da576f0755319669c98809d82276b3e680350cd8e3f404f78f0/detection
File Similarity (ssdeep match)
MIT License. Copyright (c) 2020-2021 Strontic.