ApplyTrustOffline.exe

  • File Path: C:\WINDOWS\system32\ApplyTrustOffline.exe
  • Description: “ApplyTrustOffline.PROGRAM”

Hashes

Type Hash
MD5 E633154C910BB8A8F04AC9308D73B019
SHA1 FCCE09A482F8017AFC501D9C67777683D72049BD
SHA256 A228C92C52FBA2F3EEB04CD1E5606FD286D2DA4CBBE459E0B32BE886BE0DD436
SHA384 3A32A9DE6274FB367E01B11555523B061377FFC6976FD1185B3AE09FBD047E177854A97898695F8E4EA0FE993DF7E174
SHA512 C396A97DB3797D8E47C488A9179809C2B31F389764B7F60861CCB136685BF0567BDD2A405FF2895987C6DB1106F5E8100E12762B12B82E7FBAC2A5C66570D841
SSDEEP 24576:Nwl4FPjVmr4PEajcVgpEn+v9X2DHFbJ1Ekgp2UU:XjVmr4PaKEXZvgzU
IMP 19C13E19CB194372B453E6B10DBDF6F2
PESHA1 464DE7790DC05E0FD64C89CB71428E956248A3CD
PE256 E8EAC6B611BCBDC5790AD65128B8EE70D163BF157C7FB90863B97DE9C6E2858A

Runtime Data

Loaded Modules:

Path
C:\WINDOWS\system32\ApplyTrustOffline.exe
C:\WINDOWS\System32\KERNEL32.DLL
C:\WINDOWS\System32\KERNELBASE.dll
C:\WINDOWS\SYSTEM32\ntdll.dll

Signature

  • Status: Signature verified.
  • Serial: 33000002ED2C45E4C145CF48440000000002ED
  • Thumbprint: 312860D2047EB81F8F58C29FF19ECDB4C634CF6A
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: “ApplyTrustOffline.PROGRAM”
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.22000.282 (WinBuild.160101.0800)
  • Product Version: 10.0.22000.282
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/73
  • VirusTotal Link: https://www.virustotal.com/gui/file/a228c92c52fba2f3eeb04cd1e5606fd286d2da4cbbe459e0b32be886be0dd436/detection

MIT License. Copyright (c) 2020-2021 Strontic.