OptionalFeatures.exe

  • File Path: C:\WINDOWS\system32\OptionalFeatures.exe
  • Description: Windows Features

Hashes

Type Hash
MD5 18FDAD8492E77DC6C6AD062F9AB7524B
SHA1 ABDD51E8FFA5B9C4CBBE0F2E8B7983B846B60873
SHA256 33EF5300ADD8B06FBE0D8E4078D2A32EC9950E9EED303CCDEA7795E0012A227A
SHA384 EB8277263088AF341EE93226D8EA0F20F84B7815A0A545A251A24AABA5CBF8435B7DE46F3100EDD84673AF275BBA97D3
SHA512 D46A0AB1A2CD261D75381B70EF4945F9A5EF6372740FB566F889BF1C3DAA924BF3021BA8CCA1038719BFEE380CA173968BFA7303E7DA774053A38CA40C7E0869
SSDEEP 3072:zQpqcIGabEaznWfH22ZsuX2xKwMPTnaSrIrvDi:zQAcIG8znWjZnXeKwMLnaqY
IMP B1DA23E5BF146552E38FA70DEE47601E
PESHA1 847D9585B13C749C8613AE7F6F815D25D2A91591
PE256 9E8705192C5FDA57AFD6CFCCA1305B49BBAFB3A9DDCE652909A37AEC7ABF6354

Runtime Data

Loaded Modules:

Path
C:\WINDOWS\System32\KERNEL32.DLL
C:\WINDOWS\System32\KERNELBASE.dll
C:\WINDOWS\SYSTEM32\ntdll.dll
C:\WINDOWS\system32\OptionalFeatures.exe

Signature

  • Status: Signature verified.
  • Serial: 33000002ED2C45E4C145CF48440000000002ED
  • Thumbprint: 312860D2047EB81F8F58C29FF19ECDB4C634CF6A
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: OptionalFeatures.EXE.MUI
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.22000.1 (WinBuild.160101.0800)
  • Product Version: 10.0.22000.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/72
  • VirusTotal Link: https://www.virustotal.com/gui/file/33ef5300add8b06fbe0d8e4078d2a32ec9950e9eed303ccdea7795e0012a227a/detection

File Similarity (ssdeep match)

File Score
C:\Windows\system32\Fondue.exe 79
C:\windows\system32\Fondue.exe 85
C:\WINDOWS\system32\Fondue.exe 82
C:\WINDOWS\system32\Fondue.exe 75
C:\Windows\system32\Fondue.exe 83
C:\Windows\system32\Fondue.exe 82
C:\Windows\system32\OptionalFeatures.exe 80
C:\Windows\system32\OptionalFeatures.exe 82
C:\WINDOWS\system32\OptionalFeatures.exe 80
C:\Windows\system32\OptionalFeatures.exe 80
C:\Windows\SysWOW64\Fondue.exe 82
C:\WINDOWS\SysWOW64\Fondue.exe 83
C:\windows\SysWOW64\Fondue.exe 82
C:\WINDOWS\SysWOW64\Fondue.exe 79
C:\Windows\SysWOW64\Fondue.exe 86
C:\Windows\SysWOW64\Fondue.exe 82

MIT License. Copyright (c) 2020-2021 Strontic.