RdpSaPs.dll

  • File Path: C:\Windows\system32\RdpSaPs.dll
  • Description: RDP Session Agent Proxy Stub

Hashes

Type Hash
MD5 23C4C2376B0D6BA361800ADBB0666FDC
SHA1 92F457B2D143B7C16ACBD9DB65D885EF7133844F
SHA256 C844340746818711894B607A8E3ADF9C031DC4C2306C1EDF1EBB0DF8DE5E1EFC
SHA384 2E8BB05A9E3691FDC240CBDAA8EA44C243983B18196105221F74ABC4072689FFF761437B21977A84D925EC9ED9DDA00D
SHA512 BB3B683D70B62BB6BF6074521833F4B27755C63CAAADE635D1B2F9C4E670BCF5BA926563DDF9F711430991C868E7007AC69A10456D5A54A3623F3109E146512E
SSDEEP 384:pGMbX2C3R5IWHezAol9gU4tn9rG0W4WWr:4k57K2T
IMP 627B3DAD5F74C3D207A3F627FBA0CE20
PESHA1 7C6CD3EDB0CD724F512C1014BEE7AF7C6C87757D
PE256 028D3426F01D75E892ED78E8DDF03C0940F046231AB28978F62896DA7ED13123

DLL Exports:

Function Name Ordinal Type
DllUnregisterServer 4 Exported Function
GetProxyDllInfo 5 Exported Function
DllRegisterServer 3 Exported Function
DllCanUnloadNow 1 Exported Function
DllGetClassObject 2 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: RdpSaPs.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/72
  • VirusTotal Link: https://www.virustotal.com/gui/file/c844340746818711894b607a8e3adf9c031dc4c2306c1edf1ebb0df8de5e1efc/detection/

MIT License. Copyright (c) 2020 Strontic.