RemotePosWorker.exe

  • File Path: C:\Windows\system32\RemotePosWorker.exe
  • Description: Remote Pos Driver Worker

Hashes

Type Hash
MD5 958717B8839C0148B3226CDF343EE8E9
SHA1 A7F5A5A01A5D785FECC1EB6679E4B0A8FE72606D
SHA256 2868B0CC04E8DC5A415DAED0FEFEC08430261FAE6B5707A83A848EDF8BF24DA7
SHA384 882E19683BD3B76ED95DE9B9746E017EAA471C937D5B30944572501C4C1E6FDCDC66ADAFF9655973EAA8001857213998
SHA512 BADD5D814077A2417533A473E6AFD5E962B632C962DC46F245A538DCBB55D96817700415FC25373D698E37B3D67401B11C3A6E9806D00AF7CB4AC4B0D59DF961
SSDEEP 192:PZzjVeQ6z/Q7d5o4tUdSm6DOHysW9Okd4qigseaRluWq7W:PZzjVeQpd59mdZ5WskFWRIWq7W
IMP C6E4FB88ABA54E5E339120511BB8F20D
PESHA1 726279907EC3D3AAC8C7E412DCD27D5B7BF6D41C
PE256 43114A7BD2C917E8081BD9F03574A9FB116B9AAD7F6BA43D3D402553C6C85D84

Runtime Data

Loaded Modules:

Path
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\system32\RemotePosWorker.exe

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: RemotePosWorker.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/74
  • VirusTotal Link: https://www.virustotal.com/gui/file/2868b0cc04e8dc5a415daed0fefec08430261fae6b5707a83a848edf8bf24da7/detection

MIT License. Copyright (c) 2020-2021 Strontic.