RemotePosWorker.exe

  • File Path: C:\Windows\system32\RemotePosWorker.exe
  • Description: Remote Pos Driver Worker

Hashes

Type Hash
MD5 CA8CBA4456A18263425CBF7EF23F71D5
SHA1 B5D6BE97AD24CDB7119E9CA384F83534026693A7
SHA256 B1A25D53C302C3B4E7D6AFFBC309E67C3761E0D189B9FC1389E16C626EF8B09D
SHA384 05762764C12B3EBC61E4588C28C0AAFD68B6E66C25AB168F68DCF8D60D79C17B4380747C5C63E458610C467F75654492
SHA512 3773E459C9DA70D7DAEC812426AC01C6DAC4B2A067C0DAB6C1EA64CF2A2855ECB643E8F5A59CE29E3FEE7DD32529CE23641D68F2E2E34BF004E900F1D2414998
SSDEEP 192:Yt9PydQJai6viLbkI4oN6BHevMqjsWPuzPCd4qigEXaRk3WF7W:YfydQJm6Leq6peviWWzPCFpRk3WF7W
IMP C6E4FB88ABA54E5E339120511BB8F20D
PESHA1 C856FDC789F58E794FB378910D7D4CF5B18FDAC8
PE256 52041A3AB1A5168FE71BB35283B2D1FB82F0F945F6969CACA5CF51E37AE966B8

Signature

  • Status: Signature verified.
  • Serial: 33000001C422B2F79B793DACB20000000001C4
  • Thumbprint: AE9C1AE54763822EEC42474983D8B635116C8452
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: RemotePosWorker.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.17763.1 (WinBuild.160101.0800)
  • Product Version: 10.0.17763.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/69
  • VirusTotal Link: https://www.virustotal.com/gui/file/b1a25d53c302c3b4e7d6affbc309e67c3761e0d189b9fc1389e16c626ef8b09d/detection/

File Similarity (ssdeep match)

File Score
C:\WINDOWS\system32\RemotePosWorker.exe 66

MIT License. Copyright (c) 2020-2021 Strontic.