TSTheme.exe

  • File Path: C:\WINDOWS\system32\TSTheme.exe
  • Description: TSTheme Server Module

Hashes

Type Hash
MD5 667931B0F6D44230923C242A70D87027
SHA1 DF76E4877E5638F95ADC40947E3C1F1527864F42
SHA256 89A145DA05986FA6870F19E37750417C9184EF4120102DE9C6D07F35C9860A56
SHA384 E401B62CEBAD98CD8002D11AB17CEBF54E4ED0634D13C9F7042ACBC491DD702B43A5D1E2D23126AEAAACA7D44647C849
SHA512 AF795FFCC66D1B96140430C120FF804F769F291A31C5E8B611B3D80B1C5F16C5CF062F53272FE385866FF4727240FBC7635228EDDFDD6A84BE0B2B22727A9B7B
SSDEEP 1536:kGUrGgFu1VyRyf3+kPYADEMqz3+LGqXgpTX/yAoUv2:kGUaIuH8K+kPYAYz3+yqwpTXK9U+
IMP 03D137EEE6934A4F67A592B69A101557
PESHA1 9BEBD8DB6E3B3BAB2617ECD00EF7B4E12AD27BB5
PE256 2B8CFA8C32B193B22C2E7024EB449320B5D893FE69A769D117B2EFC5D011B037

Runtime Data

Open Handles:

Path Type
(R-D) C:\Windows\System32\en-US\TSTheme.exe.mui File
(RW-) C:\Windows\System32 File
\BaseNamedObjects__ComCatalogCache__ Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000001.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro Section
\Sessions\2\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\Sessions\2\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section

Loaded Modules:

Path
C:\WINDOWS\System32\KERNEL32.DLL
C:\WINDOWS\System32\KERNELBASE.dll
C:\WINDOWS\SYSTEM32\ntdll.dll
C:\WINDOWS\system32\TSTheme.exe

Signature

  • Status: Signature verified.
  • Serial: 33000002ED2C45E4C145CF48440000000002ED
  • Thumbprint: 312860D2047EB81F8F58C29FF19ECDB4C634CF6A
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: TSThemeS.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.22000.1 (WinBuild.160101.0800)
  • Product Version: 10.0.22000.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/73
  • VirusTotal Link: https://www.virustotal.com/gui/file/89a145da05986fa6870f19e37750417c9184ef4120102de9c6d07f35c9860a56/detection

Possible Misuse

The following table contains possible examples of TSTheme.exe being misused. While TSTheme.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma sysmon_suspicious_remote_thread.yml - '\tstheme.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.