action_runner.exe

  • File Path: C:\Users\user\AppData\Local\Temp\action_runner.exe
  • Description: PowerToys ActionRunner

Hashes

Type Hash
MD5 7913456F440A99B152DDDDDCFA6CDC22
SHA1 9367DC9BC25B7FF9190237CB1FE4F8F90100D391
SHA256 6587BA1F05405A2E5655E8B4C95D6D70D543894A00451F418AC548E6BB5D320B
SHA384 1AC3CA38E446E196292D1E1E1F76D903161B0D864A79FE51D74739EC6F9EE7EDB2D2C2E7FF1A6B5F51FD478A7DD02DC8
SHA512 17ADE056A3D96B015764334B1FD5453928E3AAED789F001663F6C40D0F22FF3E5922E15AEC9703469E6C42ED71D400A4CE2AA569A4844A1C37D8EA9118686734
SSDEEP 6144:XiaUviy9/GJ2NTlikp0Gbo9coeX8f1053ecSyI+rd11e8CfVGd3yfBkdA+ohBS0M:hy9/GJAikAcfvayI+B+BfYA+oZZaoYR
IMP 7233A0C46408E1C57C4A60564D677521
PESHA1 C6D7AF2A2D50B8993B9B819BEC8FC4C2D492008C
PE256 A4C5DDF5B1B7A456CB980D3C285D9F160ACA1281E1A0CB4665AD6CA3BEC6FBE2

Runtime Data

Loaded Modules:

Path
C:\Users\user\AppData\Local\Temp\action_runner.exe
C:\Windows\System32\combase.dll
C:\Windows\System32\GDI32.dll
C:\Windows\System32\gdi32full.dll
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\System32\msvcp_win.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\shcore.dll
C:\Windows\System32\ucrtbase.dll
C:\Windows\System32\USER32.dll
C:\Windows\System32\win32u.dll

Signature

  • Status: Signature verified.
  • Serial: 33000001864D2175A0D907BE2C000000000186
  • Thumbprint: 8EE1E4E037942BE5BC7E58B061FB559BDC381D82
  • Issuer: CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: action_runner.exe
  • Product Name: PowerToys
  • Company Name: Microsoft Corporation
  • File Version: 0.23.0.0
  • Product Version: 0.23.0.0
  • Language: English (United States)
  • Legal Copyright: Copyright (C) 2020 Microsoft Corporation
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/70
  • VirusTotal Link: https://www.virustotal.com/gui/file/6587ba1f05405a2e5655e8b4c95d6d70d543894a00451f418ac548e6bb5d320b/detection/

File Similarity (ssdeep match)

File Score
C:\Program Files\PowerToys\action_runner.exe 85

MIT License. Copyright (c) 2020-2021 Strontic.