aitstatic.exe

  • File Path: C:\Windows\system32\aitstatic.exe
  • Description: Application Impact Telemetry Static Analyzer

Hashes

Type Hash
MD5 27D53636B86A9CE2366BA584DF09227F
SHA1 4507133B37588A052D390B535BE65865EE8ECA92
SHA256 6D20F18CF10653B7324AB41B1A3F633CCC1CE48A737949616B336071F4277924
SHA384 19A11BC6DC85DE7CD50FEF46DE7913113BE7536AF35DA6FDAA172DE3BB91FCB34BD4A011DDF758A7C6CC3AA71EB073BC
SHA512 FE02550487BFEA75916F76A767EE81725A98E5FC37627085AC9569C98E4AAEB22DCC4B1B1482CE2D10F2D37D94FD1BACADB67AE8CB74FFB6A517804C67FA6E3A
SSDEEP 49152:qjt1+tENWqA/+pSYryLTQ4ullYF5svlRlZPAoTMZmhJv3eEkF/LL:qveAwvAImAoTMgJvuLL
IMP F72ACD5834B43927998E9B0707B7AE4B
PESHA1 CFC33455CBE24E7CADCB92FAD4AF8E034E5A1B6D
PE256 DEEE0C488309C70CF1F5B6B79B7B6A4FCD3A8DF20E3EBF9D9E0E19C655A9134C

Runtime Data

Child Processes:

csrss.exe winlogon.exe

Loaded Modules:

Path
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
C:\Windows\System32\advapi32.dll
C:\Windows\system32\aitstatic.exe
C:\Windows\System32\bcryptPrimitives.dll
C:\Windows\System32\combase.dll
C:\Windows\System32\GDI32.dll
C:\Windows\System32\gdi32full.dll
C:\Windows\System32\IMM32.DLL
C:\Windows\System32\kernel.appcore.dll
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\system32\mscoree.dll
C:\Windows\System32\msvcp_win.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\ole32.dll
C:\Windows\System32\OLEAUT32.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\sechost.dll
C:\Windows\System32\SHLWAPI.dll
C:\Windows\System32\ucrtbase.dll
C:\Windows\System32\USER32.dll
C:\Windows\system32\uxtheme.dll
C:\Windows\System32\win32u.dll

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename:
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19645.1016 (WinBuild.160101.0800)
  • Product Version: 10.0.19645.1016
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: Unknown

File Similarity (ssdeep match)

File Score
C:\Program Files (x86)\Windows Kits\10\App Certification Kit\aitstatic.exe 86
C:\Windows\system32\aitstatic.exe 86
C:\windows\system32\aitstatic.exe 68
C:\WINDOWS\system32\aitstatic.exe 66
C:\Windows\system32\aitstatic.exe 96
C:\Windows\system32\aitstatic.exe 66
C:\Windows\system32\aitstatic.exe 66
C:\WINDOWS\system32\aitstatic.exe 90
C:\Windows\system32\aitstatic.exe 97

MIT License. Copyright (c) 2020-2021 Strontic.