espexe.exe
- File Path:
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x86\espexe.exe
- Description: Microsoft Windows(TM) Economical Service Provider Application
Screenshot
Hashes
Type |
Hash |
MD5 |
88E35AB456A7EDDD041185DFA528C389 |
SHA1 |
6B0F43C8BF933E12415901E92DCBA9FD0BB1C8B0 |
SHA256 |
42CD2B1844818BF66796048BFC0FB3CA6B59E410DA87FFC294C04E7368A1594D |
SHA384 |
0FFE6841F10509179D999F869C0B158B8A7AD883985E34C8152803B50C70249E4CB8BD7CD3FE0062AA0EA995F5070B92 |
SHA512 |
31CB2CC2B3C9A2158751988DE495ACB314B0EF67E410A3724D82F946AA8AF83608413257B594913D1EDF40CD986E749C58A1555DF2944435EEE930A3E38BEE22 |
SSDEEP |
768:JP/oOjx7qgi7hMLXRXvTBjkuCCe8RLIWM+giTGicL:Z/YL7hIFbBjdCd8RhM+giKj |
IMP |
08F8F762932C1554A5E68AB3209F7544 |
PESHA1 |
C0FE64EFD94D768734B7E044AC114290C11CBD07 |
PE256 |
14E1933CA9DB69C371CE0FA60728D3EB2A2CEB6917A3D07CFD495DA2323E4E46 |
Runtime Data
Window Title:
ESP: The Economical Service Provider
Open Handles:
Path |
Type |
(R-D) C:\Windows\Fonts\StaticCache.dat |
File |
(R-D) C:\Windows\SysWOW64\en-US\user32.dll.mui |
File |
(RW-) C:\Users\user |
File |
(RW-) C:\Windows |
File |
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627 |
File |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db |
Section |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db |
Section |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2 |
Section |
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 |
Section |
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 |
Section |
\Sessions\1\Windows\Theme1383959086 |
Section |
\Windows\Theme2042523233 |
Section |
Loaded Modules:
Path |
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x86\espexe.exe |
C:\Windows\SYSTEM32\ntdll.dll |
C:\Windows\System32\wow64.dll |
C:\Windows\System32\wow64cpu.dll |
C:\Windows\System32\wow64win.dll |
Signature
- Status: Signature verified.
- Serial:
33000002CF6D2CC57CAA65A6D80000000002CF
- Thumbprint:
1A221B3B4FEF088B17BA6704FD088DF192D9E0EF
- Issuer: CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Original Filename: ESPEXE.EXE
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.19041.1 (WinBuild.160101.0800)
- Product Version: 10.0.19041.1
- Language: English (United States)
- Legal Copyright: Copyright Microsoft Corporation 1995. All Rights Reserved.
- Machine Type: 32-bit
File Scan
- VirusTotal Detections: Unknown
MIT License. Copyright (c) 2020-2021 Strontic.