rdpshell.exe

  • File Path: C:\Windows\SysWOW64\rdpshell.exe
  • Description: RemoteApp Shell

Hashes

Type Hash
MD5 57398890C054387424BA518C1BB5CC33
SHA1 A0684172570FE14168AD470A1F9CE004A4289C78
SHA256 B1BFB826A9E765AAAFEA339F585C4E66E7DD61673094ABAAAAC23E093C1374ED
SHA384 03D1772F668348032A6A4816A944EDE7921783A8B4CCC347E359C93D26004C5DD3DEF52EFB7FB4BAB7B14C5F6A81FD4D
SHA512 FE76DB8F9E0FFF527CF85D66CA570E41B7977A63C216518AD4533590E8E680513150A362B02BE2421E490FF691FAAD8B1579B020EBAB327337E804A47240D970
SSDEEP 6144:tSB/053CMox5gVkHcr3u331rfP2yX+Oxr/l268m/xz+:AXT5MbD+rO6r/lF8mxz
IMP A00A1F5C000626FE86C2E86DE8433E26
PESHA1 CCBDA78C9A8E41725670DBF2115B4D31F7F52463
PE256 9B4F5A3AA888FE7D450AF55F5A8498A87447113991DBC788829B11121F540865

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: rdpshell.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.17763.1 (WinBuild.160101.0800)
  • Product Version: 10.0.17763.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 1/71
  • VirusTotal Link: https://www.virustotal.com/gui/file/b1bfb826a9e765aaafea339f585c4e66e7dd61673094abaaaac23e093c1374ed/detection/

MIT License. Copyright (c) 2020-2021 Strontic.