Gridinsoft Logo
File Icon

The ndp48-web.exe (Microsoft .NET Framework 4.8 Setup) File Analysis

Technical Analysis

File Name ndp48-web.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.211.174
Database Version 2025-03-25 03:01:12 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
1,439,328
File Size (bytes)
2025-03-25
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
34a5c76979563918b953e66e0d39c7ef
SHA1
4181398aa1fd5190155ac3a388434e5f7ea0b667
SHA256
0bba3094588c4bfec301939985222a20b340bf03431563dec8b2b4478b06fffa
SHA512
642721c60d52051c7f3434d8710fe3406a7cfe10b2b39e90ea847719ed1697d7c614f2df44ad50412b1df8c98dd78fdc57ca1d047d28c81ac158092e5fb18040
ImpHash
9b2f6a441f9ff8df98ae6e9e6b5d4271

PE Analysis

Basic Information

Icon
Hash: 5ddef14d8de6be03b951dc7227faa0e4
Fuzzy: 8d9ea2da3f2392b7501126f9ff5c8e07
dHash: c9d1d8cd96a0aec6
Image Base 0x00400000
Entry Point 0x00418ee7
Compilation Time 2017-07-16 21:09:16
Checksum 0x0016064c (Actual: 0x0016064c)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path C:\NetFXDev1\binaries\x86ret\bin\i386\VSSetup\Utils\boxstub.pdb
Digital Signature OK
Imports 8 libraries
ADVAPI32, KERNEL32, COMCTL32, RPCRT4, SHELL32, SHLWAPI, USER32, OLEAUT32
Exports 3 functions
Resources 11 Resources
Sections 6 Sections

Version Information

CompanyName Microsoft Corporation
FileDescription Microsoft .NET Framework 4.8 Setup
FileVersion 4.8.04115.00
InternalName NDP48-Web.exe
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename NDP48-Web.exe
ProductName Microsoft .NET Framework 4.8
ProductVersion 4.8.04115.00
Translation 0x0409 0x04b0
CompanyName Microsoft Corporation
FileDescription Box Stub
FileVersion 14.7.2224.0 built by: NETFXDEV1(RAKSINGH-SECURE-RAKSINGH)
InternalName BoxStub.exe
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename BoxStub.exe
ProductName Microsoft® .NET Framework
ProductVersion 14.7.2224.0
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 160,122 bytes 160,256 bytes 6.57 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 7B3B1EE9AE8AD7764EC9D706F5340480
.data 0x00029000 14,176 bytes 5,120 bytes 2.46 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE A149D291B9BCD11002C627167764F938
.idata 0x0002d000 4,584 bytes 4,608 bytes 5.50 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 21F29DCEA9763E518871FB03F70A5066
.boxld01 0x0002f000 182 bytes 512 bytes 1.66 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 118F53165C330598D57A34CA3D476F86
.rsrc 0x00030000 7,908 bytes 8,192 bytes 4.29 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 0FD002798F59E06D78E2D5855CB4E247
.reloc 0x00032000 10,564 bytes 10,752 bytes 4.99 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 0E90504F35D64A06AE725D5C4572A9E4
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 11 (7,240 bytes)
Resource Type Count Total Size Percentage
RT_ICON 2 1,040 bytes
14.4%
RT_DIALOG 2 636 bytes
8.8%
RT_STRING 3 1,654 bytes
22.8%
RT_GROUP_ICON 1 34 bytes
0.5%
RT_VERSION 2 2,444 bytes
33.8%
RT_MANIFEST 1 1,432 bytes
19.8%

Certificate Chain Analysis

Certificate Information
Product Microsoft .NET Framework 4.8
Description Microsoft .NET Framework 4.8 Setup
File Version 4.8.04115.00
Original Name NDP48-Web.exe
Signing Date 07:33 AM 05/01/2021 (1498 days ago)
Verification Status Signed
Signers Microsoft Corporation; Microsoft Code Signing PCA 2011; Microsoft Root Certificate Authority 2011
Counter Signers Microsoft Time-Stamp Service; Microsoft Time-Stamp PCA 2010; Microsoft Root Certificate Authority 2010
Internal Name NDP48-Web.exe
Copyright © Microsoft Corporation. All rights reserved.
Certificate Chain Summary
Microsoft Corporation #1 Primary
Validity Period: 2020-12-15 21:31:45 → 2021-12-02 21:31:45
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 01 DF 6B F0 2E 92 A7 4A B4 D0 00 00 00 00 01 DF
Microsoft Code Signing PCA 2011 #2 Chain
Validity Period: 2011-07-08 20:59:09 → 2026-07-08 21:09:09
Signature Algorithm: sha256RSA
Serial Number: 61 0E 90 D2 00 00 00 00 00 03
Microsoft Time-Stamp Service #3 Chain
Validity Period: 2020-10-15 17:28:26 → 2022-01-12 17:28:26
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 01 40 23 19 D6 5E DE 95 24 31 00 00 00 00 01 40
Microsoft Time-Stamp PCA 2010 #4 Chain
Validity Period: 2010-07-01 21:36:55 → 2025-07-01 21:46:55
Signature Algorithm: sha256RSA
Serial Number: 61 09 81 2A 00 00 00 00 00 02

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware