| File Name | aui.8756241008.exe |
| File Type |
Win32 EXE
|
| Magic Bytes | PE32+ executable (GUI) x86-64, for MS Windows |
| SSDEEP Hash |
393216:RKmZuJXsmJ7coYzTiWwoVDVmfC3U8CNluI3Vaqv8Wqud76tGboYrChZZROu8WLAP:nwOD82k3L1qBw
|
| Scanner Version | 1.0.226.174 |
| Database Version | 2025-10-01 11:00:43 UTC |
Detected by 7 security engines - requires caution
| Hash Type | Value | Action |
|---|---|---|
| MD5 |
c30bec888d243536f66af29438cfdd22
|
|
| SHA1 |
03c502efdbd0892667638252b27bcd1f080d5af6
|
|
| SHA256 |
1c4b6b9c2fadda863748af855dc6f34bc43f716cc9368d8ed8b32f6f8eecc007
|
|
| SHA512 |
27baeeb5a850939962cb130b31f4b4d92bbd654b33e37b88a05a8186bd808df2f787eff2d68161bb6a805d5389a0d4556b7c97c6e7aa58a5ad7d8962aa2622f3
|
|
| ImpHash |
c329cfdce996b315359260e710fbdc76
|
| Image Base | 0x140000000 |
| Entry Point | 0x140009770 |
| Compilation Time | 2025-07-22 06:21:15 |
| Checksum | 0x00083c9e (Actual: 0x04bcd591) |
| OS Version | 10.0 |
| PEiD Signatures |
PE32+ executable (GUI) x86-64, for MS Windows
|
| Digital Signature | The expected hash does not match the digest in SpcInfo |
| Imports |
4 libraries
ADVAPI32, KERNEL32, RPCRT4, ntdll |
| Exports | 0 functions |
| Resources | 4 Resources |
| Sections | 6 Sections |
| CompanyName | Microsoft Corporation |
| FileDescription | Microsoft Antimalware WU Stub |
| InternalName | AM_Delta_Patch_1.431.814.0.exe |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | AM_Delta_Patch_1.431.814.0.exe |
| ProductName | Microsoft Malware Protection |
| FileVersion | 1.431.820.0 |
| ProductVersion | 1.431.820.0 |
| StubName | WuStubFinal |
| StubVersion | 1.1.24010.2001 |
| Translation | 0x0409 0x04b0 |
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
|---|---|---|---|---|---|---|
.text |
0x00001000 |
187,490 bytes | 188,416 bytes | 6.45 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
B18BA13953B217BDC720196F8FC0A9A5 |
.rdata |
0x0002f000 |
57,068 bytes | 57,344 bytes | 5.07 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
6968D8814C787F288D0B82E4AD91097E |
.data |
0x0003d000 |
66,784 bytes | 61,440 bytes | 7.37 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
3355AE0E2BE2A46036EA495C4CB63635 |
.pdata |
0x0004e000 |
8,388 bytes | 12,288 bytes | 4.05 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
3109C9D17CEEF01B26ABB9C2CFCE5B5D |
.rsrc |
0x00051000 |
259,452 bytes | 262,144 bytes | 7.99 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
54D4081615846072CB471EC66667E792 |
.reloc |
0x00091000 |
1,552 bytes | 4,096 bytes | 2.91 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
291AC0FE645F34BD2A6FED557BB6ED7D |
1 section(s) with high entropy (≥7.5) detected - possible packing/encryption
1 section(s) with elevated entropy (≥6.5) - possible compression
| Resource Type | Count | Total Size | Percentage |
|---|---|---|---|
| BINARY | 1 | 1 bytes | |
| CABINET | 1 | 256,583 bytes | |
| RT_VERSION | 1 | 1,548 bytes | |
| RT_MANIFEST | 1 | 931 bytes |
| Product | Microsoft Malware Protection |
| Description | Microsoft Antimalware WU Stub |
| File Version | 1.431.820.0 |
| Original Name | AM_Delta_Patch_1.431.814.0.exe |
| Internal Name | AM_Delta_Patch_1.431.814.0.exe |
| Copyright | © Microsoft Corporation. All rights reserved. |
33 00 00 00 1C 48 9F 81 DF A1 B0 B7 77 00 00 00 00 00 1C33 00 00 00 84 B6 D5 F8 6E A3 41 32 1D 00 00 00 00 00 8433 00 00 01 F4 17 46 85 C0 CB 3F 39 E5 00 01 00 00 01 F433 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 1561 04 B3 F5 00 00 00 00 00 0D61 15 23 0F 00 00 00 00 00 0A61 16 68 34 00 00 00 00 00 1C61 07 02 DC 00 00 00 00 00 0B33 00 00 00 BC E1 20 FD D2 7C C8 EE 93 00 00 00 00 00 BC61 07 76 56 00 00 00 00 00 0861 09 81 2A 00 00 00 00 00 0233 00 00 00 9B 21 D7 96 01 93 57 8B A4 00 00 00 00 00 9B33 00 00 01 C4 22 B2 F7 9B 79 3D AC B2 00 00 00 00 01 C433 00 00 00 C8 24 19 CB AA 54 E6 6C 2A 00 00 00 00 00 C833 00 00 00 5A ED 2F F4 E4 20 99 3F 3A 00 00 00 00 00 5A✓ This file has been digitally signed and the certificate chain has been verified
The expected hash does not match the digest in SpcInfo
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-MalwareThis file appears clean, but regular security maintenance is important
Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware
Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!