Gridinsoft Logo
File Icon

The powershell.exe (Windows PowerShell) File Analysis

Technical Analysis

File Name powershell.exe
File Type
PE32+ executable (console) x86-64, for MS Windows
Scanner Version 1.0.224.174
Database Version 2025-09-13 12:00:56 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
493,568
File Size (bytes)
2025-09-13
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
6726185b70b5adf05e8a1a1df82ebf30
SHA1
8db8ff070eabf20486dcd3ba7c84619081880a73
SHA256
64dd55e1c2373deed25c2776f553c632e58c45e56a0e4639dfd54ee97eab9c19
SHA512
71b4819a56ad465f01a27c5b41039e36364d8bc97c01ee28e9735a00d5a91232ef91fbd554c29d1c883122033fbbce4c62e98e32cd7d6502f339f048ed030432
ImpHash
e3007c8e0098d06abf617eee6f0c5abd

PE Analysis

Basic Information

Icon
Hash: 211310fa36c43b67f4b9dd836a6d1e84
Fuzzy: 3ef19c85b9689424e7450af5fb583bf6
dHash: 10acd8b2b2ece609
Image Base 0x140000000
Entry Point 0x140004710
Compilation Time 2023-01-08 13:36:53
Checksum 0x00082584 (Actual: 0x00082584)
OS Version 10.0
PEiD Signatures PE32+ executable (console) x86-64, for MS Windows
PDB Path powershell.pdb
Digital Signature No valid SignedData structure was found.
Imports 8 libraries
msvcrt, ATL, KERNEL32, OLEAUT32, ADVAPI32, OLE32, USER32, mscoree
Exports 0 functions
Resources 26 Resources
Sections 6 Sections

Version Information

CompanyName Microsoft Corporation
FileDescription Windows PowerShell
FileVersion 10.0.19041.3636 (WinBuild.160101.0800)
InternalName POWERSHELL
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename PowerShell.EXE
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.19041.3636
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 68,869 bytes 69,120 bytes 6.14 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 8B9EA5438D8BC0C4A244712B5400E703
.rdata 0x00012000 53,626 bytes 53,760 bytes 4.29 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BA7C62B3057518B5A556AF4EA54D8497
.data 0x00020000 5,012 bytes 2,048 bytes 3.27 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE A7D741833942D193616D77CDF23AC700
.pdata 0x00022000 4,560 bytes 4,608 bytes 4.92 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 93A27737A26DDEB6A7AFE4744E792FD5
.rsrc 0x00024000 359,816 bytes 359,936 bytes 5.31 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4E1C54D9D69CB2F67438B02B92DC8ACA
.reloc 0x0007c000 2,748 bytes 3,072 bytes 5.21 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 5960B3E37738DCDC55D225D4C408D785

Resource Analysis

Total Resources: 26 (358,359 bytes)
Resource Type Count Total Size Percentage
MUI 1 216 bytes
0.1%
RT_ICON 21 355,214 bytes
99.1%
RT_GROUP_ICON 2 306 bytes
0.1%
RT_VERSION 1 924 bytes
0.3%
RT_MANIFEST 1 1,699 bytes
0.5%

Certificate Chain Analysis

Certificate Information
Product Microsoft® Windows® Operating System
Description Windows PowerShell
File Version 10.0.19041.3636 (WinBuild.160101.0800)
Original Name PowerShell.EXE
Internal Name POWERSHELL
Copyright © Microsoft Corporation. All rights reserved.

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware