Gridinsoft Logo
File Icon

The RAMMap64a.exe (RamMap - physical memory analyzer) File Analysis

Technical Analysis

File Name RAMMap64a.exe
File Type
PE32+ executable (GUI) Aarch64, for MS Windows
Scanner Version 1.0.210.174
Database Version 2025-03-14 11:00:57 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
379,792
File Size (bytes)
2025-03-14
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
1de68434548372c7d3eb79b3f10fca3e
SHA1
fbb9728dd7900b72808ff6aca815b0c5de43445d
SHA256
9d110b7af0f89899bd6c8e7b3d7e689dd1e0f5471ad7aef03e8288ba169f4de3
SHA512
186bdc837f7f4630cc9e20c3b71bd654ccdc854c7b998c1ae5b779a6cd63eacdcdb5e082b2de812f959ed035cffc03178173c56615ca5dabdc974ec37a42a263
ImpHash
9c3c230e8f6a041bd38b5a3ae39bb1b6

PE Analysis

Basic Information

Icon
Hash: a810bbfbdcaed0982c51fa7370d429f2
Fuzzy: 162007db970dcccb1bc04cbb1ee91ab3
dHash: 3838383838383838
Image Base 0x140000000
Entry Point 0x140020fd8
Compilation Time 2022-05-06 22:40:14
Checksum 0x00068516 (Actual: 0x00068516)
OS Version 6.2
PEiD Signatures PE32+ executable (GUI) Aarch64, for MS Windows
PDB Path D:\a\1\s\ARM64\Release\RamMap64a.pdb
Digital Signature OK
Imports 10 libraries
COMCTL32, VERSION, GDI32, ADVAPI32, SHELL32, COMDLG32, KERNEL32, USER32, ole32, OLEAUT32
Exports 0 functions
Resources 21 Resources
Sections 6 Sections

Version Information

CompanyName Sysinternals - www.sysinternals.com
FileDescription RamMap - physical memory analyzer
FileVersion 1.61
InternalName RamMap
LegalCopyright Copyright © 2010-2022 Mark Russinovich
OriginalFilename RamMap
ProductName RamMap
ProductVersion 1.61
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 241,144 bytes 241,152 bytes 6.43 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ EF738A972429A36202C86E8DDDE38C0A
.rdata 0x0003c000 97,990 bytes 98,304 bytes 4.65 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ CC2C1C8D5C3990762F7543535CB2FF44
.data 0x00054000 10,828 bytes 4,096 bytes 2.87 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BE5BB268271CB76953D61D225D97F4A7
.pdata 0x00057000 7,456 bytes 7,680 bytes 5.46 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1BD7E276D32D1EA2FB23659F9D6FD3B0
.rsrc 0x00059000 14,536 bytes 14,848 bytes 4.08 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 21B1D551E22A90A1B5D3037FF1C7AB52
.reloc 0x0005d000 2,204 bytes 2,560 bytes 5.12 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ C1B3A0AD57E91D165FA9CC8FF1A61934

Resource Analysis

Total Resources: 21 (12,952 bytes)
Resource Type Count Total Size Percentage
RT_CURSOR 1 308 bytes
2.4%
RT_ICON 3 3,832 bytes
29.6%
RT_MENU 1 522 bytes
4%
RT_DIALOG 9 5,310 bytes
41%
RT_ACCELERATOR 1 56 bytes
0.4%
RT_GROUP_CURSOR 1 20 bytes
0.2%
RT_GROUP_ICON 3 60 bytes
0.5%
RT_VERSION 1 792 bytes
6.1%
RT_MANIFEST 1 2,052 bytes
15.8%

Certificate Chain Analysis

Certificate Information
Product RamMap
Description RamMap - physical memory analyzer
File Version 1.61
Original Name RamMap
Signing Date 10:40 PM 05/06/2022 (1127 days ago)
Verification Status Signed
Signers Microsoft Corporation; Microsoft Code Signing PCA 2011; Microsoft Root Certificate Authority 2011
Counter Signers Microsoft Time-Stamp Service; Microsoft Time-Stamp PCA 2010; Microsoft Root Certificate Authority 2010
Internal Name RamMap
Copyright Copyright © 2010-2022 Mark Russinovich
Certificate Chain Summary
Microsoft Corporation #1 Primary
Validity Period: 2021-09-02 18:32:59 → 2022-09-01 18:32:59
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 02 52 8B 33 AA F8 95 F3 39 DB 00 00 00 00 02 52
Microsoft Code Signing PCA 2011 #2 Chain
Validity Period: 2011-07-08 20:59:09 → 2026-07-08 21:09:09
Signature Algorithm: sha256RSA
Serial Number: 61 0E 90 D2 00 00 00 00 00 03
Microsoft Time-Stamp Service #3 Chain
Validity Period: 2021-12-02 19:05:14 → 2023-02-28 19:05:14
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 01 97 03 CF 59 9C 6B 89 78 3F 00 01 00 00 01 97
Microsoft Time-Stamp PCA 2010 #4 Chain
Validity Period: 2021-09-30 18:22:25 → 2030-09-30 18:32:25
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware