Gridinsoft Logo
File Icon

The WINWORD.EXE (Microsoft Word) File Analysis

Technical Analysis

File Name WINWORD.EXE
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.228.174
Database Version 2025-11-04 04:00:27 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
1,769,168
File Size (bytes)
2025-11-04
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
dda8fafbf79e51c6a2f6c72f04db6e52
SHA1
bafcc47b26f0920a64bd182837387740d54156a2
SHA256
a378c44206781108fae7daf796a625c9ed6736a7400635dc5ee8e93908af0a96
SHA512
9f5e6430eea53da2441b413192b096355dda1605ed5efa41573206473c2a379e1258ba4aa0513a1775351f9a981aef21eddce8404f36df67c6acd02ab25234d5
ImpHash
cbcc3e0661fdf067103373849217fd73

PE Analysis

Basic Information

Icon
Hash: d22181d2aba5e26188e85a41b13652a3
Fuzzy: 20252e75bce7470c992245b7771bb0cc
dHash: 88a0a5acae8e8198
Image Base 0x140000000
Entry Point 0x140001730
Compilation Time 2025-10-08 00:03:35
Checksum 0x001b0f18 (Actual: 0x001b0f18)
OS Version 6.1
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path D:\dbs\el\omr\Target\x64\ship\postc2r\x-none\winword.pdb000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Digital Signature OK
Imports 13 libraries
Exports 1 functions
Resources 243 Resources
Sections 8 Sections

Version Information

CompanyName Microsoft Corporation
FileDescription Microsoft Word
FileVersion 16.0.19127.20302
InternalName WinWord
LegalTrademarks1 Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2 Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename WinWord.exe
ProductName Microsoft Office
ProductVersion 16.0.19127.20302
Translation 0x0000 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 15,672 bytes 15,872 bytes 6.14 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 013BB77111DE984B996188EBCB599867
.rdata 0x00005000 9,167 bytes 9,216 bytes 4.40 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9B0F54B9E0C4223840D09272CC361852
.data 0x00008000 2,656 bytes 1,024 bytes 1.61 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 6286CAF2FA3313928C0D8B1ECDA736B6
.pdata 0x00009000 1,320 bytes 1,536 bytes 3.79 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1B1E5695F21E17C15B0B329BDFC40426
.didat 0x0000a000 80 bytes 512 bytes 0.54 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 9F7163C3779DD8D004EB40FD516A83A8
.c2r 0x0000b000 336 bytes 512 bytes 1.82 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D0917E599D87B2649EC07F04B1A14715
.rsrc 0x0000c000 1,717,368 bytes 1,717,760 bytes 4.47 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 65D45EB753E8C66F91FB3C11468252B0
.reloc 0x001b0000 168 bytes 512 bytes 2.28 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 50A7106E36A84DCECB74FF0A52C2D6B1

Resource Analysis

Total Resources: 243 (1,705,205 bytes)
Resource Type Count Total Size Percentage
EDPENLIGHTENEDAPPINFOID 1 2 bytes
0%
EDPPERMISSIVEAPPINFOID 1 2 bytes
0%
LIMITEDACCESSFEATURE 1 70 bytes
0%
RT_ICON 225 1,566,026 bytes
91.8%
RT_GROUP_ICON 13 3,228 bytes
0.2%
RT_VERSION 1 2,044 bytes
0.1%
RT_MANIFEST 1 133,833 bytes
7.8%

Certificate Chain Analysis

Certificate Information
Product Microsoft Office
Description Microsoft Word
File Version 16.0.19127.20302
Original Name WinWord.exe
Signing Date 12:05 AM 10/08/2025 (94 days ago)
Verification Status Signed
Signers Microsoft Corporation; Microsoft Windows Code Signing PCA 2024; Microsoft Root Certificate Authority 2010
Counter Signers Microsoft Time-Stamp Service; Microsoft Time-Stamp PCA 2010; Microsoft Root Certificate Authority 2010
Internal Name WinWord
Certificate Chain Summary
Microsoft Windows Code Signing PCA 2024 #1 Primary
Validity Period: 2024-08-08 21:36:23 → 2035-06-23 22:04:01
Signature Algorithm: sha384RSA
Serial Number: 33 00 00 00 1C 48 9F 81 DF A1 B0 B7 77 00 00 00 00 00 1C
Microsoft Corporation #2 Chain
Validity Period: 2025-06-19 18:03:26 → 2026-06-18 18:03:26
Signature Algorithm: sha384RSA
Serial Number: 33 00 00 00 C3 33 AB 2C 1A F5 42 F2 C8 00 00 00 00 00 C3
Microsoft Time-Stamp Service #3 Chain
Validity Period: 2025-01-30 19:42:49 → 2026-04-22 19:42:49
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 02 05 3C 75 6C 82 44 87 CD FE 00 01 00 00 02 05
Microsoft Time-Stamp PCA 2010 #4 Chain
Validity Period: 2021-09-30 18:22:25 → 2030-09-30 18:32:25
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15
Microsoft Corporation #5 Chain
Validity Period: 2025-06-19 18:03:23 → 2026-06-18 18:03:23
Signature Algorithm: sha384RSA
Serial Number: 33 00 00 00 C0 5C 75 FF F0 2A 66 B5 35 00 00 00 00 00 C0
Microsoft Time-Stamp Service #6 Chain
Validity Period: 2025-01-30 19:43:03 → 2026-04-22 19:43:03
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 02 0E 2C CB 28 7D 95 20 75 63 00 01 00 00 02 0E

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware