Gridinsoft Logo
File Icon

The Setup_it-IT_DBWQN-2DHPP-7XGRH-MKDFW-JFK6D_2024.exe (Office_Deployment_Tool) File Analysis

Technical Analysis

File Name Setup_it-IT_DBWQN-2DHPP-7XGRH-MKDFW-JFK6D_2024.exe
File Type
PE32 executable (console) Intel 80386, for MS Windows
Scanner Version 1.0.214.174
Database Version 2025-04-22 23:00:27 UTC
āœ“

Clean File

No threats detected by our scanner

0%
Detection Rate
13,416,096
File Size (bytes)
2025-04-22
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
1487c175a066a5f5aec5a72ffdd9ae3d
SHA1
ce75d1580d0a6364b0113a61895509a2a364b2b2
SHA256
f9cb255376f334bf2dae9a78136c6268dccf4e167bff93217eeb8b45f7ac49c1
SHA512
7518615e8d533db68c6be794b2a52a78848eb9d168f66ac7ae304f251a556d7f19ba57814df90d9e1b32047ad39326909900c30efe37ce6673a44e50d12d7cf8
ImpHash
aa9f3a2087e12b9bb85387e33424b173

PE Analysis

Basic Information

ā–¼
Icon
Hash: cf8b3d44cc80ac3d3f5b2c3f6848133a
Fuzzy: 71fcd2e860bbcd562ce257f969072383
dHash: e0c8ccc6c6c6c0e0
Image Base 0x00400000
Entry Point 0x008ebeb0
Compilation Time 2024-03-19 19:35:24
Checksum 0x00ccfc7d (Actual: 0x00ccfc7d)
OS Version 6.0
PEiD Signatures PE32 executable (console) Intel 80386, for MS Windows
PDB Path D:\a\_work\1\s\artifacts\obj\coreclr\windows.x86.Release\Corehost.Static\singlefilehost.pdb
Digital Signature An error occurred while validating the countersignature: The root Certum Trusted Network CA 2 lists its extended key usages, but {'time_stamping'} are not present
Imports 17 libraries
Exports 5 functions
Resources 10 Resources
Sections 8 Sections

Version Information

ā–¼
Translation 0x0000 0x04b0
CompanyName Office_Deployment_Tool
FileDescription Office_Deployment_Tool
FileVersion 1.0.0.0
InternalName Office_Deployment_Tool.dll
LegalCopyright
OriginalFilename Office_Deployment_Tool.dll
ProductName Office_Deployment_Tool
ProductVersion 1.0.0+1985d1889c3f41f18b3edf7274cf3d88ac061d4d
Assembly Version 1.0.0.0

PE Sections

ā–¼
Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 5,487,050 bytes 5,487,104 bytes 6.56 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 27028F6C227E03E80EDD3FA24FA8760B
.CLR_UEF 0x0053d000 68 bytes 512 bytes 0.96 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ F2B641ED546BF3BC31D08DEC881D9E8C
.rdata 0x0053e000 1,281,134 bytes 1,281,536 bytes 5.15 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C8DF93EE833A4A778AD2DDFF72671A8F
.data 0x00677000 80,836 bytes 29,184 bytes 3.81 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C298453753D5BC98E8D564A93CCED00F
.didat 0x0068b000 28 bytes 512 bytes 0.26 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 34950FE11F3A721D87970A33D0128597
_RDATA 0x0068c000 69,392 bytes 69,632 bytes 5.36 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 211089D7D672E1712B48C26D0BDC0A1B
.rsrc 0x0069d000 1,351,056 bytes 1,351,168 bytes 6.24 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 0140BA018E8A1F17276ED2DD8AF87D00
.reloc 0x007e7000 261,920 bytes 262,144 bytes 6.67 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 863392D201BA4CD20AC6B106854BDF4F
Entropy Analysis Alert

2 section(s) with elevated entropy (≄6.5) - possible compression

Resource Analysis

ā–¼
Total Resources: 10 (1,350,288 bytes)
Resource Type Count Total Size Percentage
RT_ICON 4 82,656 bytes
6.1%
RT_RCDATA 3 1,266,152 bytes
93.8%
RT_GROUP_ICON 1 62 bytes
0%
RT_VERSION 1 928 bytes
0.1%
RT_MANIFEST 1 490 bytes
0%

Certificate Chain Analysis

ā–¼
Certificate Information
Product Office_Deployment_Tool
Description Office_Deployment_Tool
File Version 1.0.0.0
Original Name Office_Deployment_Tool.dll
Signing Date 11:18 AM 11/29/2024 (190 days ago)
Verification Status Signed
Signers AGM Software OÜ; Certum Extended Validation Code Signing 2021 CA; Certum Trusted Network CA 2; Certum Trusted Network CA
Counter Signers Certum Timestamp 2023; Certum Timestamping 2021 CA; Certum Trusted Network CA 2; Certum Trusted Network CA
Internal Name Office_Deployment_Tool.dll
Certificate Chain Summary
.NET DAC #1 Primary
Validity Period: 2024-01-11 20:05:37 → 2025-01-10 20:05:37
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 05 63 7E FC 35 2E 2D 23 08 E3 00 00 00 00 05 63
Microsoft Code Signing PCA 2010 #2 Chain
Validity Period: 2010-07-06 20:40:17 → 2025-07-06 20:50:17
Signature Algorithm: sha256RSA
Serial Number: 61 0C 52 4C 00 00 00 00 00 03
Microsoft Time-Stamp Service #3 Chain
Validity Period: 2023-10-12 19:06:59 → 2025-01-10 19:06:59
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 01 DA 8E D5 C9 5A 00 D1 11 B1 00 01 00 00 01 DA
Microsoft Time-Stamp PCA 2010 #4 Chain
Validity Period: 2021-09-30 18:22:25 → 2030-09-30 18:32:25
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15
Certum Trusted Network CA 2 #5 Chain
Validity Period: 2021-05-31 06:43:06 → 2029-09-17 06:43:06
Signature Algorithm: sha384RSA
Serial Number: 1B B5 8F 25 2A DF 23 00 49 28 C9 AE 3D 7E ED 27
Certum Timestamp 2023 #6 Chain
Validity Period: 2023-11-02 08:32:23 → 2034-10-30 08:32:23
Signature Algorithm: sha384RSA
Serial Number: 09 C5 CC F8 BB 66 7D 71 37 AA C1 59 80 06 CB 31
Certum Timestamping 2021 CA #7 Chain
Validity Period: 2021-05-19 05:32:07 → 2036-05-18 05:32:07
Signature Algorithm: sha384RSA
Serial Number: E7 FF 69 C7 3B 35 CE 4B 91 26 D8 74 7C 68 A5 87
Certum Extended Validation Code Signing 2021 CA #8 Chain
Validity Period: 2021-05-19 05:32:13 → 2036-05-18 05:32:13
Signature Algorithm: sha384RSA
Serial Number: BB F0 CC B5 B7 B8 31 FD 21 AE 32 77 8A E4 0C 89
AGM Software OÜ #9 Chain
Validity Period: 2024-05-17 12:08:57 → 2025-05-17 12:08:56
Signature Algorithm: sha256RSA
Serial Number: 04 51 56 00 AF 94 B0 95 1F B6 28 12 AD D4 70 B6

āœ“ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

An error occurred while validating the countersignature: The root Certum Trusted Network CA 2 lists its extended key usages, but {'time_stamping'} are not present

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware