rammap64.exe

RamMap

Sysinternals

Publisher:
Sysinternals - www.sysinternals.com  (signed by Sysinternals)

Product:
RamMap

Description:
RamMap - physical memory analyzer

Version:
1.11

MD5:
f0c48c8ea390db1dd5e44cf02f35dd9d

SHA-1:
4d43108bd2e50c9616f62cda20c7b6372e25ec53

SHA-256:
f875399cbdba709473d87dbac43145d5c0ca2357e066efd119fdcd652b0ccc59

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 3:28:29 AM UTC  (today)

File size:
312.3 KB (319,816 bytes)

Product version:
1.11

Copyright:
Copyright © 2010-2011 Mark Russinovich and Bryce Cogswell

Original file name:
RamMap

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/4/2010 12:00:00 AM

Valid to:
4/19/2013 12:59:59 AM

Subject:
CN=Sysinternals, OU=Headquarters, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sysinternals, L=Austin, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4112E632C7B18A029A3A1FAC803AB89F

File PE Metadata
Compilation timestamp:
5/17/2011 8:24:12 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:hUnmLVRtKfx6lHO/dDg3InlcbkbYy2R+BOW3rUE+AV:hUYtKfQRI3lcbk8RaUdAV

Entry address:
0x24994

Entry point:
48, 83, EC, 28, E8, 67, 52, 00, 00, 48, 83, C4, 28, E9, 1A, FE, FF, FF, CC, CC, 48, 83, EC, 38, 80, 3D, A9, 41, 02, 00, 00, 75, 26, 83, 64, 24, 20, 00, 41, B9, 01, 00, 00, 00, 45, 33, C0, 33, D2, 33, C9, C6, 05, 8E, 41, 02, 00, 01, E8, 15, A1, FE, FF, 48, 8B, C8, E8, DD, 52, 00, 00, 48, 83, C4, 38, C3, 48, 83, EC, 38, 41, B9, 01, 00, 00, 00, 45, 33, C0, 33, D2, 33, C9, 44, 89, 4C, 24, 20, E8, ED, A0, FE, FF, 48, 83, C4, 38, C3, 48, 89, 7C, 24, 08, 4C, 8B, C9, 48, 85, C9, 74, 22, 48, 85, D2, 74, 1D, 4D, 85...
 
[+]

Entropy:
6.2514

Code size:
213 KB (218,112 bytes)