Process
ubiquitoussigned
applicationframehost.exe
File identity
File details
- File type
- PE32+ executable
- Magic
- PE32+ executable (GUI)
- Original name
- ApplicationFrameHost.exe
- Internal name
- Application Frame Host
- Product
- Microsoft® Windows® Operating System
Signing information
- Status
- Signed
- Publisher
- Microsoft Corporation
- Signer
- Microsoft Windows
- Issuer
- Microsoft Windows Production PCA 2011
- Signature rate
- 100%
File version1
10.0.26100.8328 (WinBuild.160101.0800)100%
File size1
94.30 KB100%
Execution context
File paths1
C:\Windows\System32\ApplicationFrameHost.exe100%
User context1
Interactive user100%
Integrity level1
Medium100%
Instances1
1100%
Session1
Session 1100%
Token privileges1
SeChangeNotifyPrivilege100%
Ancestry
Parents1
svchost.exe100%
Children0
Not observed.
Grandparents0
Not observed.
Grandchildren0
Not observed.
Behavior
Loaded modules73
Named pipes0
Not observed.
Process handles2
explorer.exe100%calculatorapp.exe100%
Command-line patterns1
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding100%
Indicators
SHA-2561
e44b9dd65c04b67254d80295b928a5800ee6690046302899075710c352d7e81b100%VirusTotal·MalwareBazaar·Hybrid Analysis·ANY.RUN·Google
SHA-11
1bfb8081e59a3a3d1207e1548bd2860457259cd2100%VirusTotal·MalwareBazaar·Hybrid Analysis·ANY.RUN·Google
MD51
4a07e32a8922b97e86241fcd512102a2100%VirusTotal·MalwareBazaar·Hybrid Analysis·ANY.RUN·Google
Imphash1
28580eceb0562a8a7fbd08dc4f37b368100%VirusTotal·MalwareBazaar·Google
Analysis
About this process
No analyst write-up yet.
Security notes
No analyst write-up yet.
Anomaly signals
None defined yet.
Telemetry
OS prevalence1
Microsoft Windows 11 Enterprise Evaluation100%
Observation timeline
- First seen
- 2026-06-08
- Last seen
- 2026-06-08
- Machines
- 1
- Executions
- 1