Process
ubiquitoussigned
calculatorapp.exe
File identity
File details
- File type
- PE32+ executable
- Magic
- PE32+ executable (GUI)
- Original name
- CalculatorApp.exe
- Internal name
- CalculatorApp.exe
- Product
- Microsoft Calculator
Signing information
- Status
- Signed
- Publisher
- Microsoft Corporation
- Signer
- Microsoft Corporation
- Signature rate
- 100%
File version1
11.2311.0.0100%
File size1
19.00 KB100%
Execution context
File paths1
C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2311.0.0_x64__8wekyb3d8bbwe\CalculatorApp.exe100%
User context1
Interactive user100%
Integrity level1
AppContainer100%
Instances1
1100%
Session1
Session 1100%
Token privileges0
Not observed.
Ancestry
Parents1
svchost.exe100%
Children0
Not observed.
Grandparents0
Not observed.
Grandchildren0
Not observed.
Behavior
Loaded modules117
mrt100_app.dll100%kernelbase.dll100%execmodelproxy.dll100%vcruntime140_1_app.dll100%msvcrt.dll100%
Named pipes0
Not observed.
Process handles0
Not observed.
Command-line patterns1
"C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2311.0.0_x64__8wekyb3d8bbwe\CalculatorApp.exe" -ServerName:App.<redacted>.mca100%
Indicators
SHA-2561
e21f9dce7e9ea0799ee0ca5b1f562e575d8debe54f68aa07360c8f34a8e7e1b8100%VirusTotal·MalwareBazaar·Hybrid Analysis·ANY.RUN·Google
SHA-11
8624440cecf2577e332f18694ccdec840eac8cc6100%VirusTotal·MalwareBazaar·Hybrid Analysis·ANY.RUN·Google
MD51
be3bcadc0fd36eb3fe6b46f655fb39be100%VirusTotal·MalwareBazaar·Hybrid Analysis·ANY.RUN·Google
Imphash1
50b4a56a3eb2e1afa1f4617500c0d4ff100%VirusTotal·MalwareBazaar·Google
Authentihash1
97baf02c986c67bbf730ee52eece9ea010b50704b82b7c055edd069c8a7d8ec7100%VirusTotal·Google
ssdeep1
384:reN7qJTQ/tBaxc8IcbUi+7AOG6HMf82utc2NIWE4W:reN7qJXk+100%MalwareBazaar·Google
Analysis
About this process
No analyst write-up yet.
Security notes
No analyst write-up yet.
Anomaly signals
None defined yet.
Telemetry
OS prevalence1
Microsoft Windows 11 Enterprise Evaluation100%
Observation timeline
- First seen
- 2026-06-08
- Last seen
- 2026-06-08
- Machines
- 1
- Executions
- 1