Sigcheck
How to verify file signatures using Sigcheck from the SysInternals Suite?
Tool Name
Version
MITRE ATT&CK Tactic
MITRE ATT&CK Technique
MITRE ATT&CK Sub-Technique
Instructions
Scanning a Single File
sigcheck64.exe -a -vt -h ruby.exeOutput
Sigcheck v2.90 - File version and signature viewer
Copyright (C) 2004-2022 Mark Russinovich
Sysinternals - www.sysinternals.com
C:\Ruby31-x64\bin\ruby.exe:
Verified: Unsigned
Link date: 10:00 01-Jan-70
Publisher: n/a
Company: http://www.ruby-lang.org/
Description: Ruby interpreter (CUI) 3.1.2p20 [x64-mingw-ucrt]
Product: Ruby interpreter 3.1.2p20 [x64-mingw-ucrt]
Prod version: 3.1.2p20
File version: 3.1.2p20
MachineType: 64-bit
Binary Version: 3.1.2.20
Original Name: ruby.exe
Internal Name: ruby.exe
Copyright: Copyright (C) 1993-2022 Yukihiro Matsumoto
Comments: 2022-04-12
Entropy: 5.294
MD5: A0E29BD17600C72A9472187FAB9E8CEE
SHA1: FC4B38E05DF834A3ADFCF310EBCF2561D1D66952
PESHA1: 20675D526BCAD96E5CEF3C54253AEFDDA290D53E
PE256: 72D1B920F65B035B0D61123CD499CAB7AFE61F9F3081131143228555881600DB
SHA256: A42943060B508B9C559BB77A8B059E4F3FFACB955DC8AB532D61314945EFC8A9
IMP: 63736A2F715AAEA097231DF6FA236320
VT detection: 0/74
VT link: https://www.virustotal.com/gui/file/a42943060b508b9c559bb77a8b059e4f3ffacb955dc8ab532d61314945efc8a9/detectionScanning Files Within a Directory
Output

Additional Detail
Importing of Digital Signature Catalog for Offline Analysis
Sources
Last updated