| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2025-Jan-27 10:50:41 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
D:\git\adp-ipc\bin\x64\Release\AdpIPC.pdb
|
| CompanyName | Autodesk, Inc. |
| FileDescription | Autodesk IPC Library |
| FileVersion | 2.0.1.0 |
| InternalName | AdpIPC.dll |
| LegalCopyright | © Autodesk, Inc. All rights reserved. |
| OriginalFilename | AdpIPC.dll |
| ProductName | Autodesk IPC Component |
| ProductVersion | 2.0.1.0 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA1
Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Autodesk
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Safe | VirusTotal score: 0/73 (Scanned on 2025-03-27 06:16:05) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x128 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2025-Jan-27 10:50:41 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x1b2600 |
| SizeOfInitializedData | 0xa4200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000011ED68 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x25b000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x25a95e |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetProcAddress
LoadLibraryA CreateFileA CloseHandle GetLastError ConnectNamedPipe DisconnectNamedPipe GetOverlappedResult CancelIo WaitForSingleObject CreateEventW Sleep CreateNamedPipeA WaitNamedPipeA LockFileEx ReadFile UnlockFileEx PeekNamedPipe GetSystemInfo LocalFree FormatMessageA FlushFileBuffers WriteFile SetLastError FormatMessageW WideCharToMultiByte GetEnvironmentVariableW FreeLibrary GetCurrentDirectoryW CreateDirectoryW CreateFileW DeleteFileW GetDiskFreeSpaceExW GetFileAttributesW GetFileAttributesExW GetFileInformationByHandle GetFileTime GetFullPathNameW RemoveDirectoryW SetEndOfFile SetFileAttributesW SetFilePointerEx SetFileTime DeviceIoControl GetWindowsDirectoryW GetModuleHandleW CreateDirectoryExW CopyFileExW MoveFileExW AreFileApisANSI MultiByteToWideChar QueryPerformanceCounter QueryPerformanceFrequency GetCurrentThread GetThreadTimes CreateWaitableTimerA GetCurrentProcessId DeleteCriticalSection InitializeCriticalSection LeaveCriticalSection SetCurrentDirectoryW EnterCriticalSection GetModuleHandleA GetLogicalProcessorInformation SetWaitableTimer OpenEventA InitializeSRWLock ReleaseSRWLockExclusive AcquireSRWLockExclusive InitializeCriticalSectionEx TryEnterCriticalSection GetCurrentThreadId WaitForSingleObjectEx SwitchToThread GetExitCodeThread GetNativeSystemInfo InitializeConditionVariable WakeConditionVariable WakeAllConditionVariable SleepConditionVariableCS SleepConditionVariableSRW SetFileInformationByHandle FlsAlloc FlsGetValue FlsSetValue FlsFree InitOnceExecuteOnce CreateEventExW CreateSemaphoreExW FlushProcessWriteBuffers GetCurrentProcessorNumber GetSystemTimeAsFileTime GetTickCount64 FreeLibraryWhenCallbackReturns CreateThreadpoolWork SubmitThreadpoolWork CloseThreadpoolWork CreateThreadpoolTimer SetThreadpoolTimer WaitForThreadpoolTimerCallbacks CloseThreadpoolTimer CreateThreadpoolWait SetThreadpoolWait CloseThreadpoolWait GetFileInformationByHandleEx CreateSymbolicLinkW EncodePointer DecodePointer LCMapStringEx GetLocaleInfoEx GetStringTypeW CompareStringEx GetCPInfo InitializeSListHead InitializeCriticalSectionAndSpinCount SetEvent ResetEvent RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetCurrentProcess TerminateProcess RtlUnwindEx RtlPcToFileHeader RaiseException InterlockedPushEntrySList InterlockedFlushSList TlsAlloc TlsGetValue TlsSetValue TlsFree LoadLibraryExW CreateThread ExitThread ResumeThread FreeLibraryAndExitThread GetModuleHandleExW ExitProcess GetModuleFileNameW HeapFree HeapAlloc GetStdHandle GetFileType GetTempPathW GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetConsoleOutputCP GetConsoleMode GetFileSizeEx ReadConsoleW HeapReAlloc HeapSize HeapQueryInformation SetConsoleCtrlHandler GetTimeZoneInformation FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetACP GetOEMCP GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW GetProcessHeap SetStdHandle WriteConsoleW OutputDebugStringW ReleaseSemaphore WaitForMultipleObjectsEx CreateEventA RtlUnwind |
|---|---|
| ADVAPI32.dll |
CryptReleaseContext
CryptAcquireContextA SetSecurityDescriptorDacl InitializeSecurityDescriptor CryptGenRandom |
| bcrypt.dll |
BCryptOpenAlgorithmProvider
BCryptCloseAlgorithmProvider BCryptGenRandom |
| Ordinal | 1 |
|---|---|
| Address | 0x282d0 |
| Ordinal | 2 |
|---|---|
| Address | 0x28440 |
| Ordinal | 3 |
|---|---|
| Address | 0x285b0 |
| Ordinal | 4 |
|---|---|
| Address | 0x286e0 |
| Ordinal | 5 |
|---|---|
| Address | 0x28730 |
| Ordinal | 6 |
|---|---|
| Address | 0x287e0 |
| Ordinal | 7 |
|---|---|
| Address | 0x288b0 |
| Ordinal | 8 |
|---|---|
| Address | 0x28970 |
| Ordinal | 9 |
|---|---|
| Address | 0x28a30 |
| Ordinal | 10 |
|---|---|
| Address | 0x28ad0 |
| Ordinal | 11 |
|---|---|
| Address | 0x28ae0 |
| Ordinal | 12 |
|---|---|
| Address | 0x28cc0 |
| Ordinal | 13 |
|---|---|
| Address | 0x28cd0 |
| Ordinal | 14 |
|---|---|
| Address | 0x28ef0 |
| Ordinal | 15 |
|---|---|
| Address | 0x291a0 |
| Ordinal | 16 |
|---|---|
| Address | 0x291c0 |
| Ordinal | 17 |
|---|---|
| Address | 0x291f0 |
| Ordinal | 18 |
|---|---|
| Address | 0x29390 |
| Ordinal | 19 |
|---|---|
| Address | 0x29440 |
| Ordinal | 20 |
|---|---|
| Address | 0x29510 |
| Ordinal | 21 |
|---|---|
| Address | 0x29710 |
| Ordinal | 22 |
|---|---|
| Address | 0x297c0 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.0.1.0 |
| ProductVersion | 2.0.1.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | Autodesk, Inc. |
| FileDescription | Autodesk IPC Library |
| FileVersion (#2) | 2.0.1.0 |
| InternalName | AdpIPC.dll |
| LegalCopyright | © Autodesk, Inc. All rights reserved. |
| OriginalFilename | AdpIPC.dll |
| ProductName | Autodesk IPC Component |
| ProductVersion (#2) | 2.0.1.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Jan-27 10:50:41 |
| Version | 0.0 |
| SizeofData | 66 |
| AddressOfRawData | 0x1f1c44 |
| PointerToRawData | 0x1f0644 |
| Referenced File | D:\git\adp-ipc\bin\x64\Release\AdpIPC.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Jan-27 10:50:41 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1f1c88 |
| PointerToRawData | 0x1f0688 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Jan-27 10:50:41 |
| Version | 0.0 |
| SizeofData | 1116 |
| AddressOfRawData | 0x1f1c9c |
| PointerToRawData | 0x1f069c |
| StartAddressOfRawData | 0x1801f2118 |
|---|---|
| EndAddressOfRawData | 0x1801f2120 |
| AddressOfIndex | 0x18023b840 |
| AddressOfCallbacks | 0x1801b47f8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks |
0x0000000180192180
|
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1802283c8 |
| XOR Key | 0x4a066cd1 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 13 |
| C++ objects (30795) | 183 |
| C objects (30795) | 18 |
| C objects (30034) | 14 |
| ASM objects (30034) | 10 |
| C++ objects (30034) | 91 |
| Imports (30795) | 7 |
| Total imports | 193 |
| C++ objects (VS2022 Update 6 (17.6.3) compiler 32534) | 36 |
| ASM objects (VS2022 Update 6 (17.6.3) compiler 32534) | 1 |
| C++ objects (VS2019 Update 11 (16.11.16-17) compiler 30146) | 9 |
| C++ objects (30154) | 17 |
| Exports (30154) | 1 |
| Resource objects (30154) | 1 |
| 151 | 1 |
| Linker (30154) | 1 |
No comments yet.