830955f41d38ed9da55e92bacd1a92dfa8f19aca8c542c1d54c5ebb9bcd1421a

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2059-Mar-15 07:59:31
Detected languages English - United States
Debug artifacts AdhSvc.pdb
CompanyName Microsoft Corporation
FileDescription AD Harvest Sites and Subnets Service
FileVersion 10.0.26100.5074 (WinBuild.160101.0800)
InternalName adhsvc.dll
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename adhsvc.dll
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.26100.5074

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentControlSet\services
Suspicious The PE is possibly packed. Unusual section name found: fothk
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Can access the registry:
  • RegCloseKey
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCreateKeyExW
  • RegQueryInfoKeyW
  • RegEnumKeyExW
  • RegDeleteValueW
  • RegSetValueExW
Interacts with services:
  • OpenServiceW
  • OpenSCManagerW
Safe VirusTotal score: 0/70 (Scanned on 2026-08-04 16:10:00) All the AVs think this file is safe.

Hashes

MD5 5d9d8994a3a965dcd987f33d8dd42bb5 🔍
SHA1 feee02517714471c5e873d818ffb7b0bd8422f8b 🔍
SHA256 830955f41d38ed9da55e92bacd1a92dfa8f19aca8c542c1d54c5ebb9bcd1421a 🔍
SHA3 9a0aaffdfd4a44bd7879cc1e8e53d31aa3460e103e61329f2e8ab0a33d378c1b 🔍
SSDeep 1536:2TqcdSKcfC8A9/qSHEtrEUWDp9k9YWYbiK/0WUpIlLnr1+szh:2FX8aiSkKUWDL/3i2UpINnxP 🔍
Imports Hash 629723207d4d35bf9283b7ff243b81b9 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 8
TimeDateStamp 2059-Mar-15 07:59:31
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xf000
SizeOfInitializedData 0xb000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000075D0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion A.0
ImageVersion A.0
SubsystemVersion A.0
Win32VersionValue 0
SizeOfImage 0x1b000
SizeOfHeaders 0x1000
Checksum 0x25bd0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x40000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 bc94145e16bcf1e19c52479013773ff4 🔍
SHA1 8f42c0db30544d06cb4de37dc81c5bae0e32d836 🔍
SHA256 83c058e1e959ed5c701731af8fb036c61453f3aa329b5db24437134b40de6379 🔍
SHA3 231050bd2f787bc5f2e8874be07d5c84ed2c01fa300fab69fad5879074ed35d1 🔍
VirtualSize 0xd08a
VirtualAddress 0x1000
SizeOfRawData 0xe000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.83931

fothk

MD5 ab8892f0eb6a6023324bd629a0ac9fcb 🔍
SHA1 49661895a4fb5246dad5e423c2011a1767008669 🔍
SHA256 47b5ba7d09134205773d05a1aea66476ef385734a182086b339a452a7616827e 🔍
SHA3 bc75c7f85a93d9fa8688012a4a8361587bcd55147e9841580eca2a5765f0989b 🔍
VirtualSize 0x1000
VirtualAddress 0xf000
SizeOfRawData 0x1000
PointerToRawData 0xf000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 0.0159202

.rdata

MD5 2cab48add2d4c8aaa509faa9f61b2631 🔍
SHA1 787084dfdbb2036f9251c49421c55c062b16c209 🔍
SHA256 89f45a9396adc9fdee95b66ea3a6c277858bc479fc09d80fe21666ea42420cf8 🔍
SHA3 e75ffa60b54895a811fc06ff3968e37a6a5b3ab22c73ac24a9846359a7f13442 🔍
VirtualSize 0x5780
VirtualAddress 0x10000
SizeOfRawData 0x6000
PointerToRawData 0x10000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.28601

.data

MD5 e86fc7997b02ca3e3e621d76900cc904 🔍
SHA1 1255e93591476a590d3a81ef9d07b349711a1f55 🔍
SHA256 d88b9611e984b9bdd173b1101c069c113a8b316e7e85105bcb2ad7b889200150 🔍
SHA3 8c8dbb5d9734edee30fdd628cdabc7749dcf8562e9b620c9f4a41756b4bafafb 🔍
VirtualSize 0xda0
VirtualAddress 0x16000
SizeOfRawData 0x1000
PointerToRawData 0x16000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.488961

.pdata

MD5 8021b7eda79093a4ff5f795f37f871f7 🔍
SHA1 d076703f4d02124f15aae19d1de22b812572bde9 🔍
SHA256 c0dd7502e524b5e71d3ca74178c196349a568c86ab2d3d5bb6a26adadce1da1d 🔍
SHA3 a0c88d5b87aa881511082e641453ef4d4393a58c434ef86bccc8b2ce3fbbb440 🔍
VirtualSize 0xd44
VirtualAddress 0x17000
SizeOfRawData 0x1000
PointerToRawData 0x17000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.23929

.didat

MD5 5b8edacc3c9b8e13735b5ca8c6c4af42 🔍
SHA1 94ddc24854b302b1f40d11d12f743bf58973d2e2 🔍
SHA256 2fec8ab3011ba6eb91182257c920d22ee08207697d903f749f5f42d6164ed2e6 🔍
SHA3 7820d0fe2acfcc3e1efd802e8dc295c8da83bfbb403bd0fabd3a34ababcc6604 🔍
VirtualSize 0x30
VirtualAddress 0x18000
SizeOfRawData 0x1000
PointerToRawData 0x18000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.0365667

.rsrc

MD5 c15470fc21c75452770e8b1dfb9ee936 🔍
SHA1 e7251bc862161bf5effb8e032bad0633034ca1e1 🔍
SHA256 eaf13a11917832fb62c2c132e09e2b080c347cdaff6b405399840c8f9f6df9a1 🔍
SHA3 aed815507ef74d72cda7a6c078242fbaffdd14d4c60571acc8b424fa58b67e95 🔍
VirtualSize 0x418
VirtualAddress 0x19000
SizeOfRawData 0x1000
PointerToRawData 0x19000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.11448

.reloc

MD5 2394deb90ee92ef3aa53cfd36d16464b 🔍
SHA1 3ab51dd5c4c70452c66bda9456e7db2743aa7f89 🔍
SHA256 8637e53a957acfd7db56b3f0dc714fad741de9a57e6b63a23edcd571836fda7e 🔍
SHA3 bc677d68a586ccdc87b0275a9935e9cef2ec7bf5ad1932399b480caaa25524d9 🔍
VirtualSize 0x220
VirtualAddress 0x1a000
SizeOfRawData 0x1000
PointerToRawData 0x1a000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.06456

Imports

api-ms-win-crt-runtime-l1-1-0.dll _initterm
_initterm_e
api-ms-win-crt-private-l1-1-0.dll _o__initialize_narrow_environment
_o__initialize_onexit_table
_o__invalid_parameter_noinfo
_o__recalloc
_o__register_onexit_function
_o__seh_filter_dll
memcpy
_o_free
_o_malloc
_o_wcsncpy_s
__C_specific_handler
__CxxFrameHandler3
_CxxThrowException
_o__execute_onexit_table
_o__errno
_o__crt_atexit
_o__configure_narrow_argv
_o__cexit
_o__callnewh
_o___std_type_info_destroy_list
_o___std_exception_destroy
_o___std_exception_copy
__std_terminate
__CxxFrameHandler4
__C_specific_handler_noexcept
api-ms-win-crt-string-l1-1-0.dll memset
ntdll.dll RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
api-ms-win-eventing-classicprovider-l1-1-0.dll TraceMessage
GetTraceEnableLevel
GetTraceEnableFlags
RegisterTraceGuidsW
UnregisterTraceGuids
GetTraceLoggerHandle
api-ms-win-core-synch-l1-1-0.dll EnterCriticalSection
SetEvent
WaitForSingleObject
WaitForMultipleObjectsEx
ResetEvent
WaitForSingleObjectEx
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
InitializeCriticalSection
ReleaseMutex
CreateMutexW
LeaveCriticalSection
CreateEventW
api-ms-win-core-heap-l1-1-0.dll HeapAlloc
HeapFree
GetProcessHeap
api-ms-win-core-libraryloader-l1-2-0.dll FreeLibrary
LoadResource
FindResourceExW
DisableThreadLibraryCalls
GetProcAddress
GetModuleHandleW
SizeofResource
GetModuleFileNameW
LoadLibraryExW
api-ms-win-security-sddl-l1-1-0.dll ConvertStringSidToSidW
ConvertStringSecurityDescriptorToSecurityDescriptorW
api-ms-win-core-errorhandling-l1-1-0.dll GetLastError
SetLastError
UnhandledExceptionFilter
SetUnhandledExceptionFilter
RaiseException
api-ms-win-core-heap-l2-1-0.dll LocalFree
RPCRT4.dll RpcServerUnregisterIfEx
I_RpcBindingIsClientLocal
RpcBindingToStringBindingW
RpcEpUnregister
RpcImpersonateClient
RpcEpRegisterW
RpcServerInqBindings
RpcServerRegisterIfEx
RpcServerUseProtseqW
RpcStringFreeW
RpcServerRegisterAuthInfoW
RpcServerInqDefaultPrincNameW
RpcBindingInqAuthClientW
RpcRevertToSelf
Ndr64AsyncServerCallAll
NdrServerCallAll
NdrAsyncServerCall
RpcAsyncAbortCall
RpcAsyncCompleteCall
RpcStringBindingParseW
NdrServerCall2
RpcBindingVectorFree
api-ms-win-core-sysinfo-l1-1-0.dll GetSystemTimeAsFileTime
api-ms-win-core-threadpool-l1-2-0.dll WaitForThreadpoolTimerCallbacks
SetThreadpoolTimer
CreateThreadpoolTimer
WaitForThreadpoolWaitCallbacks
CloseThreadpoolWait
SetThreadpoolWait
CreateThreadpoolWait
CloseThreadpoolTimer
api-ms-win-core-handle-l1-1-0.dll CloseHandle
api-ms-win-core-processthreads-l1-1-0.dll OpenThreadToken
GetCurrentThread
TerminateProcess
GetCurrentProcess
GetCurrentProcessId
CreateThread
GetCurrentThreadId
api-ms-win-service-management-l1-1-0.dll OpenServiceW
CloseServiceHandle
StartServiceW
OpenSCManagerW
api-ms-win-service-management-l2-1-0.dll NotifyServiceStatusChangeW
WLDAP32.dll #191
#27
#41
#135
#13
#145
#14
#18
#88
#73
#224
#203
#97
#140
#16
#206
#26
api-ms-win-core-localization-l1-2-0.dll FormatMessageW
api-ms-win-core-debug-l1-1-0.dll IsDebuggerPresent
api-ms-win-core-string-l1-1-0.dll MultiByteToWideChar
api-ms-win-core-com-l1-1-0.dll CoUninitialize
CoTaskMemAlloc
CoTaskMemFree
CoTaskMemRealloc
CoInitializeEx
CoCreateInstance
api-ms-win-security-base-l1-1-0.dll AccessCheck
api-ms-win-core-registry-l1-1-0.dll RegCloseKey
RegQueryValueExW
RegOpenKeyExW
RegCreateKeyExW
RegQueryInfoKeyW
RegEnumKeyExW
RegDeleteValueW
RegSetValueExW
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceCounter
api-ms-win-core-interlocked-l1-1-0.dll InitializeSListHead
api-ms-win-core-processthreads-l1-1-1.dll IsProcessorFeaturePresent
api-ms-win-core-string-obsolete-l1-1-0.dll lstrcmpiW
FirewallAPI.dll FwConvertIPv6SubNetToRange
FwCopyWFAddressesContents
FwAlloc
FwFree
FwGetAddressesAsString
FwFreeAddresses
FwStringToAddresses
FwMergeAddresses
OLEAUT32.dll VarUI4FromStr
api-ms-win-core-string-l2-1-0.dll CharNextW
api-ms-win-core-delayload-l1-1-1.dll ResolveDelayLoadedAPI
api-ms-win-core-delayload-l1-1-0.dll DelayLoadFailureHook
wkscli.dll (delay-loaded) NetGetJoinInformation

Delayed Imports

Attributes 0x1
Name wkscli.dll
ModuleHandle 0x16878
DelayImportAddressTable 0x18020
DelayImportNameTable 0x13ba0
BoundDelayImportTable 0x13c00
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

SubServiceScmNotification

Ordinal 1
Address 0x36f0

SubServiceStart

Ordinal 2
Address 0x4190

SubServiceStop

Ordinal 3
Address 0x88b0

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x3b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5073
MD5 d6f7a2dc7e23f426443fdca009d2efcc 🔍
SHA1 a8d1996c6ce68c5fb2c49d97e1681f4523ed4c37 🔍
SHA256 980b6a9ac5da0e1f51c556baa533b20fb562059ee3b66679828daf820180df61 🔍
SHA3 26cbdda4bd3e2635760d994523c40f8a5cf43fce27de5f0cd304ea38770ec6be 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 10.0.26100.5074
ProductVersion 10.0.26100.5074
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Microsoft Corporation
FileDescription AD Harvest Sites and Subnets Service
FileVersion (#2) 10.0.26100.5074 (WinBuild.160101.0800)
InternalName adhsvc.dll
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename adhsvc.dll
ProductName Microsoft® Windows® Operating System
ProductVersion (#2) 10.0.26100.5074
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2059-Mar-15 07:59:31
Version 0.0
SizeofData 35
AddressOfRawData 0x12818
PointerToRawData 0x12818
Referenced File AdhSvc.pdb

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2059-Mar-15 07:59:31
Version 0.0
SizeofData 1152
AddressOfRawData 0x1283c
PointerToRawData 0x1283c

UNKNOWN

Characteristics 0
TimeDateStamp 2059-Mar-15 07:59:31
Version 0.0
SizeofData 36
AddressOfRawData 0x12ce4
PointerToRawData 0x12ce4

UNKNOWN (#2)

Characteristics 0
TimeDateStamp 2059-Mar-15 07:59:31
Version 0.0
SizeofData 4
AddressOfRawData 0x12d08
PointerToRawData 0x12d08

TLS Callbacks

StartAddressOfRawData 0x180012d30
EndAddressOfRawData 0x180012d38
AddressOfIndex 0x180016870
AddressOfCallbacks 0x180011258
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x148
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x180016180
GuardCFCheckFunctionPointer 6442521016
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0xd27f8af7
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 86
Unmarked objects (#2) 1
C objects (33145) 14
ASM objects (33145) 5
Total imports 1275
Imports (33145) 7
C++ objects (33145) 29
Exports (33145) 1
C objects (LTCG) (33145) 22
253 (33145) 1
Resource objects (33145) 1
Linker (33145) 1

Errors

Leave a comment

No comments yet.