| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2015-Jun-03 09:33:02 |
| Detected languages |
English - United States
|
| Debug artifacts |
api-ms-win-core-file-l1-2-0.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | ApiSet Stub DLL |
| FileVersion | 10.0.10137.0 (th1.150602-2238) |
| InternalName | apisetstub |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | apisetstub |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 10.0.10137.0 |
| Suspicious | The PE is possibly packed. | The PE only has 0 import(s). |
| Info | The PE is digitally signed. |
Signer: Microsoft Windows
Issuer: Microsoft Windows Production PCA 2011 |
| Safe | VirusTotal score: 0/72 (Scanned on 2026-03-25 20:47:08) | All the AVs think this file is safe. |
| MD5 | 7041205ea1a1d9ba68c70333086e6b48 🔍 |
|---|---|
| SHA1 | 5034155f7ec4f91e882eae61fd3481b5a1c62eb0 🔍 |
| SHA256 | eff4703a71c42bec1166e540aea9eeaf3dc7dfcc453fedcb79c0f3b80807869d 🔍 |
| SHA3 | 49e8911817751e080cd111e901f0b293312d2a23414d14675bba314e63b26a25 🔍 |
| SSDeep | 192:SE3WOhWST71ojDBQABJrbA0nqnajLQvTP+8jIrJT:SMWOhWDDBRJf3nlvQyUIrJT 🔍 |
| Imports Hash | d41d8cd98f00b204e9800998ecf8427e 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xd0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 2 |
| TimeDateStamp | 2015-Jun-03 09:33:02 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 12.0 |
| SizeOfCode | 0 |
| SizeOfInitializedData | 0x800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000000000 (Section: ?) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | A.0 |
| ImageVersion | A.0 |
| SubsystemVersion | A.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x3000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xb065 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x40000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 88e0ee88b4c16c63fa570deb280995d2 🔍 |
|---|---|
| SHA1 | def74a9124550f619c8c6b0d743fbabd0301a8d8 🔍 |
| SHA256 | 0c3c6c2bd50b9314212c036a35ef439df10ebddeda825479fb6b08566bdcd687 🔍 |
| SHA3 | ef8ce6aebc45d7ee83ce3f81f379e460d36718b21ea44cb7c8c798b9e100b871 🔍 |
| VirtualSize | 0x25c |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.15932 |
| MD5 | 091a5f66cf45d4f432edc64aec1818de 🔍 |
|---|---|
| SHA1 | 7e8fa1ec2663ae25fddab1a1e6fe3c6d7790272a 🔍 |
| SHA256 | 4cba84c7ed3053d62d56e8e4b75481aa327b60e36e39cbce5c31c7651fed67fc 🔍 |
| SHA3 | e9ceeeee9278c6e147b152faf4d1301697ff353857fcf27719d1b203aab60727 🔍 |
| VirtualSize | 0x3d8 |
| VirtualAddress | 0x2000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 3.23762 |
| Ordinal | 1 |
|---|---|
| Address | 0x10dc |
| ForwardName | kernel32.CreateFile2 |
| Ordinal | 2 |
|---|---|
| Address | 0x10fe |
| ForwardName | kernel32.GetTempPathW |
| Ordinal | 3 |
|---|---|
| Address | 0x1136 |
| ForwardName | kernel32.GetVolumeNameForVolumeMountPointW |
| Ordinal | 4 |
|---|---|
| Address | 0x1182 |
| ForwardName | kernel32.GetVolumePathNamesForVolumeNameW |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x374 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.49407 |
| MD5 | 2aa1fb0af36d5d76f32ba97ac33f338f 🔍 |
| SHA1 | 44ab2f96b1bbd95c21eb98cf4b1bd5e1e38dc725 🔍 |
| SHA256 | 605fa9b4d3bcf72e74847c2b74496d2bb28a4400aacc8ff20406792224ed5e9b 🔍 |
| SHA3 | f8c5073bba3dce0db686646ae0c38d79a3e9d2c2420581ac6556cd74e8494616 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.10137.0 |
| ProductVersion | 10.0.10137.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | ApiSet Stub DLL |
| FileVersion (#2) | 10.0.10137.0 (th1.150602-2238) |
| InternalName | apisetstub |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | apisetstub |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 10.0.10137.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2015-Jun-03 09:33:02 |
| Version | 0.0 |
| SizeofData | 56 |
| AddressOfRawData | 0x11ac |
| PointerToRawData | 0x5ac |
| Referenced File | api-ms-win-core-file-l1-2-0.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2015-Jun-03 09:33:02 |
| Version | 0.0 |
| SizeofData | 100 |
| AddressOfRawData | 0x11f8 |
| PointerToRawData | 0x5f8 |
| XOR Key | 0x91b35329 |
|---|---|
| Unmarked objects | 0 |
| 238 (40116) | 1 |
| 242 (40116) | 2 |
| Imports (40116) | 1 |
| 240 (40116) | 1 |
No comments yet.