03960c4e54a72bd83d9e52603eaf6e1d

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2016-Nov-08 22:26:41
Detected languages English - United States
Debug artifacts D:\DOTNET-CLI-W002\_work\4\s\artifacts\win10-x86\corehost\cmake\cli\exe\RelWithDebInfo\dotnet.pdb
CompanyName Microsoft Corporation
FileDescription dotnet
FileVersion 1,1,001179,00,1.1.0, 928f77c4bc3f49d892459992fb6e1d5542cb5e86 built by: DOTNET-CLI-W002, UTC: 11/8/2016 10:26:21 PM
InternalName dotnet
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename dotnet
ProductName Microsoft® .NET Core Framework
ProductVersion 1.1.0, 928f77c4bc3f49d892459992fb6e1d5542cb5e86 built by: DOTNET-CLI-W002, UTC: 11/8/2016 10:26:21 PM

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • go.microsoft.com
  • http://go.microsoft.com
  • http://go.microsoft.com/fwlink/?LinkID
  • microsoft.com
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Safe VirusTotal score: 0/68 (Scanned on 2019-11-14 04:03:04) All the AVs think this file is safe.

Hashes

MD5 03960c4e54a72bd83d9e52603eaf6e1d
SHA1 89f89a85a891e2d24ea2983f7886e16668c9d6ee
SHA256 34c2b401e1651494078b2be9a8d56c1f70667c303af8d24b56b114e7c0dbf708
SHA3 daa25f8cf32883b8ba66ff8ce320e2809cd9fed851b60db2b4ae45913288e2bf
SSDeep 1536:SF0GCsvwBV91cHbmNQbG80eYsis8jsddBICg2cAtN7ON:SF0GC+wBVXwbmNVPeXLg2cAfi
Imports Hash 35e9c2adf50cf14df4005a438507a9d3

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 7
TimeDateStamp 2016-Nov-08 22:26:41
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0xe800
SizeOfInitializedData 0xa400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000B581 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x10000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1e000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x180000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0a756243063dc6fb904c3bc7f5640daa
SHA1 ce0f7a28f6e02bd64dc0c191511af04980970fc3
SHA256 ed230ece52ec69ddef8ed8387d600915391bd5b6d4ae0c7aa1848a4322c5b4e1
SHA3 5f2d62011512e316659d0733f8b5b29b6039c6d93c0283735e0c9b37ee83c699
VirtualSize 0xe653
VirtualAddress 0x1000
SizeOfRawData 0xe800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46522

.rdata

MD5 e8cd47bae0b2e0b01a3f12bebea05023
SHA1 7c6299432b24b1d44813864372e5412629dd7f36
SHA256 672a89007ad07df1f212d24fafa8440de38b24849da2dce9bd1b4a569736d95e
SHA3 ab38b4744d1382852e9563d2b2cd86d8a1aa207be2f190c0206434f2ae26c851
VirtualSize 0x71c4
VirtualAddress 0x10000
SizeOfRawData 0x7200
PointerToRawData 0xec00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.57386

.data

MD5 71e13dc48e15d0a82a37715592bf5dc2
SHA1 5a29ffd578623e03799ca9e00a3127e22a5d8b24
SHA256 63e578c7a9ca5031820d186471d495188a25696adadbf6fcad89a048cfc2d307
SHA3 8b659cde80ba86e450cdfd88ec64228390fbb992761e8a8054f9b0598b99adf9
VirtualSize 0xdb4
VirtualAddress 0x18000
SizeOfRawData 0x800
PointerToRawData 0x15e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.0937

.gfids

MD5 44a1ee3c2d91bbaf396a214b9664a186
SHA1 8022975e8b98087b93a72f946ed7c4bd50ccfc49
SHA256 c1fd882c5490e4213ba2ff18573799059a971745be0bf1f52287f56f9cb624af
SHA3 f18366e6c7051b2c31464a0b3ca2aa0af291473f6aef080bc7876738ee7b79ce
VirtualSize 0x288
VirtualAddress 0x19000
SizeOfRawData 0x400
PointerToRawData 0x16600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.2389

.tls

MD5 1f354d76203061bfdd5a53dae48d5435
SHA1 aa0d33a0c854e073439067876e932688b65cb6a9
SHA256 4c6474903705cb450bb6434c29e8854f17d8324efca1fdb9ee9008599060883a
SHA3 991fbbd46bbd69198269fe6c247d440e0f8a7d38259b7a1e04b74790301d1d2b
VirtualSize 0x9
VirtualAddress 0x1a000
SizeOfRawData 0x200
PointerToRawData 0x16a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.0203931

.rsrc

MD5 7e628f069c13ebb5dae75865ad8d70f4
SHA1 080a54680af063a6d2ad3c205c3f2ab264fcf8f2
SHA256 a5ec136757e2fdb96d0586a5768a252f8eb76380874fe8fb5cb0470a4a49faf7
SHA3 d3692e431cd0e3dd7c4408ff748d8a5b54d0572c68457c59074726a25f14919c
VirtualSize 0x6c8
VirtualAddress 0x1b000
SizeOfRawData 0x800
PointerToRawData 0x16c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.7118

.reloc

MD5 201057b462831088a293c26c22b3973a
SHA1 cd4124864a6fffb16e8c3d786577e9ff11cfd144
SHA256 70989f17e438b73ba58381bb1a05233bc01d26b06da6fc8b32d6e856c51a2701
SHA3 5e1b38912b80611ae7953ef3c9e2701f3e8853ca334f84a6bdee79d35d895fd6
VirtualSize 0x148c
VirtualAddress 0x1c000
SizeOfRawData 0x1600
PointerToRawData 0x17400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.34454

Imports

KERNEL32.dll FindClose
FindFirstFileW
FindFirstFileExW
FindNextFileW
GetFullPathNameW
CloseHandle
GetModuleFileNameW
GetModuleHandleExW
GetProcAddress
LoadLibraryExW
MultiByteToWideChar
WideCharToMultiByte
GetLastError
GetEnvironmentVariableW
FreeLibrary
RtlUnwind
RaiseException
InitializeSListHead
GetCurrentThreadId
GetCurrentProcessId
QueryPerformanceCounter
TerminateProcess
GetCurrentProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
IsDebuggerPresent
IsProcessorFeaturePresent
WaitForSingleObjectEx
ResetEvent
SetEvent
LCMapStringW
GetModuleHandleW
GetStringTypeW
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
EncodePointer
DecodePointer
SetLastError
InitializeCriticalSectionAndSpinCount
CreateEventW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
api-ms-win-crt-runtime-l1-1-0.dll _c_exit
_invalid_parameter_noinfo_noreturn
_errno
__p___wargv
__p___argc
_exit
exit
_initterm_e
abort
_initterm
_get_initial_wide_environment
_initialize_wide_environment
_configure_wide_argv
_set_app_type
_seh_filter_exe
_cexit
_controlfp_s
terminate
_crt_atexit
_register_onexit_function
_register_thread_local_exe_atexit_callback
_initialize_onexit_table
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
frexp
api-ms-win-crt-heap-l1-1-0.dll _callnewh
malloc
calloc
_calloc_base
free
_free_base
_set_new_mode
api-ms-win-crt-convert-l1-1-0.dll wcstoul
_wtoi
api-ms-win-crt-stdio-l1-1-0.dll __stdio_common_vfwprintf
__stdio_common_vsprintf_s
__acrt_iob_func
fputws
__p__commode
_set_fmode
api-ms-win-crt-string-l1-1-0.dll strcpy_s
_wcsdup
memset
wcsnlen
strcspn
api-ms-win-crt-locale-l1-1-0.dll ___lc_codepage_func
setlocale
_configthreadlocale
__pctype_func
_unlock_locales
localeconv
___mb_cur_max_func
_lock_locales
___lc_locale_name_func
ADVAPI32.dll SystemFunction036
api-ms-win-crt-multibyte-l1-1-0.dll _ismbblead

Delayed Imports

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x4a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.62726
MD5 6b9471003007c65027ef3e6ee80625b8
SHA1 aea6c3062ad2a2343576068b258aaaeeb6871838
SHA256 42f8e66252b60968f94861bdbe75a9e34acc53fe7ef1350676500f2b80e9f222
SHA3 c170753213353350c23563da0e532f358981504e1b25a9f0279e15c8cfc49047

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.1.0.1179
ProductVersion 1.1.0.1179
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
CompanyName Microsoft Corporation
FileDescription dotnet
FileVersion (#2) 1,1,001179,00,1.1.0, 928f77c4bc3f49d892459992fb6e1d5542cb5e86 built by: DOTNET-CLI-W002, UTC: 11/8/2016 10:26:21 PM
InternalName dotnet
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename dotnet
ProductName Microsoft® .NET Core Framework
ProductVersion (#2) 1.1.0, 928f77c4bc3f49d892459992fb6e1d5542cb5e86 built by: DOTNET-CLI-W002, UTC: 11/8/2016 10:26:21 PM
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2016-Nov-08 22:26:41
Version 0.0
SizeofData 122
AddressOfRawData 0x152ec
PointerToRawData 0x13eec
Referenced File D:\DOTNET-CLI-W002\_work\4\s\artifacts\win10-x86\corehost\cmake\cli\exe\RelWithDebInfo\dotnet.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2016-Nov-08 22:26:41
Version 0.0
SizeofData 20
AddressOfRawData 0x15368
PointerToRawData 0x13f68

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2016-Nov-08 22:26:41
Version 0.0
SizeofData 992
AddressOfRawData 0x1537c
PointerToRawData 0x13f7c

TLS Callbacks

StartAddressOfRawData 0x41a000
EndAddressOfRawData 0x41a008
AddressOfIndex 0x4189ac
AddressOfCallbacks 0x4101fc
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x5c
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x418070
SEHandlerTable 0x415160
SEHandlerCount 53

RICH Header

XOR Key 0x8dc53327
Unmarked objects 0
ASM objects (23907) 13
C++ objects (23907) 59
C objects (23907) 33
Imports (VS2008 SP1 build 30729) 18
244 (40116) 1
239 (40116) 7
Total imports 147
C++ objects (VS2015 UPD2 build 23918) 5
Resource objects (VS2015 UPD2 build 23918) 1
151 1
Linker (VS2015 UPD2 build 23918) 1

Errors