0505c43da0a303f6c5a4b0f48727744a7f55d8ab88adf54c7350d6ef75cfe0f6

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2068-Jan-02 13:42:11
Detected languages English - United States
Debug artifacts appidsvc.pdb
CompanyName Microsoft Corporation
FileDescription Application Identity Service
FileVersion 10.0.26100.8457 (WinBuild.160101.0800)
InternalName appidsvc.dll
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename appidsvc.dll
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.26100.8457

Plugin Output

Suspicious The PE is possibly packed. Unusual section name found: fothk
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • GetProcAddress
Can access the registry:
  • RegQueryInfoKeyW
  • RegSetValueExW
  • RegDeleteKeyExW
  • RegCreateKeyExW
  • RegOpenKeyExW
  • RegGetValueW
  • RegCloseKey
  • RegSetKeyValueW
Uses Windows's Native API:
  • NtQueryLicenseValue
  • NtOpenKey
  • NtCreateKey
  • NtQueryValueKey
  • NtClose
  • NtQueryKey
  • NtCreateTransaction
  • NtCommitTransaction
  • NtQueryInformationFile
  • NtCreateFile
  • NtSetValueKey
  • NtSetSystemInformation
  • NtSetInformationProcess
  • NtQuerySystemTime
Interacts with services:
  • OpenServiceW
  • OpenSCManagerW
Safe VirusTotal score: 0/71 (Scanned on 2026-09-21 17:29:00) All the AVs think this file is safe.

Hashes

MD5 56a740d8a803c27b7a8cc1afc32deb68 🔍
SHA1 4cdc717a7def31ff6836ac5e87df74b28c6869b5 🔍
SHA256 0505c43da0a303f6c5a4b0f48727744a7f55d8ab88adf54c7350d6ef75cfe0f6 🔍
SHA3 5c45c56e4e0e0be9e53d4f109f86cd7a08630a105ebfde092a27b3094d6c6c9b 🔍
SSDeep 1536:9eQQVo3CuC8baaG+CZuoGq8q8sd/Rd2Mur/++80DM/qNZnI/S/2/fTuO:94otC8eaG+ytQsd6G+80g/Wma/2/r9 🔍
Imports Hash 2569be212de5ace3149c22ae58d221ee 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 8
TimeDateStamp 2068-Jan-02 13:42:11
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xe000
SizeOfInitializedData 0xe000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001610 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion A.0
ImageVersion A.0
SubsystemVersion A.0
Win32VersionValue 0
SizeOfImage 0x1d000
SizeOfHeaders 0x1000
Checksum 0x29ff5
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x40000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 52c7258bd80fe2a8edea43fbaebd7abd 🔍
SHA1 ff83ccc37e9389f28fc43a6503bf94ba2cd6b648 🔍
SHA256 8ec170e66ae2cc3f85b5c296e91f14e844d9f93e8c9ed9dffde87171e36123ee 🔍
SHA3 b46aa6b2d072506ad1d4df3f20e521a41059f8150480b80323dbaa60e5aa040e 🔍
VirtualSize 0xc900
VirtualAddress 0x1000
SizeOfRawData 0xd000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.96832

fothk

MD5 6a2c51bde0398e9789234c4bfc7587bb 🔍
SHA1 9c9bcfc1c31871d38c8140caf438440709c5b1f5 🔍
SHA256 64b48a7eddd4afd369ba2e5b41a4f98f1d65ed9a6e8bae730984af6e94bbd368 🔍
SHA3 29979267386996f03494e049b3008b1d8e593924e782b42b7a1046df8e1715e8 🔍
VirtualSize 0x1000
VirtualAddress 0xe000
SizeOfRawData 0x1000
PointerToRawData 0xe000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 0.0159202

.rdata

MD5 ede5916539421feab295063e3b10d2a7 🔍
SHA1 eb55536d8885c8eeb2e5541a2b202db1abd8ec10 🔍
SHA256 98c1eec53f6fb3c687d9f2910518d4460f085fd6ee447f5cc305e508a1e7cf53 🔍
SHA3 cea17a56e45cde42860e99aba4b6eee8af1a23b36587a00001c039843ac28493 🔍
VirtualSize 0x82bc
VirtualAddress 0xf000
SizeOfRawData 0x9000
PointerToRawData 0xf000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.27018

.data

MD5 6d89bf1507cc5bb719c99c3f1ca706d5 🔍
SHA1 10736342f8e0176c1924c68e3687769cfb2c3fb6 🔍
SHA256 2a7b21fbfd21c164cb99f24caa50035b6452693d2ae8646045bb174aab1179f6 🔍
SHA3 08999306d5ad5d531cf744809266052e26062d9dcd2d0e9aed0bf697e0410429 🔍
VirtualSize 0xa60
VirtualAddress 0x18000
SizeOfRawData 0x1000
PointerToRawData 0x18000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.452364

.pdata

MD5 0b6b4bcadd5bed14bc2bd8d0d5e391ff 🔍
SHA1 c8a0f9bb9030f658b76c75038784ebd04ae70e89 🔍
SHA256 23cab07b88147bee7212afc048baf53953322264cfc74669fe45f0f895d6495f 🔍
SHA3 9db2115563ab2eb5967822fbd62a37511c5328cfda63534dc8ac45c2fea7bdaf 🔍
VirtualSize 0x8dc
VirtualAddress 0x19000
SizeOfRawData 0x1000
PointerToRawData 0x19000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.08944

.didat

MD5 bdac4152de3e054061373032863adcd1 🔍
SHA1 f7fbac53d18c77fa8f7d755dfcb800ac1c355844 🔍
SHA256 08600930bc790d647cf5c857b19706549c739d18592885a7afd2fcdcc5003c6b 🔍
SHA3 22b5cfa46733f675e19be79c4290233a13dadfc2f0b76ac21168da39a4de2481 🔍
VirtualSize 0x1b8
VirtualAddress 0x1a000
SizeOfRawData 0x1000
PointerToRawData 0x1a000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.388215

.rsrc

MD5 b35c1f73808e5c4278f5a0d3e10954b5 🔍
SHA1 d86bea82998024e55ee60f0f393d8ae50d0db063 🔍
SHA256 a088202a3b194702b0901af2134d065270a4e5611a3f5df25c19019bbbbf89b5 🔍
SHA3 46bc7f28d7286a411d6e0bd5289f821f69cdc74d6b6fcb22924e605524710596 🔍
VirtualSize 0x528
VirtualAddress 0x1b000
SizeOfRawData 0x1000
PointerToRawData 0x1b000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.33473

.reloc

MD5 45628d004ef0a8943b311d372a840c41 🔍
SHA1 77a7f8055abfbf66f6fad9b52759b5f661cdbfa7 🔍
SHA256 523e2ce3e5ae47853825e8460e0b10e234711ea462ffe409eb039ec4cb619a02 🔍
SHA3 759ebdf941a84f50b1509a57ca411f33f59dd6396a2c2fd3cb8caa568eb5312e 🔍
VirtualSize 0x438
VirtualAddress 0x1c000
SizeOfRawData 0x1000
PointerToRawData 0x1c000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 2.0607

Imports

msvcrt.dll __C_specific_handler
free
_amsg_exit
_XcptFilter
??0exception@@QEAA@AEBQEBD@Z
memmove
??1type_info@@UEAA@XZ
_CxxThrowException
_callnewh
malloc
_purecall
_lock
_initterm
_unlock
?what@exception@@UEBAPEBDXZ
_vsnwprintf
__dllonexit
??0exception@@QEAA@AEBV0@@Z
_onexit
memset
??0exception@@QEAA@AEBQEBDH@Z
__CxxFrameHandler4
??3@YAXPEAX@Z
??1exception@@UEAA@XZ
memcpy
strcmp
api-ms-win-core-errorhandling-l1-1-0.dll RaiseException
SetUnhandledExceptionFilter
GetLastError
UnhandledExceptionFilter
api-ms-win-core-synch-l1-1-0.dll AcquireSRWLockExclusive
ReleaseSRWLockExclusive
SetEvent
CreateEventW
api-ms-win-core-threadpool-l1-2-0.dll CloseThreadpoolCleanupGroup
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolCleanupGroupMembers
WaitForThreadpoolTimerCallbacks
CreateThreadpoolCleanupGroup
CloseThreadpoolWork
CreateThreadpoolWait
SetThreadpoolWait
CreateThreadpoolTimer
SetThreadpoolTimer
CloseThreadpoolWait
WaitForThreadpoolWaitCallbacks
CloseThreadpoolTimer
api-ms-win-core-file-l1-1-0.dll GetFinalPathNameByHandleW
CompareFileTime
CreateFileW
api-ms-win-core-io-l1-1-0.dll DeviceIoControl
api-ms-win-core-registry-l1-1-0.dll RegQueryInfoKeyW
RegSetValueExW
RegDeleteKeyExW
RegCreateKeyExW
RegOpenKeyExW
RegGetValueW
RegCloseKey
api-ms-win-core-registry-l1-1-1.dll RegSetKeyValueW
api-ms-win-eventing-provider-l1-1-0.dll EventRegister
EventUnregister
EventActivityIdControl
EventSetInformation
EventWriteTransfer
api-ms-win-core-handle-l1-1-0.dll CloseHandle
api-ms-win-core-com-l1-1-0.dll CoSetProxyBlanket
CoCreateInstance
CoInitializeEx
CoUninitialize
StringFromGUID2
OLEAUT32.dll VariantInit
RPCRT4.dll RpcImpersonateClient
RpcRevertToSelf
RpcServerInqCallAttributesW
RpcEpRegisterW
RpcEpUnregister
RpcServerTestCancel
RpcBindingVectorFree
I_RpcMapWin32Status
NdrAsyncServerCall
RpcAsyncAbortCall
RpcServerInqBindings
RpcServerUnregisterIf
RpcServerRegisterIf3
RpcAsyncCompleteCall
Ndr64AsyncServerCallAll
RpcServerUseProtseqW
api-ms-win-core-localization-l1-2-0.dll FormatMessageW
api-ms-win-core-processthreads-l1-1-0.dll GetCurrentThread
GetCurrentProcess
GetCurrentThreadId
TerminateProcess
OpenThreadToken
GetCurrentProcessId
SetThreadToken
api-ms-win-core-heap-l1-1-0.dll GetProcessHeap
HeapAlloc
HeapFree
api-ms-win-core-libraryloader-l1-2-0.dll GetModuleHandleW
LoadLibraryExA
GetProcAddress
FreeLibrary
api-ms-win-core-heap-l2-1-0.dll LocalAlloc
LocalFree
api-ms-win-core-winrt-l1-1-0.dll RoActivateInstance
RoGetActivationFactory
api-ms-win-core-winrt-string-l1-1-0.dll WindowsDeleteString
WindowsCreateStringReference
api-ms-win-security-base-l1-1-0.dll RevertToSelf
GetSecurityDescriptorDacl
api-ms-win-core-synch-l1-2-0.dll Sleep
api-ms-win-core-rtlsupport-l1-1-0.dll RtlCaptureContext
RtlVirtualUnwind
RtlLookupFunctionEntry
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceCounter
api-ms-win-core-sysinfo-l1-1-0.dll GetTickCount
GetSystemTimeAsFileTime
GetSystemInfo
api-ms-win-core-threadpool-legacy-l1-1-0.dll UnregisterWaitEx
ntdll.dll RtlUpcaseUnicodeString
RtlAcquireSRWLockExclusive
RtlAcquireSRWLockShared
RtlRunOnceExecuteOnce
RtlReleaseSRWLockExclusive
RtlReleaseSRWLockShared
RtlAllocateHeap
RtlFreeHeap
NtQueryLicenseValue
EtwEventWriteTransfer
NtOpenKey
NtCreateKey
NtQueryValueKey
NtClose
RtlInitUnicodeString
NtQueryKey
NtCreateTransaction
NtCommitTransaction
NtQueryInformationFile
NtCreateFile
NtSetValueKey
EtwEventUnregister
NtSetSystemInformation
RtlNtStatusToDosErrorNoTeb
EtwEventRegister
NtSetInformationProcess
EtwUnregisterTraceGuids
EtwRegisterTraceGuidsW
EtwGetTraceEnableFlags
EtwGetTraceEnableLevel
EtwGetTraceLoggerHandle
EtwTraceMessage
NtQuerySystemTime
api-ms-win-core-memory-l1-1-0.dll VirtualQuery
VirtualProtect
api-ms-win-service-management-l1-1-0.dll (delay-loaded) CloseServiceHandle
OpenServiceW
StartServiceW
OpenSCManagerW

Delayed Imports

Attributes 0x1
Name api-ms-win-service-management-l1-1-0.dll
ModuleHandle 0x18770
DelayImportAddressTable 0x1a160
DelayImportNameTable 0x15118
BoundDelayImportTable 0x155b8
UnloadDelayImportTable 0x15a08
TimeStamp 1970-Jan-01 00:00:00

ServiceMain

Ordinal 1
Address 0x3e70

SvchostPushServiceGlobals

Ordinal 2
Address 0x4b70

1

Type MUI
Language English - United States
Codepage UNKNOWN
Size 0xc8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.68306
MD5 bc287f87c8d65d1d7e1175294810b1d3 🔍
SHA1 2b6cae4d8dff7e3a08006e59ca4d296e2d48062c 🔍
SHA256 e954bc08795f72b93b3622ecb29fa31201ee2703885081728e1aedccf1c9bcef 🔍
SHA3 1aa0cc489bd8ca99169faa8f7d215ae01caab1ab742e24b1e0cc8a7eb52bb665 🔍

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x3b0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.50529
MD5 50c203bf198e86439f182d9844ccbfcc 🔍
SHA1 ee634fd8e1ac24e2877beb096bbaedd59951aac0 🔍
SHA256 2a7be205a89d6d5cb058c6f3f8dd9373df7de5bea177fb99994b3aed0ba8214b 🔍
SHA3 c189f4b01d2f6c529328890cd43771b85a82d4a11c82460ffbc01b197ae4e8ab 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 10.0.26100.8457
ProductVersion 10.0.26100.8457
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
CompanyName Microsoft Corporation
FileDescription Application Identity Service
FileVersion (#2) 10.0.26100.8457 (WinBuild.160101.0800)
InternalName appidsvc.dll
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename appidsvc.dll
ProductName Microsoft® Windows® Operating System
ProductVersion (#2) 10.0.26100.8457
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2068-Jan-02 13:42:11
Version 0.0
SizeofData 37
AddressOfRawData 0x13a50
PointerToRawData 0x13a50
Referenced File appidsvc.pdb

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2068-Jan-02 13:42:11
Version 0.0
SizeofData 920
AddressOfRawData 0x13a78
PointerToRawData 0x13a78

UNKNOWN

Characteristics 0
TimeDateStamp 2068-Jan-02 13:42:11
Version 0.0
SizeofData 36
AddressOfRawData 0x13e38
PointerToRawData 0x13e38

UNKNOWN (#2)

Characteristics 0
TimeDateStamp 2068-Jan-02 13:42:11
Version 0.0
SizeofData 4
AddressOfRawData 0x13e5c
PointerToRawData 0x13e5c

TLS Callbacks

Load Configuration

Size 0x148
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x180018180
GuardCFCheckFunctionPointer 6442519944
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0xe4f0716b
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 58
Unmarked objects (#2) 1
ASM objects (33145) 5
C objects (33145) 16
Total imports 251
Imports (33145) 5
C++ objects (33145) 6
Exports (33145) 1
C objects (LTCG) (33145) 21
Resource objects (33145) 1
Linker (33145) 1

Errors

Leave a comment

No comments yet.