14f19abb03285556b2b8c6e3565cecf9

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2096-Jun-06 09:56:17
Detected languages English - United States
Debug artifacts hmmapi.pdb
CompanyName Microsoft Corporation
FileDescription Microsoft HTTP Mail Simple MAPI
FileVersion 11.00.15063.0 (WinBuild.160101.0800)
InternalName HMMAPI
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename HMMAPI.DLL
ProductName Internet Explorer
ProductVersion 11.00.15063.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • rundll32.exe
May have dropper capabilities:
  • %ALLUSERSPROFILE%
Info The PE contains common functions which appear in legitimate applications. Can access the registry:
  • RegOpenKeyExA
  • RegSetValueExA
  • RegEnumKeyExA
  • RegCreateKeyExA
  • RegQueryValueExA
  • RegCloseKey
  • RegDeleteKeyA
  • SHGetValueA
Possibly launches other programs:
  • ShellExecuteA
Can create temporary files:
  • CreateFileA
  • GetTempPathA
Safe VirusTotal score: 0/67 (Scanned on 2018-08-25 18:21:14) All the AVs think this file is safe.

Hashes

MD5 14f19abb03285556b2b8c6e3565cecf9
SHA1 1817f8d5d3a3a23a39b768caad8b38dd64a0082d
SHA256 d8bf447559de56afc73acb813279b2ae4d0b84210b6a0dbedb19a71e66706bfc
SHA3 157a1419cef624e0a15155129bee45bd6093269724db48af7884e53843ed9832
SSDeep 768:2GBUo7fhz9BF703PVqVKnTCZJMj0O6LvOFKrdjciUw0n:Qq9B98NqVKnT1
Imports Hash b880101c1ed3683d6d5b63727f6e8da5

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2096-Jun-06 09:56:17
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x3400
SizeOfInitializedData 0x9000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00003270 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x5000
ImageBase 0x10000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion A.0
ImageVersion A.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x10000
SizeOfHeaders 0x400
Checksum 0x1bde3
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x40000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 3007b11d2ebc8c62baabe69dd90e47eb
SHA1 2f0e107630007f6f78f0bf5eb8f260752fdc5e82
SHA256 f5c5fe2e9628d92efa4eae0f79e79a075d26ed450862b9ec224f0968b2127878
SHA3 44f31a22b6535a8c3e190579176a206d0573e9ffb51f88ec719dc212dbf434fd
VirtualSize 0x3210
VirtualAddress 0x1000
SizeOfRawData 0x3400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.72807

.data

MD5 c9c704c531342086704b9f61076b6799
SHA1 310c6254c7b4d079628ac2b1aafd08e7cfb2d71e
SHA256 da233890a4e670f2fd7dd2748eabe89d390200cb61c04edae85fa79c0fb7c4d4
SHA3 93165829ecd6ea3bdedae43b9af6a6a6e17aaed7b49840e370985f1868b6061f
VirtualSize 0x354
VirtualAddress 0x5000
SizeOfRawData 0x200
PointerToRawData 0x3800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.249053

.idata

MD5 a653d870251c72200a2299ef16451390
SHA1 e23d4b03bd5172ae4cc7f5258e943c661bd5d631
SHA256 edaac6986048e16df4642664be806c8938bac13ff8cce9c82e0c2e9df983b52c
SHA3 cb739efa9f3551f3b91c811e811539bcaadb2cb0e4201b14a1b516ccc6405a05
VirtualSize 0x9e8
VirtualAddress 0x6000
SizeOfRawData 0xa00
PointerToRawData 0x3a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.67887

.rsrc

MD5 ce98f2b43202b9138ca6dcd8b2968531
SHA1 4e5590eab77126a943e8583405982af4207105a3
SHA256 2ed91ea28310b97e53c886f53a964fb97fd37aae299bebba4cd7dabec76cf04d
SHA3 e600a067c42b0cdea647a2cb713a5e5d9f5fb3f90d7bc798f7c60b0bb4845392
VirtualSize 0x7c68
VirtualAddress 0x7000
SizeOfRawData 0x7e00
PointerToRawData 0x4400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.19861

.reloc

MD5 2722196a7af1f42f402342369e87533c
SHA1 9c712aad8800893156b71a57ebc2529b55328917
SHA256 fa7d5899e23a30fc4ba044c2334d15bf3adc45ce2dc67188ed2887c7f76e3b50
SHA3 05fdd832c1bb08126ce918285b44334d94ebc624bee7b7d05e43329114f22c5d
VirtualSize 0x2ec
VirtualAddress 0xf000
SizeOfRawData 0x400
PointerToRawData 0xc200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.42293

Imports

msvcrt.dll _vsnprintf
_except_handler4_common
_initterm
malloc
free
_amsg_exit
_XcptFilter
memset
api-ms-win-core-libraryloader-l1-1-1.dll DisableThreadLibraryCalls
GetModuleFileNameA
LoadStringA
api-ms-win-core-registry-l1-1-0.dll RegOpenKeyExA
RegSetValueExA
RegEnumKeyExA
RegCreateKeyExA
RegQueryValueExA
RegCloseKey
api-ms-win-core-heap-l1-2-0.dll GetProcessHeap
HeapFree
HeapAlloc
api-ms-win-core-processenvironment-l1-2-0.dll ExpandEnvironmentStringsA
api-ms-win-core-errorhandling-l1-1-1.dll UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetLastError
api-ms-win-core-file-l1-2-0.dll GetFileSize
CreateFileA
GetFileTime
SetFileAttributesA
api-ms-win-core-sysinfo-l1-2-0.dll GetVersionExA
GetSystemTimeAsFileTime
GetTickCount
api-ms-win-core-handle-l1-1-0.dll CloseHandle
api-ms-win-core-localization-l1-2-0.dll FormatMessageA
api-ms-win-core-synch-l1-2-0.dll Sleep
api-ms-win-core-processthreads-l1-1-1.dll GetCurrentProcess
TerminateProcess
GetCurrentThreadId
GetCurrentProcessId
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceCounter
ADVAPI32.dll RegDeleteKeyA
KERNEL32.dll lstrlenA
MoveFileA
CompareStringA
lstrcmpA
GetTempPathA
GetShortPathNameA
LocalFree
SHELL32.dll ShellExecuteA
SHLWAPI.dll SHGetValueA
PathIsPrefixA
StrChrA
PathRemoveBackslashA
urlmon.dll CreateUriFromMultiByteString
USER32.dll MessageBoxA
WININET.dll GetUrlCacheConfigInfoA

Delayed Imports

MAPIFreeBuffer

Ordinal 16
Address 0x1cc0

DllRegisterServer

Ordinal 17
Address 0x3020

DllUnregisterServer

Ordinal 18
Address 0x3040

MAPISendDocuments

Ordinal 208
Address 0x2420

MAPILogon

Ordinal 209
Address 0x1c90

MAPILogoff

Ordinal 210
Address 0x1cb0

MAPISendMail

Ordinal 211
Address 0x1cd0

MAPISaveMail

Ordinal 212
Address 0x2440

MAPIReadMail

Ordinal 213
Address 0x2440

MAPIFindNext

Ordinal 214
Address 0x2450

MAPIDeleteMail

Ordinal 215
Address 0x2420

MAPIAddress

Ordinal 217
Address 0x2430

MAPIDetails

Ordinal 218
Address 0x2420

MAPIResolveName

Ordinal 219
Address 0x2440

BMAPISendMail

Ordinal 220
Address 0x2450

BMAPISaveMail

Ordinal 221
Address 0x2460

BMAPIReadMail

Ordinal 222
Address 0x2460

BMAPIGetReadMail

Ordinal 223
Address 0x2420

BMAPIFindNext

Ordinal 224
Address 0x2450

BMAPIAddress

Ordinal 225
Address 0x2470

BMAPIGetAddress

Ordinal 226
Address 0x2480

BMAPIDetails

Ordinal 227
Address 0x2420

BMAPIResolveName

Ordinal 228
Address 0x2440

MailToProtocolHandler

Ordinal 300
Address 0x2490

OpenInboxHandler

Ordinal 301
Address 0x2560

AddService

Ordinal 302
Address 0x2f80

RemoveService

Ordinal 303
Address 0x2fe0

1

Type MUI
Language English - United States
Codepage UNKNOWN
Size 0xd8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65994
MD5 b95b6e2e979cb6456a508e890ba2a55f
SHA1 c435a7ff8eca023806196eeac707f782b8e4d323
SHA256 150f76d6838bdab7b5e6a566fb8c6067da152f98c42d186d38db15d91724991f
SHA3 bb0a3455a50ff87632e3513a033bf9feb8b9362b4e818f29cf2283096d7e1bc1

1 (#2)

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.29223
MD5 2fa6546f6c6f3ca98d4b3eb3f88576fb
SHA1 eb6a9362f008154f23424ba9d6714b881d37c2c4
SHA256 30a1f467aaca6ada8454728a9cb2dc7bd5ee96e3f8bc06f8b495ca8681065c5b
SHA3 4d8580d5cdb1cc6d37ddc3af21e09912ea1645eb3411a48b7967c05b13e95f36

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.53592
MD5 9df68c4d07131c7a79ac40d354500085
SHA1 701c9ec2cb85a0101b586f3520c7b237e59008d6
SHA256 aabbf56355d59d7ed3a52fac8aee2a149870c06c42bd3507d41be55fc917500c
SHA3 e1f176e8b067272f9a67c319d79443ed5fb3ebed413dc7e188fdce8468b42085

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.29696
MD5 1fe6e937ca84b145bb067c0507893f97
SHA1 5db83dfff25586d82ac84218d4ab3fa8096a7e65
SHA256 0c1f9b71abf9abe15672e84d6e2ed1ca9d453e8b8438be527df07017663391d8
SHA3 1472bc4aecd660e99e3011f047ff54b3d5f9abc8f197f785931b4414bd317e36

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.40387
MD5 ee45d6ead53b8d103dfd79ff12c62ca7
SHA1 556f93a4e6c82ce4acba10c52cfa2e4b7974f9c2
SHA256 3630b703c4a7f116b4aecf472658f7e88f9de13d493615c423d7dee988790497
SHA3 736713e11d7d78235d54738113009af9e1c36d741fa2d1db1b616865ccb93312

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.87363
MD5 67d86b5cd3308e59836211ced2b2b373
SHA1 4663bc10a663fb3c2d5ee67eba39657b1691bf88
SHA256 f6b17c596f74e6ef324013e66712844582b97dfb0eb14f298c01c2a16bd1a291
SHA3 e65558789e25de61346d8800cf1bf6b2d20b6a92b9a52a99b849d8c0a7803bef

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49773
MD5 7eb0188265552e2a96bbb74e90e5cb07
SHA1 80618e33178569269ea601fc60e5106ed426ff82
SHA256 9199052b290f749d9d5ea125bf9a69bfa2ced3dae95be494197a11a1e7f860d6
SHA3 8f4167da72644728d57c549d44ce9613e5abc1866ef0c8115cb74c39d2666d95

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x6c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38466
MD5 20a22855cb4d558ffb120db08755a10b
SHA1 bdf0d97502cc855e8167901acc9c8bebf151d62f
SHA256 e665042df0f1a6a36c22fd2f5afa871220430c48efd61175b6fa3074ee8c69e8
SHA3 cbb6761ed02771a665229844f5885b1fba80f2f82fe6b209e8bd41b358c8562f

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.31314
MD5 6cc012c164bbd9e2849fcd32599bc136
SHA1 fe2c7aad1f65fb8794cd1ae9154fa8a3e1e56a99
SHA256 0bdf61bfa5018118a305ed4ac9032628e598bcb46b081a879f4e331e991d2f2b
SHA3 4d68ca7d21f89dc27c22fc7cdfa4b932e52089fbc85c4ddb7685d404d6cd37c8

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.88657
MD5 98bdd6cbf20bed271a54bfd20bab18c0
SHA1 1cbf718a474b464ad0f33fe1a9e034bac0bb2fc8
SHA256 ea1aab28fda075805289987c95dc16d3a27d42e4e20a9e09e488048198c99fb5
SHA3 dd51b63ac242b74cec8f8c5cfd64f76ff150dac35ddddfdd487551cf613b185b

10

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.09281
MD5 759088d0048d1e41f1a34aa2a1aefb57
SHA1 dec0e602183678e3f9e460254b93bc6c32e79d4f
SHA256 c2babdee56bad8e9b59cd7eafca2424b17405391f21eeb1c618d8fd0449b825b
SHA3 1e7616402d93ef7e09e5cac4b79172c32b78d74fc2bc186265a16232d9c53faa

11

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.11238
MD5 8575a3e365bb67c70ea79b3c549b5c03
SHA1 878820a777697a6a48fcc1fae73be01213eb7c14
SHA256 bb5e2d74c924e297f258f2f78f5f2b9cb470518e08ea6502e9f020fa577c66cc
SHA3 8eef99f00a785b28bc6e13e039f7e8173adaaad91582d459ba5248c332ec00b5

12

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.69368
MD5 4885e47fa739e583a3a948809826d83b
SHA1 1cfc6e19d5e9e73ca76f574b13cb04622c4f1d67
SHA256 4d9bcae2b20ea71f0ccbb04db9b8bd5ca358631f9fc3aa7322dd9ba1fd114dc2
SHA3 f02135c828d7df28d44997e37c0106f4452077f8fca186cdec45a0cec8e8ea1f

1 (#3)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0xae
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06492
Detected Filetype Icon file
MD5 9f09cf7bb38a28604b82294714b5aff8
SHA1 92235b3d49fd27218a58fbfad27ad6a619b54ffb
SHA256 d2d8ccd68849e94ea6b84f6835d0fe98ffa5c11e74a1138529e3c0b8d8edfe60
SHA3 31d634f42904a006333aee6a5258ab8c02eb1729897f4083ef50dad9565e0da3

1 (#4)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x370
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49095
MD5 709e73f84c739533d91f7b2cd770cf66
SHA1 bc14f07a758e20b3683b87673e9ec68c01c35975
SHA256 5910fc2fac8901a848ff7015b2a1e3d19bf909da5850477a6f6d327e853ac603
SHA3 e2a5a29babc190abca2f4b0ad54044055ea8e134b903401859219d485603fee3

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 11.0.15063.0
ProductVersion 11.0.15063.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
CompanyName Microsoft Corporation
FileDescription Microsoft HTTP Mail Simple MAPI
FileVersion (#2) 11.00.15063.0 (WinBuild.160101.0800)
InternalName HMMAPI
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename HMMAPI.DLL
ProductName Internet Explorer
ProductVersion (#2) 11.00.15063.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2096-Jun-06 09:56:17
Version 0.0
SizeofData 35
AddressOfRawData 0x14c4
PointerToRawData 0x8c4
Referenced File hmmapi.pdb

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2096-Jun-06 09:56:17
Version 0.0
SizeofData 448
AddressOfRawData 0x14e8
PointerToRawData 0x8e8

UNKNOWN

Characteristics 0
TimeDateStamp 2096-Jun-06 09:56:17
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

Load Configuration

Size 0x98
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x10005004
SEHandlerTable 0x100014c0
SEHandlerCount 1
GuardCFCheckFunctionPointer 268460332
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0xa3ba7343
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 24
ASM objects (24610) 2
C objects (24610) 12
Total imports 59
Imports (24610) 17
Exports (24610) 1
265 (24610) 1
Resource objects (24610) 1
Linker (24610) 1

Errors

[*] Warning: 261 invalid export(s) not shown.
<-- -->