351b03cfd4c8a79980783622b28413fbd6bf7d523ce1fe47e15585ef92677b2d

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2024-Jan-19 23:04:32
Debug artifacts D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
CompanyName ERLC
FileDescription ERLC
FileVersion 1.0.0.0
InternalName ERLC.dll
LegalCopyright
OriginalFilename ERLC.dll
ProductName ERLC
ProductVersion 1.0.0+a0a59c28a625e05f86b87118cd3678f957971c31
Assembly Version 1.0.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • go.microsoft.com
  • https://aka.ms
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/?linkid
  • microsoft.com
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryA
Can access the registry:
  • RegOpenKeyExW
  • RegGetValueW
  • RegCloseKey
Possibly launches other programs:
  • ShellExecuteW
Safe VirusTotal score: 0/69 (Scanned on 2026-07-09 18:15:16) All the AVs think this file is safe.

Hashes

MD5 4585bde4555e577e8cdc98bdc07fe72f
SHA1 2441adb433ab176b8184efb8287ca3307b272eaf
SHA256 351b03cfd4c8a79980783622b28413fbd6bf7d523ce1fe47e15585ef92677b2d
SHA3 7a343ccf17aab7e1c04376796bb032d0fe7ac03d5f74af6adf797819f96b8844
SSDeep 3072:Yczkitvo4BpYN/6mBPry8TXROLdW5m4mUR39OOG00kV:YA4NCmBPry/N2jOOZ
Imports Hash 6dbf27f4c70fe2c8ed3e0122ba75d641

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2024-Jan-19 23:04:32
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x18400
SizeOfInitializedData 0xcc00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000013C60 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x2b000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x180000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0a11f732cbe48283e2e6549421819adc
SHA1 c5cb1aefaad6966861c1593b481dc6e8fed82372
SHA256 55b187364a6cf01ac803214aeedb96c9588da715fa3ac29a596b879d29c59774
SHA3 3b9124a69f6481bf950dde188713e6039d1377cfc28db5e279fe76747d3bbeba
VirtualSize 0x1821c
VirtualAddress 0x1000
SizeOfRawData 0x18400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.32025

.rdata

MD5 b15a0704259c42be6da207e64632d182
SHA1 f755526436dce6e7a95ed583766cd326cbcd9e70
SHA256 7fa39a0e03c7c8bbc2eaa5c4b7a59aa53cb5400de008d6ba2083a086ddb27599
SHA3 f05be35cddc5362e6b8b3fcb6b67ac7c322c33f0ab998686efe574f6740f871c
VirtualSize 0x9302
VirtualAddress 0x1a000
SizeOfRawData 0x9400
PointerToRawData 0x18800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.5256

.data

MD5 978408ad1623820b9d3dfe38fd553672
SHA1 b5cde0ffc6eb25828a601dc2e72a46852ac67804
SHA256 6cbd4a42e6e8ef7794fedf3ca9f5fa07fee8387a59c33552c77c65bc560bf32a
SHA3 efaf6dadc0163d5b3dc671e8704a567bc77629364affb38d2704e9fa2196af62
VirtualSize 0x14f8
VirtualAddress 0x24000
SizeOfRawData 0xa00
PointerToRawData 0x21c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.45337

.pdata

MD5 6a2868947463d3292323bc1a5bca8733
SHA1 2338807f0d382e29efb2c3a60f3b13fd29f19fdc
SHA256 872fada299f9a72839e8f338a941422b92108ff391d3e877bd5b91cde2bbc9a0
SHA3 5f1b5d4cbc29dd8f37e3f4caebc05de07a941eebb28c7c59788c02fb4b05b3e1
VirtualSize 0x1440
VirtualAddress 0x26000
SizeOfRawData 0x1600
PointerToRawData 0x22600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.7227

_RDATA

MD5 0a880db69ef3d95f9e9e17c8465b574f
SHA1 8c0233ee3e7781c46c243eb9c9d34d6018a32e5a
SHA256 a2883e2f291e5a0efb77a5a2caf278041459695021b5b35f867fb1a93853f789
SHA3 7d6ead6313f0fe7c807dc795dbebf5e5145023647e5a5a89fd5e79e5e7c6177e
VirtualSize 0xf4
VirtualAddress 0x28000
SizeOfRawData 0x200
PointerToRawData 0x23c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.41185

.reloc

MD5 541be3271e778d705125ef64917f1dc4
SHA1 fa285b25439b88de9d303d95d4cad3cf5e3bb74d
SHA256 d908c0f796c74b16b48dbe64c40d90df7afde69eaa10f3fc72fe5fd0a3eb0b24
SHA3 27e3b8dc62cdbc1f5daa3041d57c6cdd2090aee26d572520c05e12350c3377b7
VirtualSize 0x318
VirtualAddress 0x29000
SizeOfRawData 0x400
PointerToRawData 0x23e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.69305

.rsrc

MD5 42cb14729d9650c9779a4f9795e674ea
SHA1 d721adb3dc29375f2cba81a596b1f261c6ed7e2a
SHA256 9ef8597a746c0ced5af6c315414d0e6e2b333cf8f82d382c7748253daf865844
SHA3 1230de5e396289a41af2cbe702b46e43812d36375d0ba76bb5d50a3e6a11562e
VirtualSize 0x578
VirtualAddress 0x2a000
SizeOfRawData 0x600
PointerToRawData 0x24200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.1234

Imports

KERNEL32.dll FindNextFileW
GetCurrentProcess
GetModuleHandleExW
GetModuleFileNameW
LeaveCriticalSection
InitializeCriticalSection
GetEnvironmentVariableW
FindClose
MultiByteToWideChar
GetLastError
GetFileAttributesExW
GetFullPathNameW
GetProcAddress
DeleteCriticalSection
WideCharToMultiByte
IsWow64Process
LoadLibraryExW
FreeLibrary
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
EnterCriticalSection
FindFirstFileExW
OutputDebugStringW
LoadLibraryA
GetModuleHandleW
InitializeCriticalSectionAndSpinCount
SetLastError
RaiseException
RtlPcToFileHeader
RtlUnwindEx
InitializeSListHead
GetSystemTimeAsFileTime
GetCurrentThreadId
GetCurrentProcessId
QueryPerformanceCounter
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
LCMapStringEx
DecodePointer
EncodePointer
InitializeCriticalSectionEx
GetStringTypeW
USER32.dll MessageBoxW
SHELL32.dll ShellExecuteW
ADVAPI32.dll RegOpenKeyExW
RegGetValueW
DeregisterEventSource
RegisterEventSourceW
ReportEventW
RegCloseKey
api-ms-win-crt-runtime-l1-1-0.dll _exit
__p___argc
_initterm_e
_initterm
_get_initial_wide_environment
_invalid_parameter_noinfo_noreturn
_initialize_wide_environment
_configure_wide_argv
_initialize_onexit_table
_set_app_type
__p___wargv
_seh_filter_exe
_register_onexit_function
_cexit
terminate
_errno
exit
abort
_crt_atexit
_c_exit
_register_thread_local_exe_atexit_callback
api-ms-win-crt-stdio-l1-1-0.dll setvbuf
fflush
_wfopen
__stdio_common_vswprintf
__stdio_common_vfwprintf
_set_fmode
__stdio_common_vsprintf_s
__acrt_iob_func
fputwc
fputws
__p__commode
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
_callnewh
free
malloc
calloc
api-ms-win-crt-string-l1-1-0.dll wcsnlen
strcpy_s
_wcsdup
strcspn
wcsncmp
toupper
api-ms-win-crt-convert-l1-1-0.dll _wtoi
wcstoul
api-ms-win-crt-locale-l1-1-0.dll setlocale
___lc_locale_name_func
localeconv
_unlock_locales
_lock_locales
___mb_cur_max_func
_configthreadlocale
__pctype_func
___lc_codepage_func
api-ms-win-crt-math-l1-1-0.dll frexp
__setusermatherr
api-ms-win-crt-time-l1-1-0.dll _gmtime64_s
_time64
wcsftime

Delayed Imports

1

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2ec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35061
MD5 843e29c6836975011ffffe714fa85a7d
SHA1 ad2e1cae5a7454fdb76e09ca25fc5e769352dac8
SHA256 a7daa77cd4f1168210fa4e2378177d0e69d65b5efa9ba4b62220ea6b427a7d11
SHA3 d1d867442b36d7b4d879276af221d6e51d54b3e3f35a65ba17a821211415867d

1 (#2)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1ea
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.00112
MD5 b7db84991f23a680df8e95af8946f9c9
SHA1 cac699787884fb993ced8d7dc47b7c522c7bc734
SHA256 539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a
SHA3 4f72877413d13a67b52b292a8524e2c43a15253c26aaf6b5d0166a65bc615cff

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName ERLC
FileDescription ERLC
FileVersion (#2) 1.0.0.0
InternalName ERLC.dll
LegalCopyright
OriginalFilename ERLC.dll
ProductName ERLC
ProductVersion (#2) 1.0.0+a0a59c28a625e05f86b87118cd3678f957971c31
Assembly Version 1.0.0.0
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2024-Jan-20 02:38:34
Version 0.0
SizeofData 109
AddressOfRawData 0x1fba0
PointerToRawData 0x1e3a0
Referenced File D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2024-Jan-20 02:38:34
Version 0.0
SizeofData 20
AddressOfRawData 0x1fc10
PointerToRawData 0x1e410

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2024-Jan-20 02:38:34
Version 0.0
SizeofData 944
AddressOfRawData 0x1fc24
PointerToRawData 0x1e424

TLS Callbacks

StartAddressOfRawData 0x14001fff8
EndAddressOfRawData 0x140020008
AddressOfIndex 0x1400254e0
AddressOfCallbacks 0x14001a4d0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140024020
GuardCFCheckFunctionPointer 5368816648
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0x2ef29280
Unmarked objects 0
C objects (30034) 12
ASM objects (30034) 10
C++ objects (30034) 77
Imports (VS2008 SP1 build 30729) 16
Imports (29395) 9
Total imports 162
C++ objects (LTCG) (30153) 10
Linker (30153) 1

Errors

Leave a comment

No comments yet.