| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2003-Feb-28 17:19:31 |
| Detected languages |
English - United States
|
| Debug artifacts |
adammigrate.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Active Directory Lightweight Directory Services migration plugin |
| FileVersion | 10.0.19041.1 (WinBuild.160101.0800) |
| InternalName | adammigrate.dll |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | adammigrate.dll |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 10.0.19041.1 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/68 (Scanned on 2026-02-09 17:15:53) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2003-Feb-28 17:19:31 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_NET_RUN_FROM_SWAP
IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x11000 |
| SizeOfInitializedData | 0xd600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000000F260 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | A.0 |
| ImageVersion | A.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x22000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1ed67 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x40000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| msvcrt.dll |
_XcptFilter
_amsg_exit _initterm _CxxThrowException _lock _unlock __dllonexit _onexit ??1type_info@@UEAA@XZ _errno realloc __CxxFrameHandler3 ??0exception@@QEAA@AEBQEBDH@Z _callnewh wcscspn _purecall ?what@exception@@UEBAPEBDXZ _local_unwind ?terminate@@YAXXZ memcmp _wcsicmp ??0exception@@QEAA@XZ memmove_s ??0exception@@QEAA@AEBV0@@Z ??1exception@@UEAA@XZ ??0exception@@QEAA@AEBQEBD@Z wcscat_s wcscpy_s memcpy_s free malloc wcsncpy_s __C_specific_handler memcpy memset |
|---|---|
| KERNEL32.dll |
OutputDebugStringA
GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive TerminateProcess GetCurrentProcess SetUnhandledExceptionFilter UnhandledExceptionFilter RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext LocalFree FreeLibrary GetLastError GetProcAddress LoadLibraryExW GetModuleHandleW lstrcmpiW RaiseException MultiByteToWideChar SizeofResource LoadResource FindResourceExW GetModuleFileNameW GetThreadLocale SetThreadLocale DeleteCriticalSection InitializeCriticalSection EnterCriticalSection LeaveCriticalSection LockResource GetComputerNameW GetTickCount Sleep HeapAlloc GetProcessHeap HeapFree ExpandEnvironmentStringsW HeapSize HeapReAlloc HeapDestroy lstrlenA |
| ole32.dll |
StringFromGUID2
CoTaskMemAlloc CoTaskMemRealloc CoTaskMemFree CoCreateInstance StringFromCLSID |
| OLEAUT32.dll |
GetErrorInfo
VariantClear LoadRegTypeLib SysAllocStringLen SysStringLen LoadTypeLib SysAllocString VarUI4FromStr SysFreeString SysAllocStringByteLen |
| USER32.dll |
UnregisterClassA
CharNextW |
| ADVAPI32.dll |
EnumDependentServicesW
QueryServiceStatus QueryServiceConfigW CloseServiceHandle StartServiceW OpenServiceW OpenSCManagerW RegDeleteValueW RegCreateKeyExW RegSetValueExW RegOpenKeyExW RegEnumKeyExW RegQueryInfoKeyW RegCloseKey ControlService RegQueryValueExW |
| SHELL32.dll |
SHGetFileInfoW
|
| Ordinal | 1 |
|---|---|
| Address | 0x17e0 |
| Ordinal | 2 |
|---|---|
| Address | 0x1450 |
| Ordinal | 3 |
|---|---|
| Address | 0x1820 |
| Ordinal | 4 |
|---|---|
| Address | 0x15b0 |
| Ordinal | 5 |
|---|---|
| Address | 0x16d0 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.19041.1 |
| ProductVersion | 10.0.19041.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Active Directory Lightweight Directory Services migration plugin |
| FileVersion (#2) | 10.0.19041.1 (WinBuild.160101.0800) |
| InternalName | adammigrate.dll |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | adammigrate.dll |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 10.0.19041.1 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2003-Feb-28 17:19:31 |
| Version | 0.0 |
| SizeofData | 40 |
| AddressOfRawData | 0x179b4 |
| PointerToRawData | 0x16db4 |
| Referenced File | adammigrate.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2003-Feb-28 17:19:31 |
| Version | 0.0 |
| SizeofData | 812 |
| AddressOfRawData | 0x179dc |
| PointerToRawData | 0x16ddc |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2003-Feb-28 17:19:31 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x17d08 |
| PointerToRawData | 0x17108 |
| StartAddressOfRawData | 0x180017d2c |
|---|---|
| EndAddressOfRawData | 0x180017d34 |
| AddressOfIndex | 0x18001e590 |
| AddressOfCallbacks | 0x180012d98 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x118 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x18001dd68 |
| GuardCFCheckFunctionPointer | 6442527968 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0xc27ea1d5 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (27412) | 3 |
| C objects (27412) | 17 |
| Total imports | 138 |
| Imports (27412) | 15 |
| Exports (27412) | 1 |
| C objects (LTCG) (27412) | 12 |
| C++ objects (27412) | 10 |
| Resource objects (27412) | 1 |
| Linker (27412) | 1 |