64c0a54f9a8233d037e339e973073b61e1ab43c942a994027758f76d42feb591

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2025-Jan-27 10:50:41
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
Debug artifacts D:\git\adp-ipc\bin\x64\Release\AdpIPC.pdb
CompanyName Autodesk, Inc.
FileDescription Autodesk IPC Library
FileVersion 2.0.1.0
InternalName AdpIPC.dll
LegalCopyright © Autodesk, Inc. All rights reserved.
OriginalFilename AdpIPC.dll
ProductName Autodesk IPC Component
ProductVersion 2.0.1.0

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Uses Microsoft's cryptographic API:
  • CryptReleaseContext
  • CryptAcquireContextA
  • CryptGenRandom
Can create temporary files:
  • CreateFileA
  • CreateFileW
  • GetTempPathW
Info The PE is digitally signed. Signer: Autodesk
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe VirusTotal score: 0/73 (Scanned on 2025-03-27 06:16:05) All the AVs think this file is safe.

Hashes

MD5 61523cc2d7d55b0ea7e9da3c572e4447
SHA1 7ec9f7146e43bba9f66afeb43256815f16ed37f9
SHA256 64c0a54f9a8233d037e339e973073b61e1ab43c942a994027758f76d42feb591
SHA3 d7629f2b5867240c1113c5081244aa9b011929c04735388ce1d1bf359f112abf
SSDeep 49152:d+M4sFV03aFWcwRGBkZS6GPFmdle/0aJo2O:M5VxGPIuQp
Imports Hash 1950f8b6852cf872216f671acd73608a

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x128

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2025-Jan-27 10:50:41
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x1b2600
SizeOfInitializedData 0xa4200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000011ED68 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x25b000
SizeOfHeaders 0x400
Checksum 0x25a95e
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 37f186ce98844857f7af2c443e622a75
SHA1 0d68702687218214e2f71fba1f364aced9ee0947
SHA256 0cd758964261b0121f86cab205bcd0b4cc35e64c125d6cd4e69551ec940c735c
SHA3 4482464315323ac70f9e799d1c29b3758ebe3c9aada622fc3a8f5d21ff60f321
VirtualSize 0x1b25ff
VirtualAddress 0x1000
SizeOfRawData 0x1b2600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.40213

.rdata

MD5 5784652f2e3146a08a11925e825666af
SHA1 a08b199e02ce61535cdfb71e60d50b3ba3b641bb
SHA256 61ac14d5c83d951d5abc4766d5169ebab76a01378c8f7e1a7b32327ffae9d416
SHA3 2c29bfc8254030ccad72d338cd0899704251968f63716b80904a182a12cb3664
VirtualSize 0x73fd2
VirtualAddress 0x1b4000
SizeOfRawData 0x74000
PointerToRawData 0x1b2a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.34232

.data

MD5 b49dfe8c15da4d0b67979cdf67d6675e
SHA1 60e29c195bb6c2f7af98ad6ca77b716977c77995
SHA256 2912b44cb69e71195fd3b54776d7e5eb73f74d974a22b5613aaffcf931de401d
SHA3 b56815d136352b53de632a8d1d221a89721ac4078bab63874cf5b833cace4c96
VirtualSize 0x153cc
VirtualAddress 0x228000
SizeOfRawData 0x10600
PointerToRawData 0x226a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.88309

.pdata

MD5 0d79027c94b52c337bb95af4a4ead782
SHA1 100485c81f77dfa0febc8b2422ebfee5779317ab
SHA256 8f51ece4159e4a1547070dbd7e04b9e9a2da8a140a0c50a849e415db9342f25c
SHA3 e04459d403fc53eab8c755bd15c96540fc332179d7635aa1658d473c1aa59324
VirtualSize 0x164a0
VirtualAddress 0x23e000
SizeOfRawData 0x16600
PointerToRawData 0x237000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.26767

_RDATA

MD5 ccfee133203448ac2eae175d0b174aae
SHA1 0418801bfade0ffbb045954a109675f5dce215cd
SHA256 b907bc7c1b6ebb76d60bef7e862d7a8204756e953fefe513fd0f5ef9720aeece
SHA3 2133a9e05d50c9cd90f746776bb8596c3045ddc7d22ee2d5013e829cb9e035dc
VirtualSize 0xf4
VirtualAddress 0x255000
SizeOfRawData 0x200
PointerToRawData 0x24d600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.38166

.rsrc

MD5 b8cc606d2f204cccd7dfea4d5af22cb5
SHA1 f1ed654db05ac0319f11c8fdb7794e96585c6ad7
SHA256 b5ff2586662a7ed98df2bb38519e43cf4ae61f5a14a50182f920c9385965ad7f
SHA3 f0ac607bc76d9904e695f1f0646c7eba71954bc05bcf53869b4bd61d24faa7d9
VirtualSize 0x530
VirtualAddress 0x256000
SizeOfRawData 0x600
PointerToRawData 0x24d800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.74914

.reloc

MD5 77aab7b5f01736c6ce3c6ffde6f937c9
SHA1 6d42a1fe48846efd773ad18e6a687838f2e7e395
SHA256 970fca7ea5ffcb3ff03639875c44253008bff13f467be1cbee22ea65f0d157ea
SHA3 3451450e0bc5b16eb45962de1006e5e54e4c8f68fbe4eb96c3a629380a89e19e
VirtualSize 0x3f64
VirtualAddress 0x257000
SizeOfRawData 0x4000
PointerToRawData 0x24de00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.44941

Imports

KERNEL32.dll GetProcAddress
LoadLibraryA
CreateFileA
CloseHandle
GetLastError
ConnectNamedPipe
DisconnectNamedPipe
GetOverlappedResult
CancelIo
WaitForSingleObject
CreateEventW
Sleep
CreateNamedPipeA
WaitNamedPipeA
LockFileEx
ReadFile
UnlockFileEx
PeekNamedPipe
GetSystemInfo
LocalFree
FormatMessageA
FlushFileBuffers
WriteFile
SetLastError
FormatMessageW
WideCharToMultiByte
GetEnvironmentVariableW
FreeLibrary
GetCurrentDirectoryW
CreateDirectoryW
CreateFileW
DeleteFileW
GetDiskFreeSpaceExW
GetFileAttributesW
GetFileAttributesExW
GetFileInformationByHandle
GetFileTime
GetFullPathNameW
RemoveDirectoryW
SetEndOfFile
SetFileAttributesW
SetFilePointerEx
SetFileTime
DeviceIoControl
GetWindowsDirectoryW
GetModuleHandleW
CreateDirectoryExW
CopyFileExW
MoveFileExW
AreFileApisANSI
MultiByteToWideChar
QueryPerformanceCounter
QueryPerformanceFrequency
GetCurrentThread
GetThreadTimes
CreateWaitableTimerA
GetCurrentProcessId
DeleteCriticalSection
InitializeCriticalSection
LeaveCriticalSection
SetCurrentDirectoryW
EnterCriticalSection
GetModuleHandleA
GetLogicalProcessorInformation
SetWaitableTimer
OpenEventA
InitializeSRWLock
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
InitializeCriticalSectionEx
TryEnterCriticalSection
GetCurrentThreadId
WaitForSingleObjectEx
SwitchToThread
GetExitCodeThread
GetNativeSystemInfo
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
SleepConditionVariableSRW
SetFileInformationByHandle
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreExW
FlushProcessWriteBuffers
GetCurrentProcessorNumber
GetSystemTimeAsFileTime
GetTickCount64
FreeLibraryWhenCallbackReturns
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
GetFileInformationByHandleEx
CreateSymbolicLinkW
EncodePointer
DecodePointer
LCMapStringEx
GetLocaleInfoEx
GetStringTypeW
CompareStringEx
GetCPInfo
InitializeSListHead
InitializeCriticalSectionAndSpinCount
SetEvent
ResetEvent
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetCurrentProcess
TerminateProcess
RtlUnwindEx
RtlPcToFileHeader
RaiseException
InterlockedPushEntrySList
InterlockedFlushSList
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
CreateThread
ExitThread
ResumeThread
FreeLibraryAndExitThread
GetModuleHandleExW
ExitProcess
GetModuleFileNameW
HeapFree
HeapAlloc
GetStdHandle
GetFileType
GetTempPathW
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetConsoleOutputCP
GetConsoleMode
GetFileSizeEx
ReadConsoleW
HeapReAlloc
HeapSize
HeapQueryInformation
SetConsoleCtrlHandler
GetTimeZoneInformation
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
SetStdHandle
WriteConsoleW
OutputDebugStringW
ReleaseSemaphore
WaitForMultipleObjectsEx
CreateEventA
RtlUnwind
ADVAPI32.dll CryptReleaseContext
CryptAcquireContextA
SetSecurityDescriptorDacl
InitializeSecurityDescriptor
CryptGenRandom
bcrypt.dll BCryptOpenAlgorithmProvider
BCryptCloseAlgorithmProvider
BCryptGenRandom

Delayed Imports

AddChannelReactor

Ordinal 1
Address 0x282d0

AddReactor

Ordinal 2
Address 0x28440

BroadCastMessage

Ordinal 3
Address 0x285b0

CleanUp

Ordinal 4
Address 0x286e0

Connect

Ordinal 5
Address 0x28730

CreateChannel

Ordinal 6
Address 0x287e0

CreateChannelHub

Ordinal 7
Address 0x288b0

DestroyChannel

Ordinal 8
Address 0x28970

GetPendingMessageCount

Ordinal 9
Address 0x28a30

IPC_FreeBuffer

Ordinal 10
Address 0x28ad0

IPC_SendMessage

Ordinal 11
Address 0x28ae0

Notify

Ordinal 12
Address 0x28cc0

RemoveReactor

Ordinal 13
Address 0x28cd0

Send

Ordinal 14
Address 0x28ef0

SetFreeBufferCallback

Ordinal 15
Address 0x291a0

SetIPCGlobalLogger

Ordinal 16
Address 0x291c0

SetIPCLogger

Ordinal 17
Address 0x291f0

SetTimeout

Ordinal 18
Address 0x29390

SkipUnlinkServerSocket

Ordinal 19
Address 0x29440

StartChannelHub

Ordinal 20
Address 0x29510

TerminateChannelHubConnections

Ordinal 21
Address 0x29710

WaitingConnection

Ordinal 22
Address 0x297c0

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x310
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37348
MD5 2c05bde709e0e65a4d5763c374387301
SHA1 d596144172e664df94ff51707831d200634b5653
SHA256 290bd1b6e7472a3954a90df513aaf204577fe5c26f320b8158ae619437f46395
SHA3 7573abffca7f706e98bf5f498d85c3df7bf16ab83ed73d8be1754dea61e6bc4f

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2.0.1.0
ProductVersion 2.0.1.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
CompanyName Autodesk, Inc.
FileDescription Autodesk IPC Library
FileVersion (#2) 2.0.1.0
InternalName AdpIPC.dll
LegalCopyright © Autodesk, Inc. All rights reserved.
OriginalFilename AdpIPC.dll
ProductName Autodesk IPC Component
ProductVersion (#2) 2.0.1.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Jan-27 10:50:41
Version 0.0
SizeofData 66
AddressOfRawData 0x1f1c44
PointerToRawData 0x1f0644
Referenced File D:\git\adp-ipc\bin\x64\Release\AdpIPC.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2025-Jan-27 10:50:41
Version 0.0
SizeofData 20
AddressOfRawData 0x1f1c88
PointerToRawData 0x1f0688

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2025-Jan-27 10:50:41
Version 0.0
SizeofData 1116
AddressOfRawData 0x1f1c9c
PointerToRawData 0x1f069c

TLS Callbacks

StartAddressOfRawData 0x1801f2118
EndAddressOfRawData 0x1801f2120
AddressOfIndex 0x18023b840
AddressOfCallbacks 0x1801b47f8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks 0x0000000180192180

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1802283c8

RICH Header

XOR Key 0x4a066cd1
Unmarked objects 0
ASM objects (30795) 13
C++ objects (30795) 183
C objects (30795) 18
C objects (30034) 14
ASM objects (30034) 10
C++ objects (30034) 91
Imports (30795) 7
Total imports 193
C++ objects (VS2022 Update 6 (17.6.3) compiler 32534) 36
ASM objects (VS2022 Update 6 (17.6.3) compiler 32534) 1
C++ objects (VS2019 Update 11 (16.11.16-17) compiler 30146) 9
C++ objects (30154) 17
Exports (30154) 1
Resource objects (30154) 1
151 1
Linker (30154) 1

Errors

Leave a comment

No comments yet.