6f6a6e38715c9b3838f95e03fa0567f3

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Mar-20 04:58:20
Detected languages English - United States
CompanyName Microsoft Corporation
FileDescription Passport CRL configuration
InternalName ppcrlconfig600
LegalCopyright Copyright © 1995-2006 Microsoft Corporation.
LegalTrademarks Microsoft® is a registered trademark of Microsoft Corporation.
OriginalFilename ppcrlconfig600.dll
ProductName Microsoft® Windows Live ID
FileVersion 16.000.28985.00
ProductVersion 16.000.28985.00

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • .devicedns.live.com
  • .live.com
  • account.live.com
  • account.microsoft.com
  • atdmt.com
  • c.live.com
  • c.msn.com
  • clientconfig.passport.net
  • devicedns.live.com
  • go.microsoft.com
  • http://clientconfig.passport.net
  • http://clientconfig.passport.net/ppcrlcheck.xml
  • http://clientconfig.passport.net/ppcrlconfig.srf
  • http://go.microsoft.com
  • http://go.microsoft.com/fwlink/?LinkId
  • http://go.microsoft.com/fwlink/p/?LinkId
  • http://login.live.com
  • http://login.live.com/hp.srf?format
  • http://schemas.microsoft.com
  • http://schemas.microsoft.com/Passport/PPCRL
  • http://sqm.microsoft.com
  • http://sqm.microsoft.com/sqm/WindowsLive/sqmserver.dll
  • http://www.microsoft.com
  • http://www.microsoft.com/account/default.aspx
  • http://www.w3.org
  • http://www.w3.org/2000/09/xmldsig#
  • https://account.live.com
  • https://account.live.com/InlineSignup.aspx?iww
  • https://account.live.com/Wizard/Password/Change?id
  • https://account.live.com/inlinesignup.aspx?iww
  • https://account.live.com/msangcwam
  • https://account.microsoft.com
  • https://account.microsoft.com/?ref
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/?LinkId
  • https://login.live.com
  • https://login.live.com/ApproveSession.srf
  • https://login.live.com/IfExists.srf?uiflavor
  • https://login.live.com/ListSessions.srf
  • https://login.live.com/ManageApprover.srf
  • https://login.live.com/ManageLoginKeys.srf
  • https://login.live.com/RST.srf
  • https://login.live.com/RST2.srf
  • https://login.live.com/didtou.srf
  • https://login.live.com/getrealminfo.srf
  • https://login.live.com/getuserrealm.srf
  • https://login.live.com/ppsecure/DeviceAssociate.srf
  • https://login.live.com/ppsecure/DeviceDisassociate.srf
  • https://login.live.com/ppsecure/DeviceQuery.srf
  • https://login.live.com/ppsecure/DeviceUpdate.srf
  • https://login.live.com/ppsecure/EnumerateDevices.srf
  • https://login.live.com/ppsecure/GetUserKeyData.srf
  • https://login.live.com/ppsecure/InlineClientAuth.srf
  • https://login.live.com/ppsecure/InlineConnect.srf?id
  • https://login.live.com/ppsecure/InlineDesktop.srf
  • https://login.live.com/ppsecure/InlineLogin.srf?id
  • https://login.live.com/ppsecure/InlinePOPAuth.srf?id
  • https://login.live.com/ppsecure/ResolveUser.srf
  • https://login.live.com/ppsecure/SHA1Auth.srf
  • https://login.live.com/ppsecure/deviceaddcredential.srf
  • https://login.live.com/ppsecure/devicechangecredential.srf
  • https://login.live.com/ppsecure/deviceremovecredential.srf
  • https://login.live.com/resetpw.srf
  • https://login.live.com/retention.srf
  • https://signup.live.com
  • https://signup.live.com/signup.aspx
  • login.live.com
  • microsoft.com
  • office.live.com
  • passport.net
  • ppauthz.com
  • schemas.microsoft.com
  • signup.live.com
  • sqm.microsoft.com
  • windowsmarketplace.com
  • workspace.office.live.com
  • www.microsoft.com
  • www.w3.org
Suspicious The PE is possibly packed. The PE only has 0 import(s).
Info The PE is digitally signed. Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA 2010
Safe VirusTotal score: 0/67 (Scanned on 2021-04-16 01:42:36) All the AVs think this file is safe.

Hashes

MD5 6f6a6e38715c9b3838f95e03fa0567f3
SHA1 40bffba8deebcfa89ff78591d1697290a8f8145d
SHA256 b1eab91db2cb293c153d0cb5ebf1ac3a9d50ac75d050403e8b9e1ec68881bd5f
SHA3 a5a9e5c054c7a5e31b9013ffd31fcd697ae202dd5fa3732c2fe06ccc3618794d
SSDeep 384:XmWQWLzrKWgr1P+2qZDZI8eNZzm5yKoStxfT/IrlgEf:nABm538
Imports Hash d41d8cd98f00b204e9800998ecf8427e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xb8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 2
TimeDateStamp 2021-Mar-20 04:58:20
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0
SizeOfInitializedData 0x4600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000 (Section: ?)
BaseOfCode 0x1000
BaseOfData 0x1000
ImageBase 0x10000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x7000
SizeOfHeaders 0x200
Checksum 0x12ebd
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.rdata

MD5 2ef28727f00a1d38500cd94422f5d72b
SHA1 07f9048ce56f0ad2b4acc63a78965396b5cff199
SHA256 48fab3a9b54a70cb3513714a281cf9117fe20a0a7d942e3179b5f8920d9df38c
SHA3 e394296649f9573830676de1da52ea91ca430428f93f5fb6660582f5945908bb
VirtualSize 0x70
VirtualAddress 0x1000
SizeOfRawData 0x200
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.991548

.rsrc

MD5 516d7af7fa1431b63309e20825650716
SHA1 d5259a5ce7780d3e74c75a2fb7226a69c8f5dacd
SHA256 d763b5f30ac89811fd6b6794814fc7e1329de93aac91bcc9f8adfd12ce17bf30
SHA3 5fa83327e86ca92523b6b25c895ce1c929fa35d7955ea54f7f1fa2d8aee73837
VirtualSize 0x4308
VirtualAddress 0x2000
SizeOfRawData 0x4400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.71973

Imports

Delayed Imports

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x41c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43728
MD5 36f6af1031d6950e4c98f596e7f618f3
SHA1 a090adb2f4a41e8145a51b5c12c74332c447e954
SHA256 f65cfa6ebde7eb6597a8575158bdc151258cff2cafd6e48d5bca9b16f8bd6c5f
SHA3 ef47b244a3259dbb31df34fec5ef5311d404b998f35398b1e4b81478c14e4f36

100

Type UNKNOWN
Language English - United States
Codepage UNKNOWN
Size 0x3e48
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.69777
MD5 cd6d94bd065dfa26d2bb7a77f635a5a2
SHA1 ece92de3bcb0a54a3c60e5d4d9209ff874af5c26
SHA256 f52bc6f7705a74605a95e409d7ec9539b2e694025fca6f6fd1a963597763fe49
SHA3 cc4a56382bfffc49c4ec86e02a183b1072ffe5859d929341802cfbc198d25c07

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 16.0.28985.0
ProductVersion 16.0.28985.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Microsoft Corporation
FileDescription Passport CRL configuration
InternalName ppcrlconfig600
LegalCopyright Copyright © 1995-2006 Microsoft Corporation.
LegalTrademarks Microsoft® is a registered trademark of Microsoft Corporation.
OriginalFilename ppcrlconfig600.dll
ProductName Microsoft® Windows Live ID
FileVersion (#2) 16.000.28985.00
ProductVersion (#2) 16.000.28985.00
Resource LangID English - United States

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2021-Mar-20 04:58:20
Version 0.0
SizeofData 84
AddressOfRawData 0x101c
PointerToRawData 0x21c

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x8c52fe7d
Unmarked objects 0
Resource objects (VS2019 Update 8 (16.8.3) compiler 29335) 1
Linker (VS2019 Update 8 (16.8.3) compiler 29335) 1

Errors

<-- -->