| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2059-Mar-15 07:59:31 |
| Detected languages |
English - United States
|
| Debug artifacts |
AdhSvc.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | AD Harvest Sites and Subnets Service |
| FileVersion | 10.0.26100.5074 (WinBuild.160101.0800) |
| InternalName | adhsvc.dll |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | adhsvc.dll |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 10.0.26100.5074 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Suspicious | The PE is possibly packed. | Unusual section name found: fothk |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/70 (Scanned on 2026-08-04 16:10:00) | All the AVs think this file is safe. |
| MD5 | 5d9d8994a3a965dcd987f33d8dd42bb5 🔍 |
|---|---|
| SHA1 | feee02517714471c5e873d818ffb7b0bd8422f8b 🔍 |
| SHA256 | 830955f41d38ed9da55e92bacd1a92dfa8f19aca8c542c1d54c5ebb9bcd1421a 🔍 |
| SHA3 | 9a0aaffdfd4a44bd7879cc1e8e53d31aa3460e103e61329f2e8ab0a33d378c1b 🔍 |
| SSDeep | 1536:2TqcdSKcfC8A9/qSHEtrEUWDp9k9YWYbiK/0WUpIlLnr1+szh:2FX8aiSkKUWDL/3i2UpINnxP 🔍 |
| Imports Hash | 629723207d4d35bf9283b7ff243b81b9 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2059-Mar-15 07:59:31 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xf000 |
| SizeOfInitializedData | 0xb000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000075D0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | A.0 |
| ImageVersion | A.0 |
| SubsystemVersion | A.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1b000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x25bd0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x40000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | bc94145e16bcf1e19c52479013773ff4 🔍 |
|---|---|
| SHA1 | 8f42c0db30544d06cb4de37dc81c5bae0e32d836 🔍 |
| SHA256 | 83c058e1e959ed5c701731af8fb036c61453f3aa329b5db24437134b40de6379 🔍 |
| SHA3 | 231050bd2f787bc5f2e8874be07d5c84ed2c01fa300fab69fad5879074ed35d1 🔍 |
| VirtualSize | 0xd08a |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0xe000 |
| PointerToRawData | 0x1000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.83931 |
| MD5 | ab8892f0eb6a6023324bd629a0ac9fcb 🔍 |
|---|---|
| SHA1 | 49661895a4fb5246dad5e423c2011a1767008669 🔍 |
| SHA256 | 47b5ba7d09134205773d05a1aea66476ef385734a182086b339a452a7616827e 🔍 |
| SHA3 | bc75c7f85a93d9fa8688012a4a8361587bcd55147e9841580eca2a5765f0989b 🔍 |
| VirtualSize | 0x1000 |
| VirtualAddress | 0xf000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0xf000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 0.0159202 |
| MD5 | 2cab48add2d4c8aaa509faa9f61b2631 🔍 |
|---|---|
| SHA1 | 787084dfdbb2036f9251c49421c55c062b16c209 🔍 |
| SHA256 | 89f45a9396adc9fdee95b66ea3a6c277858bc479fc09d80fe21666ea42420cf8 🔍 |
| SHA3 | e75ffa60b54895a811fc06ff3968e37a6a5b3ab22c73ac24a9846359a7f13442 🔍 |
| VirtualSize | 0x5780 |
| VirtualAddress | 0x10000 |
| SizeOfRawData | 0x6000 |
| PointerToRawData | 0x10000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.28601 |
| MD5 | e86fc7997b02ca3e3e621d76900cc904 🔍 |
|---|---|
| SHA1 | 1255e93591476a590d3a81ef9d07b349711a1f55 🔍 |
| SHA256 | d88b9611e984b9bdd173b1101c069c113a8b316e7e85105bcb2ad7b889200150 🔍 |
| SHA3 | 8c8dbb5d9734edee30fdd628cdabc7749dcf8562e9b620c9f4a41756b4bafafb 🔍 |
| VirtualSize | 0xda0 |
| VirtualAddress | 0x16000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x16000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0.488961 |
| MD5 | 8021b7eda79093a4ff5f795f37f871f7 🔍 |
|---|---|
| SHA1 | d076703f4d02124f15aae19d1de22b812572bde9 🔍 |
| SHA256 | c0dd7502e524b5e71d3ca74178c196349a568c86ab2d3d5bb6a26adadce1da1d 🔍 |
| SHA3 | a0c88d5b87aa881511082e641453ef4d4393a58c434ef86bccc8b2ce3fbbb440 🔍 |
| VirtualSize | 0xd44 |
| VirtualAddress | 0x17000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x17000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.23929 |
| MD5 | 5b8edacc3c9b8e13735b5ca8c6c4af42 🔍 |
|---|---|
| SHA1 | 94ddc24854b302b1f40d11d12f743bf58973d2e2 🔍 |
| SHA256 | 2fec8ab3011ba6eb91182257c920d22ee08207697d903f749f5f42d6164ed2e6 🔍 |
| SHA3 | 7820d0fe2acfcc3e1efd802e8dc295c8da83bfbb403bd0fabd3a34ababcc6604 🔍 |
| VirtualSize | 0x30 |
| VirtualAddress | 0x18000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x18000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0.0365667 |
| MD5 | c15470fc21c75452770e8b1dfb9ee936 🔍 |
|---|---|
| SHA1 | e7251bc862161bf5effb8e032bad0633034ca1e1 🔍 |
| SHA256 | eaf13a11917832fb62c2c132e09e2b080c347cdaff6b405399840c8f9f6df9a1 🔍 |
| SHA3 | aed815507ef74d72cda7a6c078242fbaffdd14d4c60571acc8b424fa58b67e95 🔍 |
| VirtualSize | 0x418 |
| VirtualAddress | 0x19000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x19000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 1.11448 |
| MD5 | 2394deb90ee92ef3aa53cfd36d16464b 🔍 |
|---|---|
| SHA1 | 3ab51dd5c4c70452c66bda9456e7db2743aa7f89 🔍 |
| SHA256 | 8637e53a957acfd7db56b3f0dc714fad741de9a57e6b63a23edcd571836fda7e 🔍 |
| SHA3 | bc677d68a586ccdc87b0275a9935e9cef2ec7bf5ad1932399b480caaa25524d9 🔍 |
| VirtualSize | 0x220 |
| VirtualAddress | 0x1a000 |
| SizeOfRawData | 0x1000 |
| PointerToRawData | 0x1a000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 1.06456 |
| api-ms-win-crt-runtime-l1-1-0.dll |
_initterm
_initterm_e |
|---|---|
| api-ms-win-crt-private-l1-1-0.dll |
_o__initialize_narrow_environment
_o__initialize_onexit_table _o__invalid_parameter_noinfo _o__recalloc _o__register_onexit_function _o__seh_filter_dll memcpy _o_free _o_malloc _o_wcsncpy_s __C_specific_handler __CxxFrameHandler3 _CxxThrowException _o__execute_onexit_table _o__errno _o__crt_atexit _o__configure_narrow_argv _o__cexit _o__callnewh _o___std_type_info_destroy_list _o___std_exception_destroy _o___std_exception_copy __std_terminate __CxxFrameHandler4 __C_specific_handler_noexcept |
| api-ms-win-crt-string-l1-1-0.dll |
memset
|
| ntdll.dll |
RtlVirtualUnwind
RtlLookupFunctionEntry RtlCaptureContext |
| api-ms-win-eventing-classicprovider-l1-1-0.dll |
TraceMessage
GetTraceEnableLevel GetTraceEnableFlags RegisterTraceGuidsW UnregisterTraceGuids GetTraceLoggerHandle |
| api-ms-win-core-synch-l1-1-0.dll |
EnterCriticalSection
SetEvent WaitForSingleObject WaitForMultipleObjectsEx ResetEvent WaitForSingleObjectEx InitializeCriticalSectionAndSpinCount DeleteCriticalSection InitializeCriticalSection ReleaseMutex CreateMutexW LeaveCriticalSection CreateEventW |
| api-ms-win-core-heap-l1-1-0.dll |
HeapAlloc
HeapFree GetProcessHeap |
| api-ms-win-core-libraryloader-l1-2-0.dll |
FreeLibrary
LoadResource FindResourceExW DisableThreadLibraryCalls GetProcAddress GetModuleHandleW SizeofResource GetModuleFileNameW LoadLibraryExW |
| api-ms-win-security-sddl-l1-1-0.dll |
ConvertStringSidToSidW
ConvertStringSecurityDescriptorToSecurityDescriptorW |
| api-ms-win-core-errorhandling-l1-1-0.dll |
GetLastError
SetLastError UnhandledExceptionFilter SetUnhandledExceptionFilter RaiseException |
| api-ms-win-core-heap-l2-1-0.dll |
LocalFree
|
| RPCRT4.dll |
RpcServerUnregisterIfEx
I_RpcBindingIsClientLocal RpcBindingToStringBindingW RpcEpUnregister RpcImpersonateClient RpcEpRegisterW RpcServerInqBindings RpcServerRegisterIfEx RpcServerUseProtseqW RpcStringFreeW RpcServerRegisterAuthInfoW RpcServerInqDefaultPrincNameW RpcBindingInqAuthClientW RpcRevertToSelf Ndr64AsyncServerCallAll NdrServerCallAll NdrAsyncServerCall RpcAsyncAbortCall RpcAsyncCompleteCall RpcStringBindingParseW NdrServerCall2 RpcBindingVectorFree |
| api-ms-win-core-sysinfo-l1-1-0.dll |
GetSystemTimeAsFileTime
|
| api-ms-win-core-threadpool-l1-2-0.dll |
WaitForThreadpoolTimerCallbacks
SetThreadpoolTimer CreateThreadpoolTimer WaitForThreadpoolWaitCallbacks CloseThreadpoolWait SetThreadpoolWait CreateThreadpoolWait CloseThreadpoolTimer |
| api-ms-win-core-handle-l1-1-0.dll |
CloseHandle
|
| api-ms-win-core-processthreads-l1-1-0.dll |
OpenThreadToken
GetCurrentThread TerminateProcess GetCurrentProcess GetCurrentProcessId CreateThread GetCurrentThreadId |
| api-ms-win-service-management-l1-1-0.dll |
OpenServiceW
CloseServiceHandle StartServiceW OpenSCManagerW |
| api-ms-win-service-management-l2-1-0.dll |
NotifyServiceStatusChangeW
|
| WLDAP32.dll |
#191
#27 #41 #135 #13 #145 #14 #18 #88 #73 #224 #203 #97 #140 #16 #206 #26 |
| api-ms-win-core-localization-l1-2-0.dll |
FormatMessageW
|
| api-ms-win-core-debug-l1-1-0.dll |
IsDebuggerPresent
|
| api-ms-win-core-string-l1-1-0.dll |
MultiByteToWideChar
|
| api-ms-win-core-com-l1-1-0.dll |
CoUninitialize
CoTaskMemAlloc CoTaskMemFree CoTaskMemRealloc CoInitializeEx CoCreateInstance |
| api-ms-win-security-base-l1-1-0.dll |
AccessCheck
|
| api-ms-win-core-registry-l1-1-0.dll |
RegCloseKey
RegQueryValueExW RegOpenKeyExW RegCreateKeyExW RegQueryInfoKeyW RegEnumKeyExW RegDeleteValueW RegSetValueExW |
| api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceCounter
|
| api-ms-win-core-interlocked-l1-1-0.dll |
InitializeSListHead
|
| api-ms-win-core-processthreads-l1-1-1.dll |
IsProcessorFeaturePresent
|
| api-ms-win-core-string-obsolete-l1-1-0.dll |
lstrcmpiW
|
| FirewallAPI.dll |
FwConvertIPv6SubNetToRange
FwCopyWFAddressesContents FwAlloc FwFree FwGetAddressesAsString FwFreeAddresses FwStringToAddresses FwMergeAddresses |
| OLEAUT32.dll |
VarUI4FromStr
|
| api-ms-win-core-string-l2-1-0.dll |
CharNextW
|
| api-ms-win-core-delayload-l1-1-1.dll |
ResolveDelayLoadedAPI
|
| api-ms-win-core-delayload-l1-1-0.dll |
DelayLoadFailureHook
|
| wkscli.dll (delay-loaded) |
NetGetJoinInformation
|
| Attributes | 0x1 |
|---|---|
| Name | wkscli.dll |
| ModuleHandle | 0x16878 |
| DelayImportAddressTable | 0x18020 |
| DelayImportNameTable | 0x13ba0 |
| BoundDelayImportTable | 0x13c00 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 1 |
|---|---|
| Address | 0x36f0 |
| Ordinal | 2 |
|---|---|
| Address | 0x4190 |
| Ordinal | 3 |
|---|---|
| Address | 0x88b0 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x3b8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.5073 |
| MD5 | d6f7a2dc7e23f426443fdca009d2efcc 🔍 |
| SHA1 | a8d1996c6ce68c5fb2c49d97e1681f4523ed4c37 🔍 |
| SHA256 | 980b6a9ac5da0e1f51c556baa533b20fb562059ee3b66679828daf820180df61 🔍 |
| SHA3 | 26cbdda4bd3e2635760d994523c40f8a5cf43fce27de5f0cd304ea38770ec6be 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.26100.5074 |
| ProductVersion | 10.0.26100.5074 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | AD Harvest Sites and Subnets Service |
| FileVersion (#2) | 10.0.26100.5074 (WinBuild.160101.0800) |
| InternalName | adhsvc.dll |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | adhsvc.dll |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 10.0.26100.5074 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2059-Mar-15 07:59:31 |
| Version | 0.0 |
| SizeofData | 35 |
| AddressOfRawData | 0x12818 |
| PointerToRawData | 0x12818 |
| Referenced File | AdhSvc.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2059-Mar-15 07:59:31 |
| Version | 0.0 |
| SizeofData | 1152 |
| AddressOfRawData | 0x1283c |
| PointerToRawData | 0x1283c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2059-Mar-15 07:59:31 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x12ce4 |
| PointerToRawData | 0x12ce4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2059-Mar-15 07:59:31 |
| Version | 0.0 |
| SizeofData | 4 |
| AddressOfRawData | 0x12d08 |
| PointerToRawData | 0x12d08 |
| StartAddressOfRawData | 0x180012d30 |
|---|---|
| EndAddressOfRawData | 0x180012d38 |
| AddressOfIndex | 0x180016870 |
| AddressOfCallbacks | 0x180011258 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x148 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x180016180 |
| GuardCFCheckFunctionPointer | 6442521016 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0xd27f8af7 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 86 |
| Unmarked objects (#2) | 1 |
| C objects (33145) | 14 |
| ASM objects (33145) | 5 |
| Total imports | 1275 |
| Imports (33145) | 7 |
| C++ objects (33145) | 29 |
| Exports (33145) | 1 |
| C objects (LTCG) (33145) | 22 |
| 253 (33145) | 1 |
| Resource objects (33145) | 1 |
| Linker (33145) | 1 |
No comments yet.