| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Jan-28 22:00:18 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\agent\_work\23\s\Licensing261\LicensingCore\AnsysLi\build\winx64\x64\Release\ansyscl.pdb
|
| CompanyName | ANSYS, Inc. |
| FileDescription | Ansys Common Licensing. Modified at Ansys Release 2026 R1. |
| FileVersion | 2026.1.0.0 |
| InternalName | ansyscl |
| LegalCopyright | Copyright (C) 2026 Synopsys, Inc. and ANSYS, Inc. All rights reserved. |
| LegalTrademarks | Ansys® is a registered trademark of ANSYS, Inc. and FlexNet Publisher is a trademark of Flexera Software Inc. |
| OriginalFilename | ansyscl.exe |
| ProductName | Ansys Common Licensing |
| ProductVersion | 2026.1.0.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for VMWare presence:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses constants related to Blowfish Uses constants related to DES Uses known Diffie-Helman primes Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. | Unusual section name found: .textidx |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: ANSYS Inc.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Safe | VirusTotal score: 0/56 (Scanned on 2026-05-30 00:08:46) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x1c8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Jan-28 22:00:18 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xe34600 |
| SizeOfInitializedData | 0x66ee00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000BD6DD8 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x14a8000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x12eb39d |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WINHTTP.dll |
WinHttpGetProxyForUrl
WinHttpCloseHandle WinHttpGetIEProxyConfigForCurrentUser WinHttpOpen |
|---|---|
| WS2_32.dll |
WSASocketW
ntohl inet_ntop inet_pton getnameinfo WSASocketA getservbyname getservbyport inet_addr freeaddrinfo InetPtonW getaddrinfo WSAPoll inet_ntoa gethostbyname gethostname WSAStartup sendto recvfrom select __WSAFDIsSet WSASetLastError setsockopt recv WSAWaitForMultipleEvents WSAResetEvent WSAEventSelect socket WSACreateEvent WSACloseEvent send WSAIoctl WSACleanup gethostbyaddr shutdown listen htons htonl getsockopt getsockname getpeername ioctlsocket connect bind accept closesocket WSAEnumNetworkEvents WSAGetLastError ntohs |
| IPHLPAPI.DLL |
GetAdaptersInfo
GetExtendedTcpTable SendARP GetAdaptersAddresses |
| ADVAPI32.dll |
CryptAcquireContextW
CryptReleaseContext CredFree CredEnumerateW RegOpenKeyA RegDeleteValueW RegCreateKeyExW RegQueryInfoKeyW RegEnumValueW RegEnumKeyExW RegOpenKeyExW OpenProcessToken GetTokenInformation IsValidSid ConvertSidToStringSidW GetUserNameA CryptGetHashParam StartServiceA ReportEventA RegisterEventSourceA RegQueryInfoKeyA RegEnumKeyExA RegSetValueExW RegSetValueExA RegQueryValueExW RegQueryValueExA RegCreateKeyExA RegOpenKeyExA RegEnumValueA IsTextUnicode RegDeleteValueA RegCloseKey CryptGenRandom CryptEnumProvidersW CryptSignHashW CryptDecrypt CryptExportKey CryptGetUserKey CryptGetProvParam CryptSetHashParam CryptCreateHash ReportEventW RegisterEventSourceW DeregisterEventSource QueryServiceStatus GetUserNameW OpenServiceA OpenSCManagerA CloseServiceHandle CryptEncrypt CryptImportKey CryptDestroyKey CryptDestroyHash CryptHashData CryptAcquireContextA |
| ole32.dll |
CoInitializeSecurity
CoSetProxyBlanket CoCreateInstance CoQueryProxyBlanket CoInitializeEx CoUninitialize CoTaskMemFree |
| SHELL32.dll |
#680
SHGetKnownFolderIDList SHGetFolderPathA SHGetPathFromIDListW |
| USER32.dll |
wsprintfA
DialogBoxIndirectParamA CreateDialogIndirectParamA GetDlgItem GetParent GetWindowLongA ScreenToClient MessageBeep GetWindowRect GetClientRect SetWindowTextA SetDlgItemTextA GetFocus EndDialog SetFocus GetDlgItemTextW MoveWindow ShowWindow SendMessageA GetSystemMetrics GetActiveWindow MessageBoxW GetUserObjectInformationW GetProcessWindowStation MessageBoxA EnableWindow GetDlgItemTextA |
| CRYPT32.dll |
CertGetIntendedKeyUsage
CertGetEnhancedKeyUsage CryptUnprotectData CertGetCertificateContextProperty CertOpenSystemStoreW CertOpenStore CertCloseStore CertEnumCertificatesInStore CertFindCertificateInStore CertFreeCertificateContext CryptStringToBinaryA CertOpenSystemStoreA CryptMsgGetParam CryptMsgClose CertDuplicateCertificateContext CertAddCertificateContextToStore CertFindExtension CertGetNameStringA CryptQueryObject CertCreateCertificateChainEngine CertFreeCertificateChainEngine CertGetCertificateChain CertFreeCertificateChain PFXImportCertStore CryptDecodeObjectEx |
| NETAPI32.dll |
Netbios
|
| RPCRT4.dll |
UuidCreate
|
| WININET.dll |
InternetCloseHandle
InternetQueryOptionA HttpSendRequestW HttpOpenRequestW InternetSetOptionW InternetOpenW InternetQueryDataAvailable InternetReadFile InternetConnectW |
| USERENV.dll |
GetProfilesDirectoryA
|
| WINTRUST.dll |
WinVerifyTrust
|
| COMCTL32.dll |
#17
|
| dbghelp.dll |
SymGetModuleBase64
StackWalk64 SymInitialize SymFunctionTableAccess64 |
| KERNEL32.dll |
UnhandledExceptionFilter
IsProcessorFeaturePresent GetStartupInfoW InitializeSListHead RtlPcToFileHeader RtlUnwindEx RtlUnwind WriteConsoleW SetConsoleCtrlHandler RtlLookupFunctionEntry GetCPInfo ExitProcess FlsFree FlsSetValue SetEnvironmentVariableW SetCurrentDirectoryW GetDriveTypeW GetFileInformationByHandle FreeLibraryAndExitThread FlsGetValue SetFileTime SetFilePointerEx FlsAlloc LCMapStringEx DecodePointer EncodePointer GetStringTypeW CompareFileTime DeleteTimerQueueEx CreateTimerQueueTimer CreateTimerQueue ConvertThreadToFiber TerminateThread CreateEventW GetSystemPowerStatus TzSpecificLocalTimeToSystemTime GetPhysicallyInstalledSystemMemory CreateFiber InitializeCriticalSectionAndSpinCount FindFirstFileExW GetCommandLineA GetDateFormatW GetTimeFormatW HeapReAlloc CompareStringW HeapCompact SetEndOfFile UnlockFile FlushViewOfFile LockFile OutputDebugStringW UnlockFileEx LCMapStringW HeapDestroy GetFileAttributesA IsValidLocale GetUserDefaultLCID EnumSystemLocalesW HeapCreate HeapValidate GetFileAttributesW FlushFileBuffers GetTempPathW HeapSize LockFileEx GetDiskFreeSpaceW CreateFileMappingA GetExitCodeProcess CreateProcessW SetStdHandle GetDiskFreeSpaceA GetConsoleOutputCP GetFileAttributesExW OutputDebugStringA IsValidCodePage GetOEMCP DeleteFileW GetTempPathA AreFileApisANSI DeleteFileA GetEnvironmentStringsW ReadFile K32GetModuleInformation K32GetModuleFileNameExW K32EnumProcessModules Module32NextW Module32FirstW Sleep SetUnhandledExceptionFilter MultiByteToWideChar WideCharToMultiByte GetCurrentDirectoryA CloseHandle GetLastError QueryPerformanceCounter QueryPerformanceFrequency WaitForSingleObject GetProcessTimes GetCurrentProcess GetCurrentProcessId TerminateProcess CreateProcessA OpenProcess GlobalMemoryStatusEx GetSystemTimeAsFileTime GetComputerNameExA LocalAlloc LocalFree FormatMessageA CreateSemaphoreA SystemTimeToFileTime CreateToolhelp32Snapshot Process32Next ReleaseMutex CreateMutexA GetCurrentThreadId GetModuleFileNameA GlobalFree HeapAlloc HeapFree GetProcessHeap ReleaseSemaphore OpenSemaphoreA GetCurrentDirectoryW CreateDirectoryA CreateDirectoryW CreateFileA CreateFileW FindClose FindFirstFileA FindNextFileA GetFinalPathNameByHandleA GetFinalPathNameByHandleW GetFullPathNameW GetFullPathNameA SetFileAttributesA SetFileAttributesW GetModuleFileNameW GetModuleHandleA MoveFileExW FreeEnvironmentStringsW WriteFile DuplicateHandle CreatePipe MoveFileExA GetCurrentThread OpenThread GetThreadTimes RtlCaptureContext GetThreadContext FreeLibrary GetProcAddress LoadLibraryA ReleaseSRWLockExclusive AcquireSRWLockExclusive SetEvent CreateEventA GetSystemTimePreciseAsFileTime SystemTimeToTzSpecificLocalTime FileTimeToSystemTime EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionEx DeleteCriticalSection GetSystemDirectoryA SleepEx SetLastError GetTickCount WaitForSingleObjectEx GetEnvironmentVariableA GetStdHandle GetFileType PeekNamedPipe WaitForMultipleObjects VerSetConditionMask VerifyVersionInfoW CreateThread LoadLibraryExA FormatMessageW GetFileSizeEx SetFilePointer FindFirstFileW FindNextFileW LoadLibraryExW GetFileSize ExitThread DeviceIoControl GetModuleHandleExW GetEnvironmentVariableW GetModuleHandleW InitializeSRWLock ReleaseSRWLockShared AcquireSRWLockShared TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemInfo VirtualFree SwitchToFiber DeleteFiber CreateFiberEx GetACP RtlVirtualUnwind InitializeCriticalSection TryEnterCriticalSection GetExitCodeThread ConvertFiberToThread ConvertThreadToFiberEx GetSystemTime LoadLibraryW GetConsoleMode SetConsoleMode ReadConsoleA ReadConsoleW SetHandleInformation SetErrorMode GetVersion GetEnvironmentStrings FreeEnvironmentStringsA GetVersionExA lstrlenA GetWindowsDirectoryA RaiseException ResetEvent GetThreadPriority ResumeThread SetThreadContext GetProcessAffinityMask SetThreadAffinityMask GetCommandLineW GetLocalTime GetTimeZoneInformation GetSystemWindowsDirectoryA GetDriveTypeA GetVolumeInformationA SetNamedPipeHandleState WaitNamedPipeA DefineDosDeviceA QueryDosDeviceA CreateFileMappingW MapViewOfFile UnmapViewOfFile IsDebuggerPresent DebugBreak GetComputerNameExW GetVersionExW GetLocaleInfoW CreateMutexW |
| COMDLG32.dll |
GetOpenFileNameA
|
| OLEAUT32.dll |
SysStringLen
SafeArrayAccessData SafeArrayUnaccessData SafeArrayGetUBound VariantClear VariantInit SysAllocString SysAllocStringLen SafeArrayDestroy SysFreeString SafeArrayGetLBound |
| PSAPI.DLL |
EnumProcesses
EnumProcessModules GetProcessMemoryInfo GetModuleBaseNameA |
| dhcpcsvc.DLL |
DhcpRequestParams
|
| SHLWAPI.dll |
PathRemoveBackslashW
|
| Secur32.dll |
InitSecurityInterfaceA
|
| bcrypt.dll |
BCryptCloseAlgorithmProvider
BCryptGenRandom BCryptOpenAlgorithmProvider |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2026.1.0.0 |
| ProductVersion | 2026.1.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | ANSYS, Inc. |
| FileDescription | Ansys Common Licensing. Modified at Ansys Release 2026 R1. |
| FileVersion (#2) | 2026.1.0.0 |
| InternalName | ansyscl |
| LegalCopyright | Copyright (C) 2026 Synopsys, Inc. and ANSYS, Inc. All rights reserved. |
| LegalTrademarks | Ansys® is a registered trademark of ANSYS, Inc. and FlexNet Publisher is a trademark of Flexera Software Inc. |
| OriginalFilename | ansyscl.exe |
| ProductName | Ansys Common Licensing |
| ProductVersion (#2) | 2026.1.0.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-28 22:00:18 |
| Version | 0.0 |
| SizeofData | 116 |
| AddressOfRawData | 0x10549f0 |
| PointerToRawData | 0x10533f0 |
| Referenced File | C:\agent\_work\23\s\Licensing261\LicensingCore\AnsysLi\build\winx64\x64\Release\ansyscl.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-28 22:00:18 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1054a64 |
| PointerToRawData | 0x1053464 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-28 22:00:18 |
| Version | 0.0 |
| SizeofData | 1064 |
| AddressOfRawData | 0x1054a78 |
| PointerToRawData | 0x1053478 |
| StartAddressOfRawData | 0x141054ed0 |
|---|---|
| EndAddressOfRawData | 0x141054ed8 |
| AddressOfIndex | 0x141384818 |
| AddressOfCallbacks | 0x140e37150 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14119d078 |
| XOR Key | 0x2783db93 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (28900) | 240 |
| 253 (32420) | 18 |
| C objects (32420) | 20 |
| ASM objects (32420) | 10 |
| ASM objects (28900) | 27 |
| C objects (28900) | 41 |
| ASM objects (VS2010 SP1 build 40219) | 1 |
| C objects (40121) | 138 |
| ASM objects (VS2013 UPD4 build 31101) | 1 |
| 208 (65501) | 4 |
| Imports (65501) | 10 |
| C objects (CVTCIL) (27412) | 1 |
| ASM objects (VS2019 Update 11 (16.11.19) compiler 30147) | 1 |
| C objects (VS2019 Update 11 (16.11.19) compiler 30147) | 45 |
| Imports (30795) | 2 |
| Imports (VS2008 SP1 build 30729) | 8 |
| C objects (VS2013 UPD4 build 31101) | 771 |
| C objects (VS2008 SP1 build 30729) | 1 |
| C objects (VS2013 UPD5 build 40629) | 68 |
| C++ objects (32420) | 92 |
| C objects (VS2019 Update 10 (16.10.4) compiler 30040) | 1 |
| C objects (VS2010 SP1 build 40219) | 472 |
| ASM objects (30158) | 1 |
| C objects (30158) | 269 |
| Imports (28900) | 27 |
| Total imports | 507 |
| C objects (32548) | 937 |
| Unmarked objects (#2) | 39 |
| C objects (32545) | 137 |
| C objects (VS2022 Update 4 (17.4.3-4) compiler 31937) | 110 |
| ASM objects (VS2022 Update 4 (17.4.3-4) compiler 31937) | 1 |
| C objects (32541) | 3 |
| C++ objects (32541) | 247 |
| Resource objects (32541) | 1 |
| Linker (32541) | 1 |
No comments yet.