b1cbcbebd3847353b52780797108cc0d

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2020-Oct-07 12:31:51
Detected languages English - United States
Debug artifacts D:\BuildAgent\work\824522dc9b449d33\_bin\Release\x64\VeeamLicense.pdb
CompanyName Veeam Software Group GmbH
FileDescription Veeam License Library
FileVersion 1.0.0.82
InternalName VeeamLicense.dll
LegalCopyright © 2020 Veeam Software Group GmbH. All rights reserved.
OriginalFilename VeeamLicense.dll
ProductName Veeam License Library
ProductVersion 1.0.0.82

Plugin Output

Info Libraries used to perform cryptographic operations: Microsoft's Cryptography API
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
Can access the registry:
  • RegQueryValueExW
  • RegSetValueExW
  • RegQueryInfoKeyW
  • RegOpenKeyExW
  • RegEnumKeyExW
  • RegDeleteValueW
  • RegDeleteKeyW
  • RegCreateKeyExW
  • RegCloseKey
Uses Microsoft's cryptographic API:
  • CryptVerifySignatureW
  • CryptDestroyHash
  • CryptHashData
  • CryptCreateHash
  • CryptImportKey
  • CryptGetHashParam
  • CryptDestroyKey
  • CryptReleaseContext
  • CryptAcquireContextW
Malicious The PE's digital signature is invalid. Signer: Veeam Software Group GmbH
Issuer: DigiCert EV Code Signing CA (SHA2)
The file was modified after it was signed.
Suspicious VirusTotal score: 1/66 (Scanned on 2021-11-25 13:55:17) eGambit: PE.Heur.InvalidSig

Hashes

MD5 b1cbcbebd3847353b52780797108cc0d
SHA1 6822a1510d381d509905dc4fccfc68fb9c0cf860
SHA256 10a57755c30e9043b3f9d65fa7ce049a09c04ee418a207487b0dfd31599c186b
SHA3 8ebcaf9c24b43c9862dedb40f8f0ccee092dd92bbcdaf097564583ee4e7ae52b
SSDeep 12288:EBA02aCyGQqGgiorHUcZn1hpAotQRvfI0c9JvU4laMqoOJM:EB7A0cPUCa7x
Imports Hash 1f08eba90d0b6dd0fbfbdf8399051f29

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2020-Oct-07 12:31:51
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x65200
SizeOfInitializedData 0x2b800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000003F7E8 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x180000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x97000
SizeOfHeaders 0x400
Checksum 0x97232
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 00c66c9f7562db78bf90d80544baf850
SHA1 4efb4528cc67221edc35adfcc5bcea5fdb59d388
SHA256 8dc6dd77da28494c6d4800903b47c08ea2d625b933b6d2df081b11e0a2146e6c
SHA3 03c0856a1ba4056a7dc8926f62371299707ba30ff326d810a49da60ce6237b8f
VirtualSize 0x651d0
VirtualAddress 0x1000
SizeOfRawData 0x65200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46281

.rdata

MD5 961f09994efb0115a0c08ca412fc79a7
SHA1 5fdd248f1175b2e33bc559114bfe41afdaf92918
SHA256 f020cd7f67cdb879b581aec30b97c547ddef2a7001221b193a2f0073bd45d0f0
SHA3 2ef495198d235e1f0aecd2f4d54320fadb653bd83394e3c52f12f27494ed1a15
VirtualSize 0x1e090
VirtualAddress 0x67000
SizeOfRawData 0x1e200
PointerToRawData 0x65600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.04315

.data

MD5 e4fc360096c9dca54d33461f21bce089
SHA1 79def23015e534156a44efc202c20c9ed435a00a
SHA256 dc5545413131d67cf258d6ea846a71c0bd6be9b28707239925888ea9ba7704fc
SHA3 4a02a93a2bf3836ed53432499f6dcfc2ea1e57e2785db8c905676c3f90bb0dc4
VirtualSize 0x44ac
VirtualAddress 0x86000
SizeOfRawData 0x2a00
PointerToRawData 0x83800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.19566

.pdata

MD5 130873a5d4ead34b9f036f57e659eea0
SHA1 dca0ba725de1044bcae5f1beed2d2d21d92e30e8
SHA256 d5d5ebbbc08a31ceb04adbcde604b146fd0337d0e2cb686cecdef4b250d47cee
SHA3 ab0f1d1cd5cee48f8ae45595c5966b1bdac21a05786a5701fce2a1001faf6dae
VirtualSize 0x420c
VirtualAddress 0x8b000
SizeOfRawData 0x4400
PointerToRawData 0x86200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.68442

_RDATA

MD5 6bda00029043b276b9d00b70f64c5873
SHA1 4b8c833cecb6444fcbd3b77d463f77b4fc6bc400
SHA256 2db57253cc534f7b267aae474ec8293c9ca816349fff205bba12f92b4fbe681b
SHA3 67c75f9c6787a020cd183784534c8aeada3310cf4461b7ebc982fd8da2630e70
VirtualSize 0x94
VirtualAddress 0x90000
SizeOfRawData 0x200
PointerToRawData 0x8a600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.45584

.rsrc

MD5 0c5d3fbe1eefd7a2ff9c66f5e6419001
SHA1 73953cab11b4232be4b53d2187d88cdd9086c4b6
SHA256 39c140c5b8415ae5624896a03ec8518135a6b1c5bea5761e35b365a0c0c7b793
SHA3 29ac4160d8843efdf57d5bc2f1afa6ab55c3e1dd322b8afd9284e4027041596e
VirtualSize 0x3528
VirtualAddress 0x91000
SizeOfRawData 0x3600
PointerToRawData 0x8a800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.98074

.reloc

MD5 a4f53fb48ec5e2f2c026d9ad46daddfb
SHA1 c91ffed92476264c1975ef2cb54f8e8f84b846fd
SHA256 f477b2bcb7b82a2dff53992eb742f445965b41bc87de1750c486477f3b09358d
SHA3 d71be605a132924cfa0c25433f1f76139b4910af021a219ff720ddff7c7be999
VirtualSize 0x1348
VirtualAddress 0x95000
SizeOfRawData 0x1400
PointerToRawData 0x8de00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.38196

Imports

RPCRT4.dll UuidFromStringW
KERNEL32.dll LoadLibraryExW
LoadResource
LockResource
SizeofResource
FindResourceW
LocalFree
lstrcmpiW
MultiByteToWideChar
DecodePointer
EncodePointer
GetThreadLocale
GetProcAddress
GetSystemTime
WideCharToMultiByte
CreateFileW
GetFileSize
ReadFile
WriteFile
CloseHandle
GetACP
GetConsoleMode
GetConsoleCP
GetModuleHandleW
GetModuleFileNameW
FreeLibrary
FindResourceExW
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
LeaveCriticalSection
EnterCriticalSection
GetProcessHeap
HeapSize
HeapFree
HeapReAlloc
HeapAlloc
HeapDestroy
GetLastError
RaiseException
WriteConsoleW
SetThreadLocale
FlushFileBuffers
SetStdHandle
SetFilePointerEx
SetEnvironmentVariableW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
IsValidCodePage
FindNextFileW
FindFirstFileExW
FindClose
GetTimeZoneInformation
GetFileType
GetStdHandle
GetOEMCP
EnumSystemLocalesW
GetUserDefaultLCID
IsValidLocale
GetTimeFormatW
GetDateFormatW
GetModuleHandleExW
ExitProcess
InterlockedFlushSList
RtlUnwindEx
RtlPcToFileHeader
InitializeSListHead
GetCurrentThreadId
GetCurrentProcessId
QueryPerformanceCounter
GetStartupInfoW
WaitForSingleObjectEx
ResetEvent
SetEvent
IsProcessorFeaturePresent
GetCommandLineA
IsDebuggerPresent
OutputDebugStringW
GetStringTypeW
SetLastError
CreateEventW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
CompareStringW
LCMapStringW
GetLocaleInfoW
GetCPInfo
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
USER32.dll CharNextW
ADVAPI32.dll RegQueryValueExW
CryptVerifySignatureW
CryptDestroyHash
CryptHashData
CryptCreateHash
CryptImportKey
CryptGetHashParam
CryptDestroyKey
CryptReleaseContext
CryptAcquireContextW
RegSetValueExW
RegQueryInfoKeyW
RegOpenKeyExW
RegEnumKeyExW
RegDeleteValueW
RegDeleteKeyW
RegCreateKeyExW
RegCloseKey
ole32.dll CoCreateInstance
CoCreateFreeThreadedMarshaler
CoTaskMemRealloc
StringFromGUID2
OleRun
CoTaskMemFree
CoTaskMemAlloc
OLEAUT32.dll SafeArrayRedim
SafeArrayUnaccessData
SafeArrayAccessData
SafeArrayUnlock
SafeArrayLock
SafeArrayGetLBound
SafeArrayGetUBound
SafeArrayGetElemsize
SafeArrayDestroy
SafeArrayCreate
CreateErrorInfo
VariantChangeType
VariantCopy
VariantInit
SystemTimeToVariantTime
UnRegisterTypeLib
RegisterTypeLib
VariantClear
SysAllocString
GetErrorInfo
LoadRegTypeLib
LoadTypeLib
VarUI4FromStr
SysAllocStringByteLen
SysStringByteLen
SysStringLen
SysFreeString
SysAllocStringLen
VariantCopyInd
SetErrorInfo

Delayed Imports

DllCanUnloadNow

Ordinal 1
Address 0x8590

DllGetClassObject

Ordinal 2
Address 0x85c0

DllRegisterServer

Ordinal 3
Address 0x8730

DllUnregisterServer

Ordinal 4
Address 0x8850

101

Type REGISTRY
Language English - United States
Codepage UNKNOWN
Size 0x81
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.58286
MD5 f08ccf7533c7265066cb3eb7f0766473
SHA1 f3ab478004e4dc8dac41e329ca1f0ee65a21db8b
SHA256 efb1a41666a26534a94397eb889ccccc62e3c09204f06db11ddfa1116c138f52
SHA3 970aeb24c6c2c8e52137ba5a8b3e1770dc64f75c61acc479164727c9e2b981cd

103

Type REGISTRY
Language English - United States
Codepage UNKNOWN
Size 0x2c3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.26442
MD5 0568abb3c025f0038000afbf2fb876e0
SHA1 884447e90c024370fe7ab3e68c826a0626a7af2f
SHA256 3ad8c82937e9118a419fef854bfdea52e72454e4b994ab8656526d27ff611961
SHA3 7f2a0b80b4f00fa3210906e9fa3608930013c738a0d3a734f0c3d53a35f0f2ba

104

Type REGISTRY
Language English - United States
Codepage UNKNOWN
Size 0x2bb
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.36471
MD5 39f01c68882aba0d96252915b926bd9b
SHA1 55e4ed16849607760532509564b5936bf096e034
SHA256 e6cff58049edbb22291c5c4706fabd262618dc619c4f76850ee82fbc186eab2d
SHA3 6a12f0ff01404ddd1473f5c7d76b2d4c94bcb1ecf00d366687e16314bb7c79b9

108

Type REGISTRY
Language English - United States
Codepage UNKNOWN
Size 0x2eb
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.28014
MD5 e20870942cfb4e63d8a493273db698e0
SHA1 9807e13e0f9d3602198d246423b70755dce3a57f
SHA256 11b70a194a23d5dcdc41edc238e9f44e6e96db7a14b8b0ef91b3d238db44f177
SHA3 a45507ce211baa8399b1a298641a6cdf4cd799bccf3d1026e50ea162fd4634f7

109

Type REGISTRY
Language English - United States
Codepage UNKNOWN
Size 0x2fb
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.24643
MD5 e8b0dd16cc5225a1533879684f543ae8
SHA1 8847e5933b430943bfbc521501304c7bb8ef399b
SHA256 91ad8bc8e6f1bf146eb5c71077c000d6b505dbd3ee81933b5ac914fae9e32369
SHA3 e0dceb2100a1a6dd12d236608aba1838d17afe342e0932d52dcc3fa0fd097f9d

1

Type TYPELIB
Language English - United States
Codepage UNKNOWN
Size 0x1f38
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.47843
MD5 70077bf124461c5d6c16cd0bff18203e
SHA1 48f346cb848c56a263df6f034ef73c892dc053e7
SHA256 46f35544d4a08464009e9bf426347f2c44fa82d40e69ea514dd7f11e44441347
SHA3 286053d600147d9cc35af27d308c4b2fbdb8cc2e0b420c4109554e1d787391bd

7

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x2b0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23151
MD5 74bc4b493e34ac4b3dc91bb3ba8a2750
SHA1 e21cab175cc47ac987ea1ecbda5b6ac6d08e6c7a
SHA256 75c420e374a183376604fec2b353f102a33ec7bd94756c1c895aa38ad163423a
SHA3 3eae14dbd606769ab3e6c0fd44bd5af1188c11d12772acbd4bfd3e8821feae09

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x360
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37308
MD5 d37a166af9bd655e6f807d684c7f2e6a
SHA1 111b27ecae0cafd9335f26413416bc072880601f
SHA256 da8ed082ee841adec6c9256723a4486d493ffe97dd2ce6513e1d46cf4b95b213
SHA3 17bb8cc4859a94511298e84affc23e109fcb21257d16eeb67339e41ad93d9e1b

2

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

String Table contents

VeeamLicense
The specified property cannot be found.
License version is invalid.
License has expired
Support period has expired
Sockets number exceeded
The license key is corrupted
Unexpected property type
License for specified product was not found.
Can't create MSXML parser.
The signature is invalid.
The license specified is too large.

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.82
ProductVersion 1.0.0.82
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
CompanyName Veeam Software Group GmbH
FileDescription Veeam License Library
FileVersion (#2) 1.0.0.82
InternalName VeeamLicense.dll
LegalCopyright © 2020 Veeam Software Group GmbH. All rights reserved.
OriginalFilename VeeamLicense.dll
ProductName Veeam License Library
ProductVersion (#2) 1.0.0.82
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2020-Oct-07 12:31:51
Version 0.0
SizeofData 94
AddressOfRawData 0x7ddd4
PointerToRawData 0x7c3d4
Referenced File D:\BuildAgent\work\824522dc9b449d33\_bin\Release\x64\VeeamLicense.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2020-Oct-07 12:31:51
Version 0.0
SizeofData 20
AddressOfRawData 0x7de34
PointerToRawData 0x7c434

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2020-Oct-07 12:31:51
Version 0.0
SizeofData 968
AddressOfRawData 0x7de48
PointerToRawData 0x7c448

TLS Callbacks

StartAddressOfRawData 0x18007e230
EndAddressOfRawData 0x18007e238
AddressOfIndex 0x1800897b8
AddressOfCallbacks 0x1800675c8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x130
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1800861a8

RICH Header

XOR Key 0xce6fa0d8
Unmarked objects 0
ASM objects (26715) 10
C++ objects (26715) 154
C objects (VS 2015/2017/2019 runtime 28920) 15
ASM objects (VS 2015/2017/2019 runtime 28920) 10
C++ objects (VS 2015/2017/2019 runtime 28920) 82
C objects (26715) 21
Imports (26715) 13
Total imports 162
C++ objects (VS2019 Update 7 (16.7.1) compiler 29111) 7
Exports (VS2019 Update 7 (16.7.1) compiler 29111) 1
Resource objects (VS2019 Update 7 (16.7.1) compiler 29111) 1
151 1
Linker (VS2019 Update 7 (16.7.1) compiler 29111) 1

Errors

<-- -->