× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 03ad57c24ff2cf895b5f533f0ecbd10266fd8634c6b9053cc9cb33b814ad5d97
File name: api-ms-win-core-localization-l1-2-0.dll
Detection ratio: 0 / 69
Analysis date: 2019-02-15 17:14:54 UTC ( 3 days, 17 hours ago )
Trusted source! This file belongs to the Microsoft Corporation software catalogue.
Antivirus Result Update
ALYac 20190215
AVG 20190215
Acronis 20190213
Ad-Aware 20190215
AegisLab 20190215
AhnLab-V3 20190215
Alibaba 20180921
Antiy-AVL 20190215
Arcabit 20190215
Avast 20190215
Avast-Mobile 20190215
Avira (no cloud) 20190215
Babable 20180918
Baidu 20190215
BitDefender 20190215
Bkav 20190215
CAT-QuickHeal 20190215
CMC 20190215
ClamAV 20190215
Comodo 20190215
CrowdStrike Falcon (ML) 20181023
Cylance 20190215
Cyren 20190215
DrWeb 20190215
ESET-NOD32 20190215
Emsisoft 20190215
Endgame 20181108
F-Prot 20190215
F-Secure 20190215
Fortinet 20190215
GData 20190215
Ikarus 20190215
Sophos ML 20181128
Jiangmin 20190215
K7AntiVirus 20190215
K7GW 20190215
Kaspersky 20190215
Kingsoft 20190215
MAX 20190215
Malwarebytes 20190215
McAfee 20190215
McAfee-GW-Edition 20190215
eScan 20190215
Microsoft 20190215
NANO-Antivirus 20190215
Palo Alto Networks (Known Signatures) 20190215
Panda 20190215
Qihoo-360 20190215
Rising 20190215
SUPERAntiSpyware 20190213
SentinelOne (Static ML) 20190203
Sophos AV 20190215
Symantec 20190215
TACHYON 20190215
Tencent 20190215
TheHacker 20190215
TotalDefense 20190215
Trapmine 20190123
TrendMicro 20190215
TrendMicro-HouseCall 20190215
Trustlook 20190215
VBA32 20190215
ViRobot 20190215
Webroot 20190215
Yandex 20190215
Zillya 20190215
ZoneAlarm by Check Point 20190215
Zoner 20190215
eGambit 20190215
Cybereason 20180308
Symantec Mobile Insight 20190207
The file being studied is a Portable Executable file! More specifically, it is a Win32 DLL file for the Windows command line subsystem.
Authenticode signature block and FileVersionInfo properties
Copyright
© Microsoft Corporation. All rights reserved.

Product Microsoft® Windows® Operating System
Original name apisetstub
Internal name apisetstub
File version 10.0.16299.15 (WinBuild.160101.0800)
Description ApiSet Stub DLL
Signature verification Signed file, verified signature
Signing date 6:31 AM 9/29/2017
Signers
[+] Microsoft Corporation
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer Microsoft Code Signing PCA
Valid from 07:11 PM 08/11/2017
Valid to 07:11 PM 08/11/2018
Valid usage Code Signing
Algorithm sha1RSA
Thumbprint 49D59D86505D82942A076388693F4FB7B21254EE
Serial number 33 00 00 01 78 25 5A B5 CD 23 C6 5F 95 00 01 00 00 01 78
[+] Microsoft Code Signing PCA
Status Valid
Issuer Microsoft Root Certificate Authority
Valid from 09:19 PM 08/31/2010
Valid to 09:29 PM 08/31/2020
Valid usage All
Algorithm sha1RSA
Thumbprint 3CAF9BA2DB5570CAF76942FF99101B993888E257
Serial number 61 33 26 1A 00 00 00 00 00 31
[+] Microsoft Root Certificate Authority
Status Valid
Issuer Microsoft Root Certificate Authority
Valid from 10:19 PM 05/09/2001
Valid to 10:28 PM 05/09/2021
Valid usage All
Algorithm sha1RSA
Thumbprint CDD4EEAE6000AC7F40C3802C171E30148030C072
Serial number 79 AD 16 A1 4A A0 A5 AD 4C 73 58 F4 07 13 2E 65
Counter signers
[+] Microsoft Time-Stamp Service
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer Microsoft Time-Stamp PCA
Valid from 04:58 PM 09/07/2016
Valid to 04:58 PM 09/07/2018
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 1D0C7C8460E7E554FBED80DC2C90722EB20B10E3
Serial number 33 00 00 00 C3 3B B8 10 D6 AB 75 9C 84 00 00 00 00 00 C3
[+] Microsoft Time-Stamp PCA
Status Valid
Issuer Microsoft Root Certificate Authority
Valid from 11:53 AM 04/03/2007
Valid to 12:03 PM 04/03/2021
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 375FCB825C3DC3752A02E34EB70993B4997191EF
Serial number 61 16 68 34 00 00 00 00 00 1C
[+] Microsoft Root Certificate Authority
Status Valid
Issuer Microsoft Root Certificate Authority
Valid from 10:19 PM 05/09/2001
Valid to 10:28 PM 05/09/2021
Valid usage All
Algorithm sha1RSA
Thumbrint CDD4EEAE6000AC7F40C3802C171E30148030C072
Serial number 79 AD 16 A1 4A A0 A5 AD 4C 73 58 F4 07 13 2E 65
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2099-12-20 04:00:19
Number of sections 2
PE sections
Overlays
MD5 5e892ffb13eac0d44a88f5095211a131
File type data
Offset 5120
Size 15672
Entropy 7.40
PE exports
Number of PE resources by type
RT_VERSION 1
Number of PE resources by language
ENGLISH US 1
PE resources
Debug information
ExifTool file metadata
SubsystemVersion
10.0

InitializedDataSize
1024

ImageVersion
10.0

ProductName
Microsoft Windows Operating System

FileVersionNumber
10.0.16299.15

UninitializedDataSize
0

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

ImageFileCharacteristics
Executable, 32-bit, DLL

CharacterSet
Unicode

LinkerVersion
14.1

FileTypeExtension
dll

OriginalFileName
apisetstub

MIMEType
application/octet-stream

Subsystem
Windows command line

FileVersion
10.0.16299.15 (WinBuild.160101.0800)

TimeStamp
2099:12:20 05:00:19+01:00

FileType
Win32 DLL

PEType
PE32

InternalName
apisetstub

ProductVersion
10.0.16299.15

FileDescription
ApiSet Stub DLL

OSVersion
10.0

FileOS
Windows NT 32-bit

LegalCopyright
Microsoft Corporation. All rights reserved.

MachineType
Intel 386 or later, and compatibles

CompanyName
Microsoft Corporation

CodeSize
3584

FileSubtype
0

ProductVersionNumber
10.0.16299.15

Warning
Possibly corrupt Version resource

EntryPoint
0x0000

ObjectFileType
Dynamic link library

Execution parents
Compressed bundles
File identification
MD5 eff11130bfe0d9c90c0026bf2fb219ae
SHA1 cf4c89a6e46090d3d8feeb9eb697aea8a26e4088
SHA256 03ad57c24ff2cf895b5f533f0ecbd10266fd8634c6b9053cc9cb33b814ad5d97
ssdeep
384:KOMw3zdp3bwjGjue9/0jCRrndbVWPhWIDz6i00GftpBj6cemjlD16Pa+4r:KOMwBprwjGjue9/0jCRrndbCOoireqv

authentihash 9b0eff7e163e4bfba849fda05e58fb5573a950c57283240a6d3bff13a62b689c
File size 20.3 KB ( 20792 bytes )
File type Win32 DLL
Magic literal
PE32 executable for MS Windows (DLL) (console) Intel 80386 32-bit

TrID Win32 Executable (generic) (42.7%)
OS/2 Executable (generic) (19.2%)
Generic Win/DOS Executable (18.9%)
DOS Executable Generic (18.9%)
Tags
pedll signed trusted overlay

Trusted verdicts
This file belongs to the Microsoft Corporation software catalogue. The file is often found with 3de45b87-3fb9-e711-80c0-0003ff7747d6.dll as its name.
VirusTotal metadata
First submission 2017-10-11 07:01:59 UTC ( 1 year, 4 months ago )
Last submission 2019-02-15 17:14:54 UTC ( 3 days, 17 hours ago )
File names api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-localization-l1-2-0.dll
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!