× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 07ea1a3c58c9c17bf8b395b0f30dd080cce9f1e61dc70726817b565d52cf3e39
File name: Microsoft.Cci.PeWriter.dll
Detection ratio: 0 / 62
Analysis date: 2017-05-18 12:08:33 UTC ( 9 months, 1 week ago )
Antivirus Result Update
Ad-Aware 20170518
AegisLab 20170518
AhnLab-V3 20170518
Alibaba 20170518
ALYac 20170518
Antiy-AVL 20170518
Arcabit 20170518
Avast 20170518
AVG 20170518
Avira (no cloud) 20170518
AVware 20170518
Baidu 20170503
BitDefender 20170518
Bkav 20170518
CAT-QuickHeal 20170518
ClamAV 20170518
CMC 20170517
Comodo 20170518
CrowdStrike Falcon (ML) 20170130
Cyren 20170518
DrWeb 20170518
Emsisoft 20170518
Endgame 20170515
ESET-NOD32 20170518
F-Prot 20170518
F-Secure 20170518
Fortinet 20170518
GData 20170518
Ikarus 20170518
Sophos ML 20170516
Jiangmin 20170518
K7AntiVirus 20170518
K7GW 20170518
Kaspersky 20170518
Kingsoft 20170518
Malwarebytes 20170518
McAfee 20170518
McAfee-GW-Edition 20170517
Microsoft 20170518
eScan 20170518
NANO-Antivirus 20170518
nProtect 20170518
Palo Alto Networks (Known Signatures) 20170518
Panda 20170517
Qihoo-360 20170518
Rising 20170518
SentinelOne (Static ML) 20170516
Sophos AV 20170518
SUPERAntiSpyware 20170518
Symantec 20170517
Symantec Mobile Insight 20170518
Tencent 20170518
TheHacker 20170516
TotalDefense 20170518
TrendMicro 20170518
TrendMicro-HouseCall 20170518
VBA32 20170518
VIPRE 20170518
ViRobot 20170518
Webroot 20170518
WhiteArmor 20170517
Yandex 20170517
Zillya 20170518
ZoneAlarm by Check Point 20170518
Zoner 20170518
The file being studied is a Portable Executable file! More specifically, it is a Win32 DLL file for the Windows command line subsystem.
FileVersionInfo properties
Copyright
Copyright (c) Microsoft Corporation. All rights reserved.

Product ModuleWriter
Original name Microsoft.Cci.PeWriter.dll
Internal name Microsoft.Cci.PeWriter.dll
File version 2.0.50.23471
Description ModuleWriter
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2012-03-28 21:21:13
Entry Point 0x0002201E
Number of sections 3
.NET details
Module Version ID 00efee1e-c1b9-414f-9072-626d012a0627
TypeLib ID ca48caa0-6b9b-42d0-a4e0-17f9120575b5
PE sections
PE imports
_CorDllMain
Number of PE resources by type
RT_VERSION 1
Number of PE resources by language
NEUTRAL 1
PE resources
Debug information
ExifTool file metadata
SubsystemVersion
4.0

LinkerVersion
8.0

ImageVersion
0.0

ProductName
ModuleWriter

FileVersionNumber
2.0.50.23471

UninitializedDataSize
0

LanguageCode
Neutral

FileFlagsMask
0x003f

CharacterSet
Unicode

InitializedDataSize
2048

FileTypeExtension
dll

OriginalFileName
Microsoft.Cci.PeWriter.dll

MIMEType
application/octet-stream

Subsystem
Windows command line

FileVersion
2.0.50.23471

TimeStamp
2012:03:28 22:21:13+01:00

FileType
Win32 DLL

PEType
PE32

InternalName
Microsoft.Cci.PeWriter.dll

ProductVersion
2.0.50.23471

FileDescription
ModuleWriter

OSVersion
4.0

FileOS
Win32

LegalCopyright
Copyright (c) Microsoft Corporation. All rights reserved.

MachineType
Intel 386 or later, and compatibles

CompanyName
Microsoft Corporation

CodeSize
131584

FileSubtype
0

ProductVersionNumber
2.0.50.23471

EntryPoint
0x2201e

ObjectFileType
Dynamic link library

AssemblyVersion
2.0.49.23471

File identification
MD5 2451bfc6897cd0f17a93277424e8db86
SHA1 d9df600cdf0ceaababa73fed647eac5ab636b6a7
SHA256 07ea1a3c58c9c17bf8b395b0f30dd080cce9f1e61dc70726817b565d52cf3e39
ssdeep
3072:IMOYgokvtWL544ITGtgL1qtopWGmsefir:IMOYgokke4ITGtgL1uopW1i

authentihash d0fddd02bfb90e511a55af3803773f37f96b98488d8e5203a4d9e9aafb6cbdbe
imphash dae02f32a21e03ce65412f6e56942daa
File size 131.0 KB ( 134144 bytes )
File type Win32 DLL
Magic literal
PE32 executable for MS Windows (DLL) (console) Intel 80386 32-bit Mono/.Net assembly

TrID Generic .NET DLL/Assembly (94.0%)
Win32 Dynamic Link Library (generic) (2.5%)
Win32 Executable (generic) (1.7%)
Generic Win/DOS Executable (0.7%)
DOS Executable Generic (0.7%)
Tags
assembly pedll

VirusTotal metadata
First submission 2012-04-02 12:59:19 UTC ( 5 years, 10 months ago )
Last submission 2012-04-02 12:59:19 UTC ( 5 years, 10 months ago )
File names Microsoft.Cci.PeWriter.dll
525CA415007EBE710CD502FA6C7A360071DA7827.dll
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!