× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 198da734d39900b07990bb9ed142f339b497db9634fd0aad2ecffb724aa6c4f6
File name: System.Core.dll
Detection ratio: 0 / 67
Analysis date: 2018-09-12 04:47:08 UTC ( 7 months, 2 weeks ago )
Antivirus Result Update
Ad-Aware 20180912
AegisLab 20180912
AhnLab-V3 20180911
Alibaba 20180713
ALYac 20180912
Antiy-AVL 20180912
Arcabit 20180912
Avast 20180912
Avast-Mobile 20180912
AVG 20180912
Avira (no cloud) 20180911
AVware 20180912
Babable 20180907
Baidu 20180910
BitDefender 20180912
Bkav 20180911
CAT-QuickHeal 20180909
ClamAV 20180912
CMC 20180912
Comodo 20180911
CrowdStrike Falcon (ML) 20180723
Cybereason 20180225
Cylance 20180912
Cyren 20180912
DrWeb 20180912
eGambit 20180912
Emsisoft 20180912
Endgame 20180730
ESET-NOD32 20180912
F-Prot 20180912
F-Secure 20180912
Fortinet 20180912
GData 20180912
Ikarus 20180911
Sophos ML 20180717
Jiangmin 20180911
K7AntiVirus 20180911
K7GW 20180912
Kaspersky 20180912
Kingsoft 20180912
Malwarebytes 20180912
MAX 20180912
McAfee 20180912
McAfee-GW-Edition 20180912
Microsoft 20180911
eScan 20180912
NANO-Antivirus 20180912
Palo Alto Networks (Known Signatures) 20180912
Panda 20180911
Qihoo-360 20180912
Rising 20180912
SentinelOne (Static ML) 20180830
Sophos AV 20180912
SUPERAntiSpyware 20180907
Symantec 20180911
Symantec Mobile Insight 20180911
TACHYON 20180912
Tencent 20180912
TheHacker 20180907
TotalDefense 20180911
TrendMicro 20180912
TrendMicro-HouseCall 20180912
Trustlook 20180912
VBA32 20180911
VIPRE 20180912
ViRobot 20180911
Webroot 20180912
Yandex 20180910
Zillya 20180911
ZoneAlarm by Check Point 20180912
Zoner 20180911
The file being studied is a Portable Executable file! More specifically, it is a Win32 DLL file.
Authenticode signature block and FileVersionInfo properties
Copyright
© Microsoft Corporation. All rights reserved.

Product Microsoft® .NET Framework
Original name System.Core.dll
Internal name System.Core.dll
File version 4.6.26515.6
Description .NET Framework
Comments Flavor=Retail
Signature verification Signed file, verified signature
Signing date 10:00 PM 5/15/2018
Signers
[+] Microsoft Corporation
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer Microsoft Code Signing PCA 2011
Valid from 9:20 PM 8/11/2017
Valid to 9:20 PM 8/11/2018
Valid usage Microsoft Publisher, Code Signing
Algorithm sha256RSA
Thumbprint 9ACA9419E53D3C9E56396DD2335FF683A8B0B8F3
Serial number 33 00 00 00 C4 E9 89 F8 7A 81 50 E9 FF 00 00 00 00 00 C4
[+] Microsoft Code Signing PCA 2011
Status Valid
Issuer Microsoft Root Certificate Authority 2011
Valid from 9:59 PM 7/8/2011
Valid to 10:09 PM 7/8/2026
Valid usage All
Algorithm sha256RSA
Thumbprint F252E794FE438E35ACE6E53762C0A234A2C52135
Serial number 61 0E 90 D2 00 00 00 00 00 03
[+] Microsoft Root Certificate Authority 2011
Status Valid
Issuer Microsoft Root Certificate Authority 2011
Valid from 11:05 PM 3/22/2011
Valid to 11:13 PM 3/22/2036
Valid usage All
Algorithm sha256RSA
Thumbprint 8F43288AD272F3103B6FB1428485EA3014C0BCFE
Serial number 3F 8B C8 B5 FC 9F B2 96 43 B5 69 D6 6C 42 E1 44
Counter signers
[+] Microsoft Time-Stamp Service
Status Valid
Issuer Microsoft Time-Stamp PCA 2010
Valid from 12:00 AM 10/3/2017
Valid to 12:00 AM 1/3/2019
Valid usage Timestamp Signing
Algorithm sha256RSA
Thumbrint D5E3D0FE5936E4C264594907E9D7228CC745EA0D
Serial number 33 00 00 00 B7 F8 22 14 7D 03 22 FE FA 00 00 00 00 00 B7
[+] Microsoft Time-Stamp PCA 2010
Status Valid
Issuer Microsoft Root Certificate Authority 2010
Valid from 10:36 PM 7/1/2010
Valid to 10:46 PM 7/1/2025
Valid usage All
Algorithm sha256RSA
Thumbrint 2AA752FE64C49ABE82913C463529CF10FF2F04EE
Serial number 61 09 81 2A 00 00 00 00 00 02
[+] Microsoft Root Certificate Authority 2010
Status Valid
Issuer Microsoft Root Certificate Authority 2010
Valid from 10:57 PM 6/23/2010
Valid to 11:04 PM 6/23/2035
Valid usage All
Algorithm sha256RSA
Thumbrint 3B1EFD3A66EA28B16697394703A72CA340A05BD5
Serial number 28 CC 3A 25 BF BA 44 AC 44 9A 9B 58 6B 43 39 AA
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2018-05-15 19:36:21
Number of sections 2
.NET details
Module Version ID 99d59ee6-aeaf-4d4b-9e9c-f1f533dd6884
PE sections
Overlays
MD5 ccad43dd2acba3d397045fb3dfdcd059
File type data
Offset 11776
Size 9176
Entropy 7.41
Number of PE resources by type
RT_VERSION 1
Number of PE resources by language
NEUTRAL 1
PE resources
Debug information
File identification
MD5 e8a8331c417a2a814805970d35401cf0
SHA1 cb5972626eeb8cbcfe7853877bce431f5794d83d
SHA256 198da734d39900b07990bb9ed142f339b497db9634fd0aad2ecffb724aa6c4f6
ssdeep
384:CQWrYWswGnAi1RaeLsB5P7n1dyVo1dppRycqEfa96FwOXCytEaQHRN7ZlJco/rl1:iZ7asB5P7n1dyVo1dppRycqEfhFwOXaV

authentihash 9ba5a4b2e3c31724ffec59682e0b161edda6d01e7552bbda31bee055ef33b845
File size 20.5 KB ( 20952 bytes )
File type Win32 DLL
Magic literal
PE32 executable for MS Windows (DLL) (console) Intel 80386 32-bit Mono/.Net assembly

TrID Win32 Executable (generic) (33.1%)
DOS Executable Borland Pascal 7.0x (14.9%)
OS/2 Executable (generic) (14.9%)
Generic Win/DOS Executable (14.7%)
DOS Executable Generic (14.7%)
Tags
assembly pedll signed overlay

VirusTotal metadata
First submission 2018-06-02 15:46:21 UTC ( 10 months, 3 weeks ago )
Last submission 2018-06-26 14:59:30 UTC ( 10 months ago )
File names e8a8331c417a2a814805970d35401cf0.virobj
System.Core.dll
System.Core.dll
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!