× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 44bd19ae3300762ef8101756450446a1536caced6721e66072487b15e820f56b
File name: SOS.NETCore.dll
Detection ratio: 0 / 68
Analysis date: 2019-02-14 01:09:53 UTC ( 2 months ago )
Antivirus Result Update
Acronis 20190213
Ad-Aware 20190214
AegisLab 20190214
AhnLab-V3 20190213
Alibaba 20180921
ALYac 20190214
Antiy-AVL 20190213
Arcabit 20190213
Avast 20190213
Avast-Mobile 20190213
AVG 20190213
Avira (no cloud) 20190214
Babable 20180918
Baidu 20190202
BitDefender 20190213
Bkav 20190213
CAT-QuickHeal 20190213
ClamAV 20190213
CMC 20190213
Comodo 20190213
CrowdStrike Falcon (ML) 20181023
Cybereason 20190109
Cylance 20190214
Cyren 20190213
DrWeb 20190214
eGambit 20190214
Emsisoft 20190214
Endgame 20181108
ESET-NOD32 20190214
F-Prot 20190213
F-Secure 20190214
Fortinet 20190213
GData 20190214
Ikarus 20190213
Sophos ML 20181128
Jiangmin 20190214
K7AntiVirus 20190213
K7GW 20190213
Kaspersky 20190213
Kingsoft 20190214
Malwarebytes 20190213
MAX 20190214
McAfee 20190214
McAfee-GW-Edition 20190213
Microsoft 20190214
eScan 20190213
NANO-Antivirus 20190213
Palo Alto Networks (Known Signatures) 20190214
Panda 20190213
Qihoo-360 20190214
Rising 20190213
SentinelOne (Static ML) 20190203
Sophos AV 20190214
SUPERAntiSpyware 20190213
Symantec 20190213
Symantec Mobile Insight 20190207
TACHYON 20190213
Tencent 20190214
TheHacker 20190212
TotalDefense 20190213
Trapmine 20190123
TrendMicro 20190214
TrendMicro-HouseCall 20190214
Trustlook 20190214
VBA32 20190213
ViRobot 20190213
Webroot 20190214
Yandex 20190213
Zillya 20190213
ZoneAlarm by Check Point 20190213
Zoner 20190214
The file being studied is a Portable Executable file! More specifically, it is a Win32 DLL file.
Authenticode signature block and FileVersionInfo properties
Copyright
© Microsoft Corporation. All rights reserved.

Product Microsoft® .NET Framework
Original name SOS.NETCore.dll
Internal name SOS.NETCore.dll
File version 4.6.26515.07
Description SOS.NETCore
Comments SOS.NETCore
Signature verification Signed file, verified signature
Signing date 10:00 PM 5/15/2018
Signers
[+] Microsoft Corporation
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer Microsoft Code Signing PCA 2011
Valid from 07:20 PM 08/11/2017
Valid to 07:20 PM 08/11/2018
Valid usage Microsoft Publisher, Code Signing
Algorithm sha256RSA
Thumbprint 9ACA9419E53D3C9E56396DD2335FF683A8B0B8F3
Serial number 33 00 00 00 C4 E9 89 F8 7A 81 50 E9 FF 00 00 00 00 00 C4
[+] Microsoft Code Signing PCA 2011
Status Valid
Issuer Microsoft Root Certificate Authority 2011
Valid from 07:59 PM 07/08/2011
Valid to 08:09 PM 07/08/2026
Valid usage All
Algorithm sha256RSA
Thumbprint F252E794FE438E35ACE6E53762C0A234A2C52135
Serial number 61 0E 90 D2 00 00 00 00 00 03
[+] Microsoft Root Certificate Authority 2011
Status Valid
Issuer Microsoft Root Certificate Authority 2011
Valid from 10:05 PM 03/22/2011
Valid to 10:13 PM 03/22/2036
Valid usage All
Algorithm sha256RSA
Thumbprint 8F43288AD272F3103B6FB1428485EA3014C0BCFE
Serial number 3F 8B C8 B5 FC 9F B2 96 43 B5 69 D6 6C 42 E1 44
Counter signers
[+] Microsoft Time-Stamp Service
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer Microsoft Time-Stamp PCA 2010
Valid from 04:56 PM 09/07/2016
Valid to 04:56 PM 09/07/2018
Valid usage Timestamp Signing
Algorithm sha256RSA
Thumbrint 9C18E61ADF1B0388175D1CC6C72C4B9AAFE130D9
Serial number 33 00 00 00 AD 80 23 37 65 C4 5A 23 6A 00 00 00 00 00 AD
[+] Microsoft Time-Stamp PCA 2010
Status Valid
Issuer Microsoft Root Certificate Authority 2010
Valid from 08:36 PM 07/01/2010
Valid to 08:46 PM 07/01/2025
Valid usage All
Algorithm sha256RSA
Thumbrint 2AA752FE64C49ABE82913C463529CF10FF2F04EE
Serial number 61 09 81 2A 00 00 00 00 00 02
[+] Microsoft Root Certificate Authority 2010
Status Valid
Issuer Microsoft Root Certificate Authority 2010
Valid from 08:57 PM 06/23/2010
Valid to 09:04 PM 06/23/2035
Valid usage All
Algorithm sha256RSA
Thumbrint 3B1EFD3A66EA28B16697394703A72CA340A05BD5
Serial number 28 CC 3A 25 BF BA 44 AC 44 9A 9B 58 6B 43 39 AA
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2018-05-15 17:53:27
Number of sections 3
.NET details
Module Version ID dc3e3b0e-c990-4c91-b9cc-255e300ddd72
PE sections
Overlays
MD5 2a907daa7cd864d05bff1a702d94c8cc
File type data
Offset 41984
Size 9176
Entropy 7.40
Number of PE resources by type
RT_VERSION 1
Number of PE resources by language
NEUTRAL 1
PE resources
Debug information
File identification
MD5 41993572391c9b66197823de9d90b173
SHA1 cbd9a1b0ffe972d4df6375de8189326e12a2cdbb
SHA256 44bd19ae3300762ef8101756450446a1536caced6721e66072487b15e820f56b
ssdeep
768:5DhBJeKQVsWen7R+6w81ZyKSrYNrSMum23ond4ctFz4ELL5SRax2L9BE:5DhBJVQU7R+VW9rvunYnttuEHAROsA

authentihash 754704a4dc4eb908064b4e4235f41d86078cc2d5aeb95fb83f2090cae99dc0fd
File size 50.0 KB ( 51160 bytes )
File type Win32 DLL
Magic literal
PE32 executable for MS Windows (DLL) (console) Intel 80386 32-bit Mono/.Net assembly

TrID Win32 Executable (generic) (33.1%)
DOS Executable Borland Pascal 7.0x (14.9%)
OS/2 Executable (generic) (14.9%)
Generic Win/DOS Executable (14.7%)
DOS Executable Generic (14.7%)
Tags
assembly pedll signed overlay

VirusTotal metadata
First submission 2018-06-02 15:38:01 UTC ( 10 months, 3 weeks ago )
Last submission 2018-06-02 15:38:01 UTC ( 10 months, 3 weeks ago )
File names SOS.NETCore.dll
SOS.NETCore.dll
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!