× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: eaf7deaa83774d21df863b73cb9bca25b6e869a45d90af6a6912c8767ada4fb1
File name: System.Collections.Immutable.dll
Detection ratio: 0 / 70
Analysis date: 2019-02-06 07:42:01 UTC ( 1 week, 3 days ago )
Antivirus Result Update
Acronis 20190130
Ad-Aware 20190206
AegisLab 20190206
AhnLab-V3 20190206
Alibaba 20180921
ALYac 20190206
Antiy-AVL 20190206
Arcabit 20190206
Avast 20190206
Avast-Mobile 20190206
AVG 20190206
Avira (no cloud) 20190206
Babable 20180918
Baidu 20190202
BitDefender 20190206
Bkav 20190201
CAT-QuickHeal 20190205
ClamAV 20190205
CMC 20190206
Comodo 20190206
CrowdStrike Falcon (ML) 20181023
Cybereason 20190109
Cylance 20190206
Cyren 20190206
DrWeb 20190206
eGambit 20190206
Emsisoft 20190206
Endgame 20181108
ESET-NOD32 20190206
F-Prot 20190206
F-Secure 20190206
Fortinet 20190206
GData 20190206
Ikarus 20190206
Sophos ML 20181128
Jiangmin 20190206
K7AntiVirus 20190206
K7GW 20190206
Kaspersky 20190206
Kingsoft 20190206
Malwarebytes 20190206
MAX 20190206
McAfee 20190206
McAfee-GW-Edition 20190205
Microsoft 20190206
eScan 20190206
NANO-Antivirus 20190206
Palo Alto Networks (Known Signatures) 20190206
Panda 20190205
Qihoo-360 20190206
Rising 20190206
SentinelOne (Static ML) 20190203
Sophos AV 20190206
SUPERAntiSpyware 20190130
Symantec 20190206
TACHYON 20190206
Tencent 20190206
TheHacker 20190203
TotalDefense 20190206
Trapmine 20190123
TrendMicro 20190206
TrendMicro-HouseCall 20190206
Trustlook 20190206
VBA32 20190206
VIPRE 20190206
ViRobot 20190206
Webroot 20190206
Yandex 20190206
Zillya 20190206
ZoneAlarm by Check Point 20190206
Zoner 20190206
The file being studied is a Portable Executable file! More specifically, it is a Win32 DLL file for the Windows command line subsystem.
Authenticode signature block and FileVersionInfo properties
Copyright
© Microsoft Corporation. All rights reserved.

Product Microsoft® .NET Framework
Original name System.Collections.Immutable.dll
Internal name System.Collections.Immutable.dll
File version 4.6.26515.06
Description System.Collections.Immutable
Comments System.Collections.Immutable
Signature verification Signed file, verified signature
Signing date 9:23 PM 5/15/2018
Signers
[+] Microsoft Corporation
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer Microsoft Code Signing PCA
Valid from 07:11 PM 08/11/2017
Valid to 07:11 PM 08/11/2018
Valid usage Code Signing
Algorithm sha1RSA
Thumbprint 5EAD300DC7E4D637948ECB0ED829A072BD152E17
Serial number 33 00 00 01 79 7C 2E 57 4E 52 E1 CA D6 00 01 00 00 01 79
[+] Microsoft Code Signing PCA
Status Valid
Issuer Microsoft Root Certificate Authority
Valid from 09:19 PM 08/31/2010
Valid to 09:29 PM 08/31/2020
Valid usage All
Algorithm sha1RSA
Thumbprint 3CAF9BA2DB5570CAF76942FF99101B993888E257
Serial number 61 33 26 1A 00 00 00 00 00 31
[+] Microsoft Root Certificate Authority
Status Valid
Issuer Microsoft Root Certificate Authority
Valid from 10:19 PM 05/09/2001
Valid to 10:28 PM 05/09/2021
Valid usage All
Algorithm sha1RSA
Thumbprint CDD4EEAE6000AC7F40C3802C171E30148030C072
Serial number 79 AD 16 A1 4A A0 A5 AD 4C 73 58 F4 07 13 2E 65
Counter signers
[+] Microsoft Time-Stamp Service
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer Microsoft Time-Stamp PCA
Valid from 04:58 PM 09/07/2016
Valid to 04:58 PM 09/07/2018
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint ADAF9D0A7A966D2660393C06E5A3730A07D64073
Serial number 33 00 00 00 C0 DE 2C 3D 07 94 E4 49 79 00 00 00 00 00 C0
[+] Microsoft Time-Stamp PCA
Status Valid
Issuer Microsoft Root Certificate Authority
Valid from 11:53 AM 04/03/2007
Valid to 12:03 PM 04/03/2021
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 375FCB825C3DC3752A02E34EB70993B4997191EF
Serial number 61 16 68 34 00 00 00 00 00 1C
[+] Microsoft Root Certificate Authority
Status Valid
Issuer Microsoft Root Certificate Authority
Valid from 10:19 PM 05/09/2001
Valid to 10:28 PM 05/09/2021
Valid usage All
Algorithm sha1RSA
Thumbrint CDD4EEAE6000AC7F40C3802C171E30148030C072
Serial number 79 AD 16 A1 4A A0 A5 AD 4C 73 58 F4 07 13 2E 65
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2018-05-15 20:11:15
Entry Point 0x0002A12A
Number of sections 3
.NET details
Module Version ID 51326120-9989-400e-86af-cf4c12bf10a4
PE sections
Overlays
MD5 128c94db3c8e9500e22ed99971137706
File type data
Offset 342528
Size 16008
Entropy 7.43
PE imports
_CorDllMain
Number of PE resources by type
IBC 1
RT_VERSION 1
Number of PE resources by language
NEUTRAL 2
PE resources
Debug information
ExifTool file metadata
SubsystemVersion
4.0

Comments
System.Collections.Immutable

InitializedDataSize
177664

ImageVersion
0.0

ProductName
Microsoft .NET Framework

FileVersionNumber
4.6.26515.6

UninitializedDataSize
0

LanguageCode
Neutral

FileFlagsMask
0x003f

ImageFileCharacteristics
Executable, Large address aware, DLL

CharacterSet
Unicode

LinkerVersion
48.0

FileTypeExtension
dll

OriginalFileName
System.Collections.Immutable.dll

MIMEType
application/octet-stream

Subsystem
Windows command line

FileVersion
4.6.26515.06

TimeStamp
2018:05:15 22:11:15+02:00

FileType
Win32 DLL

PEType
PE32

InternalName
System.Collections.Immutable.dll

ProductVersion
4.6.26515.06 @BuiltBy: dlab-DDVSOWINAGE059 @Branch: release/2.1 @SrcCode: https://github.com/dotnet/corefx/tree/30ab651fcb4354552bd4891619a0bdd81e0ebdbf

FileDescription
System.Collections.Immutable

OSVersion
4.0

FileOS
Win32

LegalCopyright
Microsoft Corporation. All rights reserved.

MachineType
Intel 386 or later, and compatibles

CompanyName
Microsoft Corporation

CodeSize
164352

FileSubtype
0

ProductVersionNumber
0.0.0.0

EntryPoint
0x2a12a

ObjectFileType
Dynamic link library

AssemblyVersion
1.2.3.0

Execution parents
Compressed bundles
File identification
MD5 1e32ed5669aa93a15d436448b42ad89a
SHA1 bc9b160dbf908e7a1e198b132529ba53b2136c45
SHA256 eaf7deaa83774d21df863b73cb9bca25b6e869a45d90af6a6912c8767ada4fb1
ssdeep
6144:+QflKn7SBCpRp6Sx5NIzO+fMTnym5DSDt7+5g9RR0p:+QflRBCpRDHK1fqMD9nR0p

authentihash bb1459455287c145cb6a65191011afdc0acb45f5a6df28cbc1426939eb5cb3a6
imphash dae02f32a21e03ce65412f6e56942daa
File size 350.1 KB ( 358536 bytes )
File type Win32 DLL
Magic literal
PE32 executable for MS Windows (DLL) (console) Intel 80386 Mono/.Net assembly

TrID Win32 Dynamic Link Library (generic) (38.4%)
Win32 Executable (generic) (26.3%)
OS/2 Executable (generic) (11.8%)
Generic Win/DOS Executable (11.6%)
DOS Executable Generic (11.6%)
Tags
assembly pedll signed overlay

VirusTotal metadata
First submission 2018-07-11 22:30:09 UTC ( 7 months, 1 week ago )
Last submission 2018-07-11 22:30:09 UTC ( 7 months, 1 week ago )
File names System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
System.Collections.Immutable.dll
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!