× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: f9a927463822c69bbfd8c8e0d28ecca8891a3ad63052ccabe089c5a4aa7c8019
File name: System.Runtime.Loader.dll
Detection ratio: 0 / 66
Analysis date: 2019-04-11 19:31:46 UTC ( 1 week, 2 days ago )
Trusted source! This file belongs to the Microsoft Corporation software catalogue.
Antivirus Result Update
ALYac 20190411
AVG 20190411
Acronis 20190409
Ad-Aware 20190411
AegisLab 20190411
AhnLab-V3 20190411
Alibaba 20190402
Antiy-AVL 20190411
Arcabit 20190411
Avast 20190411
Avast-Mobile 20190411
Avira (no cloud) 20190411
Babable 20180918
Baidu 20190318
BitDefender 20190411
Bkav 20190410
CAT-QuickHeal 20190411
CMC 20190321
ClamAV 20190411
Comodo 20190411
CrowdStrike Falcon (ML) 20190212
Cyren 20190411
DrWeb 20190411
ESET-NOD32 20190411
Emsisoft 20190411
Endgame 20190403
F-Secure 20190411
FireEye 20190411
Fortinet 20190411
GData 20190411
Ikarus 20190411
Sophos ML 20190313
Jiangmin 20190411
K7AntiVirus 20190411
K7GW 20190411
Kaspersky 20190411
Kingsoft 20190411
MAX 20190411
Malwarebytes 20190411
McAfee 20190411
McAfee-GW-Edition 20190411
eScan 20190411
Microsoft 20190411
NANO-Antivirus 20190411
Palo Alto Networks (Known Signatures) 20190411
Panda 20190411
Qihoo-360 20190411
Rising 20190411
SUPERAntiSpyware 20190410
SentinelOne (Static ML) 20190407
Sophos AV 20190411
TACHYON 20190411
Tencent 20190411
TheHacker 20190411
TotalDefense 20190411
Trapmine 20190325
TrendMicro-HouseCall 20190411
Trustlook 20190411
VBA32 20190411
VIPRE 20190411
ViRobot 20190411
Yandex 20190411
Zillya 20190410
ZoneAlarm by Check Point 20190411
Zoner 20190411
eGambit 20190411
Cybereason 20190403
Symantec Mobile Insight 20190410
The file being studied is a Portable Executable file! More specifically, it is a Win32 DLL file.
Authenticode signature block and FileVersionInfo properties
Copyright
© Microsoft Corporation. All rights reserved.

Product Microsoft® .NET Framework
Original name System.Runtime.Loader.dll
Internal name System.Runtime.Loader.dll
File version 4.6.25519.03
Description System.Runtime.Loader
Comments System.Runtime.Loader
Signature verification Signed file, verified signature
Signing date 1:20 AM 7/21/2017
Signers
[+] Microsoft Corporation
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer Microsoft Code Signing PCA 2011
Valid from 11:09 PM 11/17/2016
Valid to 11:09 PM 02/17/2018
Valid usage Microsoft Publisher, Code Signing
Algorithm sha256RSA
Thumbprint B9EAA034C821C159B05D3521BCF7FEB796EBD6FF
Serial number 33 00 00 00 8E 87 91 A4 57 1A 5F CA 3E 00 00 00 00 00 8E
[+] Microsoft Code Signing PCA 2011
Status Valid
Issuer Microsoft Root Certificate Authority 2011
Valid from 08:59 PM 07/08/2011
Valid to 09:09 PM 07/08/2026
Valid usage All
Algorithm sha256RSA
Thumbprint F252E794FE438E35ACE6E53762C0A234A2C52135
Serial number 61 0E 90 D2 00 00 00 00 00 03
[+] Microsoft Root Certificate Authority 2011
Status Valid
Issuer Microsoft Root Certificate Authority 2011
Valid from 11:05 PM 03/22/2011
Valid to 11:13 PM 03/22/2036
Valid usage All
Algorithm sha256RSA
Thumbprint 8F43288AD272F3103B6FB1428485EA3014C0BCFE
Serial number 3F 8B C8 B5 FC 9F B2 96 43 B5 69 D6 6C 42 E1 44
Counter signers
[+] Microsoft Time-Stamp Service
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer Microsoft Time-Stamp PCA 2010
Valid from 05:56 PM 09/07/2016
Valid to 05:56 PM 09/07/2018
Valid usage Timestamp Signing
Algorithm sha256RSA
Thumbrint BDFFC5956390F1139C60D619C0AFE9B89E1E201D
Serial number 33 00 00 00 B2 35 05 68 37 22 1C 0D A7 00 00 00 00 00 B2
[+] Microsoft Time-Stamp PCA 2010
Status Valid
Issuer Microsoft Root Certificate Authority 2010
Valid from 09:36 PM 07/01/2010
Valid to 09:46 PM 07/01/2025
Valid usage All
Algorithm sha256RSA
Thumbrint 2AA752FE64C49ABE82913C463529CF10FF2F04EE
Serial number 61 09 81 2A 00 00 00 00 00 02
[+] Microsoft Root Certificate Authority 2010
Status Valid
Issuer Microsoft Root Certificate Authority 2010
Valid from 09:57 PM 06/23/2010
Valid to 10:04 PM 06/23/2035
Valid usage All
Algorithm sha256RSA
Thumbrint 3B1EFD3A66EA28B16697394703A72CA340A05BD5
Serial number 28 CC 3A 25 BF BA 44 AC 44 9A 9B 58 6B 43 39 AA
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2017-07-19 16:39:06
Number of sections 2
.NET details
Module Version ID 8d5bc07a-f7e0-4211-b09d-b4967afc3c3a
PE sections
Overlays
MD5 ae479005740770bf2cc8d5069d57af75
File type data
Offset 5120
Size 9232
Entropy 7.39
Number of PE resources by type
RT_VERSION 1
Number of PE resources by language
NEUTRAL 1
PE resources
Debug information
Compressed bundles
File identification
MD5 6baa1d66a5811b4bd0e520f94f5d6b19
SHA1 7ecb5ad2ce9bed4deedb1767bbb594a44adb086d
SHA256 f9a927463822c69bbfd8c8e0d28ecca8891a3ad63052ccabe089c5a4aa7c8019
ssdeep
192:KjsWXLIWBIdxEtxsai5FWlY7ws64bHnhWgN7acWn5qnajnp+MVc1qdy:KjsWbIW2ks95ixT4bHRN7EldBc1My

authentihash e201c95129d3a5855e29bd226a21e27778763041110112420c5d256e6b737c8f
File size 14.0 KB ( 14352 bytes )
File type Win32 DLL
Magic literal
PE32 executable for MS Windows (DLL) (console) Intel 80386 32-bit Mono/.Net assembly

TrID Win32 Executable (generic) (33.1%)
DOS Executable Borland Pascal 7.0x (14.9%)
OS/2 Executable (generic) (14.9%)
Generic Win/DOS Executable (14.7%)
DOS Executable Generic (14.7%)
Tags
pedll assembly signed trusted overlay

Trusted verdicts
This file belongs to the Microsoft Corporation software catalogue. The file is often found with fil2D666D23BA00E4275E9150A61BAC03D4 as its name.
VirusTotal metadata
First submission 2017-08-15 05:49:13 UTC ( 1 year, 8 months ago )
Last submission 2019-04-11 19:31:46 UTC ( 1 week, 2 days ago )
File names filBA5BDE93E528FF9139422D3B1316BF57
System.Runtime.Loader.dll
System.Runtime.Loader.dll
fil44E82CCF3F41FD3A7A1B5769649399A6
DotNetCoreAgentApp.System.Runtime.Loader.dll
fil2D666D23BA00E4275E9150A61BAC03D4
filE80F2EE3FC132DD37344049C1D7B670F
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!