DismCore.dll

  • File Path: C:\Windows\system32\Dism\DismCore.dll
  • Description: DISM Core Framework

Hashes

Type Hash
MD5 22C4F083F0D9625C3F9AA347A686C716
SHA1 0DDC1D61FDFBB2A3666FC9249B4DC45DDFFCD81E
SHA256 27DEC838BBECD60A94DA0D9B4F744F7DCDD78087A56540127EED01B5D2A1F400
SHA384 1CA0B5B038F6AB7EBA4C8046BEA44742D9A6DC85B56E88F4164036A8EE11C4CB1DA66349D52BD5D0518BCEFF10C64E0E
SHA512 453E89875FD5ADCE1CD769512C85A6C7EB0322036264AE74599412572A5BD359A1F12F7DC191B43B4AAD06D3505373DE2309521A0D3F0BA176F0DCD4FCF65FC7
SSDEEP 6144:WzcBsjan8DLp8+gFlPfnXqF3HR19n0bPnRKQoA:WzcBsx6+gFlHnGD9Wkk
IMP A55A338FA10D5AB8D8B5431B869ED4FE
PESHA1 922488F1EC5121983E73E2897D3D80940F6BFD79
PE256 124D0D85CCA28704AD562121F1014BD7DC3B6B13322B8BDA3F05BF17D79ADC34

DLL Exports:

Function Name Ordinal Type
DllRegisterServer 3 Exported Function
DllUnregisterServer 4 Exported Function
DllCanUnloadNow 1 Exported Function
DllGetClassObject 2 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 330000026551AE1BBD005CBFBD000000000265
  • Thumbprint: E168609353F30FF2373157B4EB8CD519D07A2BFF
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: DismCore.dll.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/68
  • VirusTotal Link: https://www.virustotal.com/gui/file/27dec838bbecd60a94da0d9b4f744f7dcdd78087a56540127eed01b5d2a1f400/detection/

Possible Misuse

The following table contains possible examples of DismCore.dll being misused. While DismCore.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_uac_bypass_via_dism.yml description: Attempts to load dismcore.dll after dropping it DRL 1.0
sigma image_load_uac_bypass_via_dism.yml - '\dismcore.dll' DRL 1.0
sigma image_load_uac_bypass_via_dism.yml - 'C:\Windows\System32\Dism\dismcore.dll' DRL 1.0
atomic-red-team T1548.002.md Component: DismCore.dll MIT License. © 2018 Red Canary

MIT License. Copyright (c) 2020-2021 Strontic.