adhsvc.dll

  • File Path: C:\Windows\system32\adhsvc.dll
  • Description: AD Harvest Sites and Subnets Service

Hashes

Type Hash
MD5 E1EAD4FAAB0CAB73E587B7A79B26E476
SHA1 D6C2E4CE7FD2CEE95D0FA73FA16D1E92F3E6D5F8
SHA256 171D58D46039D5F48DF2B859471E10B1E93E972AAF0FBE0D35ED950EEB998D20
SHA384 B14D1E3548468506EE6ED1AE316A63829D65C8F6F06802A42205196FF0049CAA6A213349EB46EC926DEC991EF13AC2D8
SHA512 D751D63A2675EDA697CD32619697C70C4318ACECB4C6BCE269DD7ECC3247D67445D5CF641F18399AF89A1F026740BECAC71BAD3B23109204492736D1E800682C
SSDEEP 1536:GyRl0GEmh+fb1ZFv8+ioUWvr9bvut+0jri+hYMHaaswRLRLq+hA+y:NNgb1rjioUGrxvy33i+XaXOLhq+hA+y
IMP AC321DC6B832EE82EAC4939D0FEE346F
PESHA1 1B5B4BCB4EC11CCC23CF26760DDAF97C7F74C58F
PE256 BC0DA353516A5EAE10AB0A3D023C911E865125ABE9B321D3BE11610EE461AD9E

DLL Exports:

Function Name Ordinal Type
SubServiceStop 3 Exported Function
SubServiceStart 2 Exported Function
SubServiceScmNotification 1 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 330000026551AE1BBD005CBFBD000000000265
  • Thumbprint: E168609353F30FF2373157B4EB8CD519D07A2BFF
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: adhsvc.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/70
  • VirusTotal Link: https://www.virustotal.com/gui/file/171d58d46039d5f48df2b859471e10b1e93e972aaf0fbe0d35ed950eeb998d20/detection/

MIT License. Copyright (c) 2020 Strontic.