api-ms-win-core-libraryloader-l1-1-0.dll

  • File Path: C:\Program Files (x86)\Cisco Systems\Cisco Jabber\api-ms-win-core-libraryloader-l1-1-0.dll
  • Description: ApiSet Stub DLL

Hashes

Type Hash
MD5 8F239C629F09E1B49CF1F03304AB8E69
SHA1 D54DBE7E79A8389B3BAE3273487BC22D4B99781A
SHA256 D8D74FB87F94A587582D56934816362B992B712E47C39F13D957058F17724886
SHA384 EFC1B9DA7128836A45E22215C67894C1B6C53055F15239EB1406ED472C514C27D8F98005B3C6354382D52E7E800B2FD7
SHA512 130D1BB38C757BBCE7B3C558624028C771FA1198B8D02F0BE1F210A688E5779F8FCBB44154678E898D6FBA4EC31D03664CC84D063816E977361D4ECABAD7911E
SSDEEP 384:tZvuBL3BmWlhWraCIcPA0GftpBjbkvg6klC0D0N:tABL3BdAiJCgG0D8
PESHA1 12CDE9077DA707C8C8263DBBE49429BA6C0E6E89
PE256 3A87C772D95B7333A3C177CC6CD5102CBFA3D18B9C39FFA4C38FA7527F31E034

DLL Exports:

Function Name Ordinal Type
GetModuleHandleW 12 Exported Function
GetProcAddress 13 Exported Function
GetModuleHandleExA 10 Exported Function
GetModuleHandleExW 11 Exported Function
LoadLibraryExA 14 Exported Function
LockResource 17 Exported Function
SizeofResource 18 Exported Function
LoadLibraryExW 15 Exported Function
LoadResource 16 Exported Function
FindStringOrdinal 3 Exported Function
FreeLibrary 4 Exported Function
DisableThreadLibraryCalls 1 Exported Function
FindResourceExW 2 Exported Function
FreeLibraryAndExitThread 5 Exported Function
GetModuleFileNameW 8 Exported Function
GetModuleHandleA 9 Exported Function
FreeResource 6 Exported Function
GetModuleFileNameA 7 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 330000010A2C79AED7797BA6AC00010000010A
  • Thumbprint: 3BDA323E552DB1FDE5F4FBEE75D6D5B2B187EEDC
  • Issuer: CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: apisetstub
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.14393.33 (rs1_release_sec.160727-1952)
  • Product Version: 10.0.14393.33
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/68
  • VirusTotal Link: https://www.virustotal.com/gui/file/d8d74fb87f94a587582d56934816362b992b712e47c39f13d957058f17724886/detection/

File Similarity (ssdeep match)

File Score
C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\agcp.exe 35
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Microsoft.VisualC.dll 30
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x64\Microsoft.Azure.KeyVault.Core.dll 36
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x64\Microsoft.WindowsAzure.Configuration.dll 27
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x86\Microsoft.Azure.KeyVault.Core.dll 36
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x86\Microsoft.WindowsAzure.Configuration.dll 27
C:\Program Files\Microsoft Silverlight\5.1.50918.0\agcp.exe 33
C:\WINDOWS\system32\microsoft.windows.softwarelogo.showdesktop.exe 35
C:\Windows\system32\mrt_map.dll 29
C:\Windows\system32\mrt100.dll 32
C:\WINDOWS\system32\TsWpfWrp.exe 27
C:\Windows\system32\TsWpfWrp.exe 32
C:\Windows\SysWOW64\mrt_map.dll 27
C:\Windows\SysWOW64\mrt100.dll 24
C:\WINDOWS\SysWOW64\TsWpfWrp.exe 30
C:\Windows\SysWOW64\TsWpfWrp.exe 29

MIT License. Copyright (c) 2020-2021 Strontic.