api-ms-win-core-memory-l1-1-0.dll

  • File Path: C:\Program Files (x86)\Cisco Systems\Cisco Jabber\api-ms-win-core-memory-l1-1-0.dll
  • Description: ApiSet Stub DLL

Hashes

Type Hash
MD5 536F07C04C316AAC61AB64A492ED9191
SHA1 0A2F45D0BA54C4FB5DECBB111BBCC9088FC3269E
SHA256 50BF87DA10AE3F442C457E42D6666993B0FCA7C5D4DF521E8CD0959995FBCDDC
SHA384 FCF8E3C077F5DC3BAA2626A2A2A73912BEB6F6EC3389C0061329CB94BDF6738F38868D5729B097E595B0A1813A67052B
SHA512 B0EC28B75761494A6121C56811DABC297B8E1EA1D56EE4B06A4488D36C16BD26015F2CE945BF9F74B455864828D321AF5DD8B66F839A047458A98984B9343819
SSDEEP 192:w4ZW2ubhWyILG9YOCAs/nGfe4pBjS7EPzXV/ACWYyieHaVWQ4SWLWqnajYONGrTN:7ZWlhWPJA0GftpBjpPzXVY4g64WlfgfN
IMP n/a
PESHA1 C7F7B71C3DE1BD3D9C89864ECBF1B7D0E229AEC4
PE256 7E7EBB8940889A56307035AB77DC1875CE0F3F42B1492A9A8F87D8402EDCC6C2

DLL Exports:

Function Name Ordinal Type
VirtualFreeEx 11 Exported Function
VirtualProtect 12 Exported Function
VirtualAllocEx 9 Exported Function
VirtualFree 10 Exported Function
VirtualQueryEx 15 Exported Function
WriteProcessMemory 16 Exported Function
VirtualProtectEx 13 Exported Function
VirtualQuery 14 Exported Function
MapViewOfFile 3 Exported Function
MapViewOfFileEx 4 Exported Function
CreateFileMappingW 1 Exported Function
FlushViewOfFile 2 Exported Function
UnmapViewOfFile 7 Exported Function
VirtualAlloc 8 Exported Function
OpenFileMappingW 5 Exported Function
ReadProcessMemory 6 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 330000010A2C79AED7797BA6AC00010000010A
  • Thumbprint: 3BDA323E552DB1FDE5F4FBEE75D6D5B2B187EEDC
  • Issuer: CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: apisetstub
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.14393.33 (rs1_release_sec.160727-1952)
  • Product Version: 10.0.14393.33
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/69
  • VirusTotal Link: https://www.virustotal.com/gui/file/50bf87da10ae3f442c457e42d6666993b0fca7c5d4df521e8cd0959995fbcddc/detection/

File Similarity (ssdeep match)

File Score
C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\agcp.exe 35
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Microsoft.VisualC.dll 33
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x64\Microsoft.Azure.KeyVault.Core.dll 36
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x64\Microsoft.WindowsAzure.Configuration.dll 27
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x86\Microsoft.Azure.KeyVault.Core.dll 36
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x86\Microsoft.WindowsAzure.Configuration.dll 27
C:\Program Files\Microsoft Silverlight\5.1.50918.0\agcp.exe 36
C:\ProgramData\Microsoft\VisualStudioSecondaryInstaller\14.0\installers\VSUV1PreReqV1_Hidden\en\0\VSUPrereq.exe 41
C:\WINDOWS\system32\microsoft.windows.softwarelogo.showdesktop.exe 35
C:\Windows\system32\mrt_map.dll 25
C:\Windows\system32\mrt100.dll 29
C:\WINDOWS\system32\TsWpfWrp.exe 30
C:\Windows\system32\TsWpfWrp.exe 32
C:\Windows\SysWOW64\mrt_map.dll 24
C:\Windows\SysWOW64\mrt100.dll 25
C:\WINDOWS\SysWOW64\TsWpfWrp.exe 29
C:\Windows\SysWOW64\TsWpfWrp.exe 27

MIT License. Copyright (c) 2020 Strontic.