dllhost.exe

  • File Path: C:\Windows\system32\dllhost.exe
  • Description: COM Surrogate

Hashes

Type Hash
MD5 C6723950D1A8CD49D93C8D082B175D41
SHA1 45E05A31CBAE71818816EC86AA6152F6D8C22E8C
SHA256 FFBFD4EA38939327584779F31F46CC8A8AFA0AD03A783A35D1C166C335E7B910
SHA384 4189FB4C78239045790FF7D036AC4C24153FA2D73EB3CBA043FE31E60184188D13AF26F8A6981F2836B278DE26A7CBD7
SHA512 EC559A2A244731CEAF10E39F7A2958FDB3500C95F9F196C644DA2CBB47135A50BCB8ACEAC559B11C9F23E085EB5EC9471A4B60E47D9470E5DAAAE1BB9D5A91C0
SSDEEP 384:Z7JRXcksOlcUcZlHWg5WiD1IDBRJJAZhKtklxt:Z7JR7WUcZlDdI1Pe
IMP CF79FCE90FCED31836373F3E48251A5D
PESHA1 62F9327ACA455C1A97198A5147BB71FD86E6610A
PE256 835786C42D11C2851B84210B81B966AD5B49E6E01CFB82FDB3B3F8AC304FA744

Runtime Data

Loaded Modules:

Path
C:\Windows\System32\combase.dll
C:\Windows\system32\dllhost.exe
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\ucrtbase.dll

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: dllhost.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/69
  • VirusTotal Link: https://www.virustotal.com/gui/file/ffbfd4ea38939327584779f31f46cc8a8afa0ad03a783a35d1c166c335e7b910/detection/

File Similarity (ssdeep match)

File Score
C:\Program Files (x86)\Common Files\Microsoft Shared\ink\TabTip32.exe 38
C:\Program Files (x86)\Windows Kits\10\Redist\10.0.19041.0\ucrt\DLLs\x64\api-ms-win-core-localization-l1-2-0.dll 27
C:\Program Files (x86)\Windows Kits\10\Redist\10.0.19041.0\ucrt\DLLs\x64\api-ms-win-core-timezone-l1-1-0.dll 35
C:\Program Files (x86)\Windows Kits\10\Redist\10.0.19041.0\ucrt\DLLs\x86\api-ms-win-core-sysinfo-l1-1-0.dll 36
C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\api-ms-win-core-console-l1-2-0.dll 35
C:\Windows\system32\69fe178f-26e7-43a9-aa7d-2b616b672dde_eventlogservice.dll 38
C:\Windows\system32\AppVClientPS.dll 33
C:\Windows\system32\AppVSentinel.dll 44
C:\Windows\system32\AppVTerminator.dll 35
C:\Windows\system32\avrt.dll 35
C:\Windows\system32\backgroundTaskHost.exe 38
C:\Windows\system32\bootstr.dll 40
C:\Windows\system32\BOOTVID.DLL 33
C:\Windows\system32\computelibeventlog.dll 32
C:\Windows\system32\DefaultDeviceManager.dll 33
C:\Windows\system32\DeviceCensus.exe 33
C:\WINDOWS\system32\DeviceCensus.exe 30
C:\Windows\system32\dllhost.exe 44
C:\Windows\system32\dllhst3g.exe 41
C:\Windows\system32\downlevel\api-ms-win-base-util-l1-1-0.dll 38
C:\Windows\system32\downlevel\api-ms-win-core-com-l1-1-0.dll 55
C:\Windows\system32\downlevel\api-ms-win-core-comm-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-core-console-l1-1-0.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-datetime-l1-1-0.dll 38
C:\Windows\system32\downlevel\api-ms-win-core-datetime-l1-1-1.dll 38
C:\Windows\system32\downlevel\api-ms-win-core-debug-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-core-debug-l1-1-1.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-delayload-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-core-errorhandling-l1-1-0.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-errorhandling-l1-1-1.dll 36
C:\Windows\system32\downlevel\api-ms-win-core-fibers-l1-1-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-fibers-l1-1-1.dll 38
C:\Windows\system32\downlevel\api-ms-win-core-file-l1-1-0.dll 40
C:\Windows\system32\downlevel\api-ms-win-core-file-l1-2-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-file-l1-2-1.dll 44
C:\Windows\system32\downlevel\API-MS-Win-core-file-l2-1-0.dll 40
C:\Windows\system32\downlevel\API-MS-Win-core-file-l2-1-1.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-handle-l1-1-0.dll 38
C:\Windows\system32\downlevel\api-ms-win-core-heap-l1-1-0.dll 41
C:\Windows\system32\downlevel\API-MS-Win-Core-Heap-Obsolete-L1-1-0.dll 40
C:\Windows\system32\downlevel\api-ms-win-core-interlocked-l1-1-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-core-io-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-core-io-l1-1-1.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-kernel32-legacy-l1-1-0.dll 35
C:\Windows\system32\downlevel\api-ms-win-core-kernel32-legacy-l1-1-1.dll 44
C:\Windows\system32\downlevel\API-MS-Win-Core-Kernel32-Private-L1-1-0.dll 38
C:\Windows\system32\downlevel\API-MS-Win-Core-Kernel32-Private-L1-1-1.dll 35
C:\Windows\system32\downlevel\api-ms-win-core-libraryloader-l1-1-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-libraryloader-l1-1-1.dll 55
C:\Windows\system32\downlevel\api-ms-win-core-localization-l1-2-0.dll 33
C:\Windows\system32\downlevel\api-ms-win-core-localization-l1-2-1.dll 41
C:\Windows\system32\downlevel\API-MS-Win-core-localization-obsolete-l1-2-0.dll 40
C:\Windows\system32\downlevel\api-ms-win-core-memory-l1-1-0.dll 36
C:\Windows\system32\downlevel\api-ms-win-core-memory-l1-1-1.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-memory-l1-1-2.dll 40
C:\Windows\system32\downlevel\api-ms-win-core-namedpipe-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-core-privateprofile-l1-1-0.dll 36
C:\Windows\system32\downlevel\api-ms-win-core-privateprofile-l1-1-1.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-processenvironment-l1-1-0.dll 55
C:\Windows\system32\downlevel\api-ms-win-core-processenvironment-l1-2-0.dll 38
C:\Windows\system32\downlevel\api-ms-win-core-processthreads-l1-1-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-processthreads-l1-1-1.dll 57
C:\Windows\system32\downlevel\api-ms-win-core-processthreads-l1-1-2.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-processtopology-obsolete-l1-1-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-core-profile-l1-1-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-realtime-l1-1-0.dll 40
C:\Windows\system32\downlevel\api-ms-win-core-registry-l1-1-0.dll 40
C:\Windows\system32\downlevel\api-ms-win-core-registry-l2-1-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-rtlsupport-l1-1-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-shlwapi-legacy-l1-1-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-shlwapi-obsolete-l1-1-0.dll 32
C:\Windows\system32\downlevel\api-ms-win-core-shutdown-l1-1-0.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-stringansi-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-core-string-l1-1-0.dll 36
C:\Windows\system32\downlevel\API-MS-Win-core-string-l2-1-0.dll 40
C:\Windows\system32\downlevel\api-ms-win-core-stringloader-l1-1-1.dll 38
C:\Windows\system32\downlevel\API-MS-Win-core-string-obsolete-l1-1-0.dll 36
C:\Windows\system32\downlevel\api-ms-win-core-synch-l1-1-0.dll 35
C:\Windows\system32\downlevel\api-ms-win-core-synch-l1-2-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-sysinfo-l1-1-0.dll 38
C:\Windows\system32\downlevel\api-ms-win-core-sysinfo-l1-2-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-sysinfo-l1-2-1.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-threadpool-l1-2-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-core-threadpool-legacy-l1-1-0.dll 35
C:\Windows\system32\downlevel\api-ms-win-core-threadpool-private-l1-1-0.dll 36
C:\Windows\system32\downlevel\api-ms-win-core-timezone-l1-1-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-core-url-l1-1-0.dll 40
C:\Windows\system32\downlevel\api-ms-win-core-util-l1-1-0.dll 38
C:\Windows\system32\downlevel\api-ms-win-core-version-l1-1-0.dll 47
C:\Windows\system32\downlevel\api-ms-win-core-wow64-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-core-xstate-l1-1-0.dll 38
C:\Windows\system32\downlevel\API-MS-Win-core-xstate-l2-1-0.dll 40
C:\Windows\system32\downlevel\api-ms-win-crt-conio-l1-1-0.dll 36
C:\Windows\system32\downlevel\api-ms-win-crt-convert-l1-1-0.dll 33
C:\Windows\system32\downlevel\api-ms-win-crt-environment-l1-1-0.dll 44
C:\Windows\system32\downlevel\api-ms-win-crt-filesystem-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-crt-heap-l1-1-0.dll 40
C:\Windows\system32\downlevel\api-ms-win-crt-locale-l1-1-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-crt-math-l1-1-0.dll 40
C:\Windows\system32\downlevel\api-ms-win-crt-multibyte-l1-1-0.dll 32
C:\Windows\system32\downlevel\api-ms-win-crt-process-l1-1-0.dll 44
C:\Windows\system32\downlevel\api-ms-win-crt-runtime-l1-1-0.dll 44
C:\Windows\system32\downlevel\api-ms-win-crt-stdio-l1-1-0.dll 36
C:\Windows\system32\downlevel\api-ms-win-crt-string-l1-1-0.dll 32
C:\Windows\system32\downlevel\api-ms-win-crt-time-l1-1-0.dll 40
C:\Windows\system32\downlevel\api-ms-win-crt-utility-l1-1-0.dll 36
C:\Windows\system32\downlevel\API-MS-Win-devices-config-L1-1-0.dll 41
C:\Windows\system32\downlevel\API-MS-Win-devices-config-L1-1-1.dll 44
C:\Windows\system32\downlevel\API-MS-Win-Eventing-ClassicProvider-L1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-eventing-consumer-l1-1-0.dll 35
C:\Windows\system32\downlevel\API-MS-Win-Eventing-Controller-L1-1-0.dll 49
C:\Windows\system32\downlevel\API-MS-Win-Eventing-Legacy-L1-1-0.dll 41
C:\Windows\system32\downlevel\API-MS-Win-Eventing-Provider-L1-1-0.dll 35
C:\Windows\system32\downlevel\API-MS-Win-EventLog-Legacy-L1-1-0.dll 35
C:\Windows\system32\downlevel\api-ms-win-security-base-l1-1-0.dll 40
C:\Windows\system32\downlevel\api-ms-win-security-cryptoapi-l1-1-0.dll 44
C:\Windows\system32\downlevel\API-MS-Win-Security-Lsalookup-L2-1-0.dll 38
C:\Windows\system32\downlevel\API-MS-Win-Security-Lsalookup-L2-1-1.dll 41
C:\Windows\system32\downlevel\API-MS-Win-security-lsapolicy-l1-1-0.dll 43
C:\Windows\system32\downlevel\API-MS-Win-security-provider-L1-1-0.dll 36
C:\Windows\system32\downlevel\api-ms-win-security-sddl-l1-1-0.dll 47
C:\Windows\system32\downlevel\api-ms-win-service-core-l1-1-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-service-core-l1-1-1.dll 44
C:\Windows\system32\downlevel\api-ms-win-service-management-l1-1-0.dll 38
C:\Windows\system32\downlevel\api-ms-win-service-management-l2-1-0.dll 38
C:\Windows\system32\downlevel\api-ms-win-service-private-l1-1-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-service-private-l1-1-1.dll 41
C:\Windows\system32\downlevel\api-ms-win-service-winsvc-l1-1-0.dll 36
C:\Windows\system32\downlevel\api-ms-win-shcore-stream-l1-1-0.dll 41
C:\Windows\system32\drivers\UMDF\SDFLauncher.dll 43
C:\Windows\system32\DriverStore\FileRepository\sdflauncher.inf_amd64_1ea082c6cf8f6982\SDFLauncher.dll 43
C:\Windows\system32\dsrole.dll 32
C:\Windows\system32\IME\IMETC\IMTCTRLN.DLL 27
C:\Windows\system32\IME\SHARED\IMEDICAPICCPS.DLL 33
C:\Windows\system32\IME\SHARED\IMESEARCHPS.DLL 36
C:\Windows\system32\kd.dll 43
C:\Windows\system32\kd_02_1af4.dll 36
C:\Windows\system32\kd_07_1415.dll 38
C:\Windows\system32\kdnet_uart16550.dll 36
C:\Windows\system32\kdstub.dll 40
C:\Windows\system32\ksuser.dll 36
C:\Windows\system32\microsoft-windows-battery-events.dll 36
C:\Windows\system32\microsoft-windows-hal-events.dll 35
C:\Windows\system32\microsoft-windows-sleepstudy-events.dll 36
C:\Windows\system32\msdmo.dll 27
C:\Windows\system32\NDKPing.exe 43
C:\Windows\system32\oobe\FirstLogonAnim.exe 36
C:\Windows\system32\pcwum.dll 33
C:\Windows\system32\prproc.exe 40
C:\Windows\system32\psapi.dll 35
C:\Windows\system32\ResetEngine.exe 33
C:\WINDOWS\system32\ResetEngine.exe 35
C:\WINDOWS\system32\ScriptRunner.exe 36
C:\Windows\system32\setupetw.dll 32
C:\Windows\system32\sfc.dll 41
C:\Windows\system32\SlideToShutDown.exe 40
C:\Windows\system32\smphost.dll 30
C:\Windows\system32\spwizres.dll 32
C:\Windows\system32\streamci.dll 29
C:\Windows\system32\ttdloader.dll 36
C:\Windows\system32\UtilityVmSysprep.dll 32
C:\Windows\system32\uxlibres.dll 35
C:\Windows\system32\VmApplicationHealthMonitorProxy.dll 32
C:\Windows\system32\wbem\Microsoft.AppV.AppVClientWmi.dll 30
C:\Windows\system32\winnsi.dll 35
C:\Windows\system32\wshhyperv.dll 40
C:\Windows\system32\wshunix.dll 35
C:\Windows\system32\wuauclt.exe 32
C:\Windows\SysWOW64\AppVClientPS.dll 36
C:\Windows\SysWOW64\AppVSentinel.dll 40
C:\Windows\SysWOW64\AppVTerminator.dll 36
C:\Windows\SysWOW64\avrt.dll 35
C:\Windows\SysWOW64\backgroundTaskHost.exe 35
C:\Windows\SysWOW64\BOOTVID.DLL 32
C:\Windows\SysWOW64\CameraSettingsUIHost.exe 27
C:\Windows\SysWOW64\DefaultDeviceManager.dll 33
C:\Windows\SysWOW64\dllhost.exe 44
C:\Windows\SysWOW64\downlevel\api-ms-win-base-util-l1-1-0.dll 35
C:\Windows\SysWOW64\downlevel\api-ms-win-core-com-l1-1-0.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-core-comm-l1-1-0.dll 33
C:\Windows\SysWOW64\downlevel\api-ms-win-core-console-l1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-datetime-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-datetime-l1-1-1.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-debug-l1-1-0.dll 36
C:\Windows\SysWOW64\downlevel\api-ms-win-core-debug-l1-1-1.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-delayload-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-errorhandling-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-errorhandling-l1-1-1.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-fibers-l1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-fibers-l1-1-1.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-file-l1-1-0.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-core-file-l1-2-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-file-l1-2-1.dll 38
C:\Windows\SysWOW64\downlevel\API-MS-Win-core-file-l2-1-0.dll 38
C:\Windows\SysWOW64\downlevel\API-MS-Win-core-file-l2-1-1.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-handle-l1-1-0.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-core-heap-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\API-MS-Win-Core-Heap-Obsolete-L1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-interlocked-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-io-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-io-l1-1-1.dll 32
C:\Windows\SysWOW64\downlevel\api-ms-win-core-kernel32-legacy-l1-1-0.dll 35
C:\Windows\SysWOW64\downlevel\api-ms-win-core-kernel32-legacy-l1-1-1.dll 40
C:\Windows\SysWOW64\downlevel\API-MS-Win-Core-Kernel32-Private-L1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\API-MS-Win-Core-Kernel32-Private-L1-1-1.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-libraryloader-l1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-libraryloader-l1-1-1.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-localization-l1-2-0.dll 29
C:\Windows\SysWOW64\downlevel\api-ms-win-core-localization-l1-2-1.dll 38
C:\Windows\SysWOW64\downlevel\API-MS-Win-core-localization-obsolete-l1-2-0.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-core-memory-l1-1-0.dll 36
C:\Windows\SysWOW64\downlevel\api-ms-win-core-memory-l1-1-1.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-core-memory-l1-1-2.dll 36
C:\Windows\SysWOW64\downlevel\api-ms-win-core-namedpipe-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-privateprofile-l1-1-0.dll 36
C:\Windows\SysWOW64\downlevel\api-ms-win-core-privateprofile-l1-1-1.dll 36
C:\Windows\SysWOW64\downlevel\api-ms-win-core-processenvironment-l1-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-processenvironment-l1-2-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-processthreads-l1-1-0.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-core-processthreads-l1-1-1.dll 35
C:\Windows\SysWOW64\downlevel\api-ms-win-core-processthreads-l1-1-2.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-processtopology-obsolete-l1-1-0.dll 35
C:\Windows\SysWOW64\downlevel\api-ms-win-core-profile-l1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-realtime-l1-1-0.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-core-registry-l1-1-0.dll 35
C:\Windows\SysWOW64\downlevel\api-ms-win-core-registry-l2-1-0.dll 35
C:\Windows\SysWOW64\downlevel\api-ms-win-core-rtlsupport-l1-1-0.dll 36
C:\Windows\SysWOW64\downlevel\api-ms-win-core-shlwapi-legacy-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-shlwapi-obsolete-l1-1-0.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-core-shutdown-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-stringansi-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-string-l1-1-0.dll 35
C:\Windows\SysWOW64\downlevel\API-MS-Win-core-string-l2-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-stringloader-l1-1-1.dll 41
C:\Windows\SysWOW64\downlevel\API-MS-Win-core-string-obsolete-l1-1-0.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-core-synch-l1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-synch-l1-2-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-sysinfo-l1-1-0.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-core-sysinfo-l1-2-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-sysinfo-l1-2-1.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-core-threadpool-l1-2-0.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-core-threadpool-legacy-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-threadpool-private-l1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-timezone-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-url-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-util-l1-1-0.dll 35
C:\Windows\SysWOW64\downlevel\api-ms-win-core-version-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-wow64-l1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-xstate-l1-1-0.dll 43
C:\Windows\SysWOW64\downlevel\API-MS-Win-core-xstate-l2-1-0.dll 35
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-conio-l1-1-0.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-convert-l1-1-0.dll 36
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-environment-l1-1-0.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-filesystem-l1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-heap-l1-1-0.dll 36
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-locale-l1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-math-l1-1-0.dll 30
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-multibyte-l1-1-0.dll 32
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-process-l1-1-0.dll 35
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-runtime-l1-1-0.dll 35
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-stdio-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-string-l1-1-0.dll 36
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-time-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-utility-l1-1-0.dll 40
C:\Windows\SysWOW64\downlevel\API-MS-Win-devices-config-L1-1-0.dll 35
C:\Windows\SysWOW64\downlevel\API-MS-Win-devices-config-L1-1-1.dll 41
C:\Windows\SysWOW64\downlevel\API-MS-Win-Eventing-ClassicProvider-L1-1-0.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-eventing-consumer-l1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\API-MS-Win-Eventing-Controller-L1-1-0.dll 36
C:\Windows\SysWOW64\downlevel\API-MS-Win-Eventing-Legacy-L1-1-0.dll 40
C:\Windows\SysWOW64\downlevel\API-MS-Win-Eventing-Provider-L1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\API-MS-Win-EventLog-Legacy-L1-1-0.dll 36
C:\Windows\SysWOW64\downlevel\api-ms-win-security-base-l1-1-0.dll 36
C:\Windows\SysWOW64\downlevel\api-ms-win-security-cryptoapi-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\API-MS-Win-Security-Lsalookup-L2-1-0.dll 43
C:\Windows\SysWOW64\downlevel\API-MS-Win-Security-Lsalookup-L2-1-1.dll 36
C:\Windows\SysWOW64\downlevel\API-MS-Win-security-lsapolicy-l1-1-0.dll 40
C:\Windows\SysWOW64\downlevel\API-MS-Win-security-provider-L1-1-0.dll 36
C:\Windows\SysWOW64\downlevel\api-ms-win-security-sddl-l1-1-0.dll 33
C:\Windows\SysWOW64\downlevel\api-ms-win-service-core-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-service-core-l1-1-1.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-service-management-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-service-management-l2-1-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-service-private-l1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-service-private-l1-1-1.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-service-winsvc-l1-1-0.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-shcore-stream-l1-1-0.dll 38
C:\Windows\SysWOW64\dsrole.dll 36
C:\Windows\SysWOW64\fltLib.dll 33
C:\Windows\SysWOW64\IME\IMETC\IMTCTRLN.DLL 36
C:\Windows\SysWOW64\IME\SHARED\imecfmps.dll 29
C:\Windows\SysWOW64\IME\SHARED\IMEDICAPICCPS.DLL 35
C:\Windows\SysWOW64\IME\SHARED\IMESEARCHPS.DLL 43
C:\Windows\SysWOW64\ksuser.dll 44
C:\Windows\SysWOW64\LocationFrameworkPS.dll 35
C:\Windows\SysWOW64\pcwum.dll 33
C:\Windows\SysWOW64\psapi.dll 36
C:\Windows\SysWOW64\sfc.dll 38
C:\Windows\SysWOW64\smphost.dll 29
C:\Windows\SysWOW64\ttdloader.dll 54
C:\Windows\SysWOW64\uxlibres.dll 35
C:\Windows\SysWOW64\wbem\Microsoft.AppV.AppVClientWmi.dll 30
C:\Windows\SysWOW64\winnsi.dll 36
C:\Windows\SysWOW64\wshhyperv.dll 54
C:\Windows\SysWOW64\wshunix.dll 40

Possible Misuse

The following table contains possible examples of dllhost.exe being misused. While dllhost.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma file_event_win_creation_system_file.yml - '\dllhost.exe' DRL 1.0
sigma file_event_win_susp_adsi_cache_usage.yml - 'C:\windows\system32\dllhost.exe' DRL 1.0
sigma file_event_win_uac_bypass_wmp.yml Image: 'C:\Windows\system32\DllHost.exe' DRL 1.0
sigma image_load_suspicious_vss_ps_load.yml - '\dllhost.exe' DRL 1.0
sigma net_connection_win_dllhost_net_connections.yml title: Dllhost Internet Connection DRL 1.0
sigma net_connection_win_dllhost_net_connections.yml description: Detects Dllhost that communicates with public IP addresses DRL 1.0
sigma net_connection_win_dllhost_net_connections.yml Image\|endswith: '\dllhost.exe' DRL 1.0
sigma proc_creation_win_apt_unc2452_cmds.yml Image\|endswith: '\dllhost.exe' DRL 1.0
sigma proc_creation_win_cmstp_com_object_access.yml ParentImage\|endswith: '\DllHost.exe' DRL 1.0
sigma proc_creation_win_cobaltstrike_process_patterns.yml ParentImage\|endswith: '\dllhost.exe' DRL 1.0
sigma proc_creation_win_mal_darkside_ransomware.yml ParentCommandLine\|contains: 'DllHost.exe /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}' DRL 1.0
sigma proc_creation_win_script_event_consumer_spawn.yml - '\dllhost.exe' DRL 1.0
sigma proc_creation_win_system_exe_anomaly.yml - '\dllhost.exe' DRL 1.0
LOLBAS Dllhost.yml Name: Dllhost.exe  
LOLBAS Dllhost.yml - Command: dllhost.exe /Processid:{CLSID}  
LOLBAS Dllhost.yml Description: Use dllhost.exe to load a registered or hijacked COM Server payload.  
LOLBAS Dllhost.yml - Path: C:\Windows\System32\dllhost.exe  
LOLBAS Dllhost.yml - Path: C:\Windows\SysWOW64\dllhost.exe  
LOLBAS Dllhost.yml - IOC: DotNet CLR libraries loaded into dllhost.exe  
LOLBAS Dllhost.yml - IOC: DotNet CLR Usage Log - dllhost.exe.log  
LOLBAS Dllhost.yml - IOC: Suspicious network connectings originating from dllhost.exe  
LOLBAS Dllhost.yml - Link: https://nasbench.medium.com/what-is-the-dllhost-exe-process-actually-running-ef9fe4c19c08  
signature-base crime_nopetya_jun17.yar $s7 = “dllhost.dat” fullword wide CC BY-NC 4.0

MIT License. Copyright (c) 2020-2021 Strontic.