imagehlp.dll

  • File Path: C:\Windows\system32\imagehlp.dll
  • Description: Windows NT Image Helper

Hashes

Type Hash
MD5 40EAF3D7B167C41B58E63CB6D6C7CF7C
SHA1 CB568E83991F7112A333EF1E38C4F0D29E5C9CC8
SHA256 8F7A32EFCE7E0975E3233FB0A1E02BD2604F1CD28B3B6185B2F38A4FD87ED6C6
SHA384 2773DDE0156EEC7888665AD48C70B09B128B1B702907DA2D305F5E2D3B1F811E84266414D59667B4D69DA223C29E05A4
SHA512 B01472C0031BA210952BAC2DC882A48FA3F8F19D20AC9EE9DCA73AEED0B16034CFC4B4010AC338323A510CF1C411FB5AF506CB6A540F271491179EF21E3D5991
SSDEEP 3072:ztSE28bT6MN2jbPw7rrDBm8GTeKtbJ6PtXrp1O:R28bT6MN0bPwGJ6PN+
IMP DC585C2D8B916631658D19F42EFE3EB6
PESHA1 B023FDBC4586D570B81D7F763BAE678127D0E005
PE256 797C03D8807C8E3FA4A6316642BF28A7FCC7F56DF77DA1BC52D5EDEB2E36EDC7

DLL Exports:

Function Name Ordinal Type
SymGetSourceFileChecksumW 105 Exported Function
SymGetSearchPath 104 Exported Function
SymGetSourceFileTokenW 107 Exported Function
SymGetSourceFileFromTokenW 106 Exported Function
SymGetOptions 103 Exported Function
SymGetModuleInfo64 100 Exported Function
SymGetModuleInfo 99 Exported Function
SymGetModuleInfoW64 102 Exported Function
SymGetModuleInfoW 101 Exported Function
SymGetSourceVarFromTokenW 108 Exported Function
SymGetSymNext 113 Exported Function
SymGetSymFromName64 112 Exported Function
SymGetSymPrev 115 Exported Function
SymGetSymNext64 114 Exported Function
SymGetSymFromName 111 Exported Function
SymGetSymbolFileW 118 Exported Function
SymGetSymbolFile 117 Exported Function
SymGetSymFromAddr64 110 Exported Function
SymGetSymFromAddr 109 Exported Function
SymGetExtendedOption 86 Exported Function
SymGetDiaSession 4 Exported Function
SymGetLineFromAddr64 88 Exported Function
SymGetLineFromAddr 87 Exported Function
SymFunctionTableAccess64AccessRoutines 85 Exported Function
SymFromName 82 Exported Function
SymFromInlineContextW 81 Exported Function
SymFunctionTableAccess64 84 Exported Function
SymFunctionTableAccess 83 Exported Function
SymGetLineFromInlineContext 89 Exported Function
SymGetLinePrev64 96 Exported Function
SymGetLinePrev 95 Exported Function
SymGetModuleBase64 98 Exported Function
SymGetModuleBase 97 Exported Function
SymGetLineNext64 94 Exported Function
SymGetLineFromName 91 Exported Function
SymGetLineFromInlineContextW 90 Exported Function
SymGetLineNext 93 Exported Function
SymGetLineFromName64 92 Exported Function
SymGetSymPrev64 116 Exported Function
SymSrvGetFileIndexes 145 Exported Function
SymSetSearchPath 142 Exported Function
SymSrvGetFileIndexString 143 Exported Function
SymSrvGetFileIndexesW 146 Exported Function
SymSetScopeFromInlineContext 141 Exported Function
SymSetOptions 138 Exported Function
SymSetExtendedOption 137 Exported Function
SymSetScopeFromIndex 140 Exported Function
SymSetScopeFromAddr 139 Exported Function
SymSrvGetFileIndexStringW 144 Exported Function
UnMapAndLoad 153 Exported Function
UnDecorateSymbolName 152 Exported Function
UpdateDebugInfoFileEx 155 Exported Function
UpdateDebugInfoFile 154 Exported Function
TouchFileTimes 151 Exported Function
SymUnDName64 148 Exported Function
SymUnDName 147 Exported Function
SymUnloadModule64 150 Exported Function
SymUnloadModule 149 Exported Function
SymLoadModule64 125 Exported Function
SymLoadModule 124 Exported Function
SymMatchFileNameW 127 Exported Function
SymMatchFileName 126 Exported Function
SymInitialize 123 Exported Function
SymGetTypeFromNameW 120 Exported Function
SymGetTypeFromName 119 Exported Function
SymGetTypeInfoEx 122 Exported Function
SymGetTypeInfo 121 Exported Function
SymMatchString 128 Exported Function
SymRegisterFunctionEntryCallback64 135 Exported Function
SymRegisterFunctionEntryCallback 134 Exported Function
SymSetDiaSession 5 Exported Function
SymSetContext 136 Exported Function
SymRegisterCallback64 133 Exported Function
SymMatchStringW 130 Exported Function
SymMatchStringA 129 Exported Function
SymRegisterCallback 132 Exported Function
SymQueryInlineTrace 131 Exported Function
SymFromInlineContext 80 Exported Function
ImageGetDigestStream 31 Exported Function
ImageGetCertificateHeader 30 Exported Function
ImagehlpApiVersionEx 39 Exported Function
ImagehlpApiVersion 38 Exported Function
ImageGetCertificateDataEx 29 Exported Function
ImageDirectoryEntryToDataEx 26 Exported Function
ImageDirectoryEntryToData 25 Exported Function
ImageGetCertificateData 28 Exported Function
ImageEnumerateCertificates 27 Exported Function
ImageLoad 32 Exported Function
MakeSureDirectoryPathExists 41 Exported Function
IsBufferCleanOfInvalidMarkers 40 Exported Function
MapFileAndCheckSumA 43 Exported Function
MapAndLoad 42 Exported Function
ImageUnload 37 Exported Function
ImageRemoveCertificate 34 Exported Function
ImageNtHeader 33 Exported Function
ImageRvaToVa 36 Exported Function
ImageRvaToSection 35 Exported Function
EnumerateLoadedModulesExW 12 Exported Function
EnumerateLoadedModulesEx 11 Exported Function
FindDebugInfoFile 14 Exported Function
EnumerateLoadedModulesW64 13 Exported Function
EnumerateLoadedModules64 10 Exported Function
BindImageEx 7 Exported Function
BindImage 6 Exported Function
EnumerateLoadedModules 9 Exported Function
CheckSumMappedFile 8 Exported Function
FindDebugInfoFileEx 15 Exported Function
GetSymLoadError 22 Exported Function
GetImageUnusedHeaderBytes 21 Exported Function
ImageAddCertificate 24 Exported Function
GetTimestampForLoadedLibrary 23 Exported Function
GetImageConfigInformation 20 Exported Function
FindExecutableImageEx 17 Exported Function
FindExecutableImage 16 Exported Function
FindFileInSearchPath 19 Exported Function
FindFileInPath 18 Exported Function
MapFileAndCheckSumW 44 Exported Function
SymEnumSym 62 Exported Function
SymEnumerateSymbolsW64 76 Exported Function
SymEnumSymbolsEx 64 Exported Function
SymEnumSymbols 63 Exported Function
SymEnumerateSymbolsW 75 Exported Function
SymEnumerateModules64 72 Exported Function
SymEnumerateModules 71 Exported Function
SymEnumerateSymbols64 74 Exported Function
SymEnumerateSymbols 73 Exported Function
SymEnumSymbolsExW 65 Exported Function
SymFindFileInPathW 78 Exported Function
SymFindFileInPath 77 Exported Function
SymFromAddr 79 Exported Function
SymFreeDiaString 3 Exported Function
SymEnumTypesW 70 Exported Function
SymEnumTypes 67 Exported Function
SymEnumSymbolsForAddr 66 Exported Function
SymEnumTypesByNameW 69 Exported Function
SymEnumTypesByName 68 Exported Function
ReportSymbolLoadSummary 50 Exported Function
RemoveRelocations 1 Exported Function
SetCheckUserInterruptShared 52 Exported Function
SearchTreeForFile 51 Exported Function
RemovePrivateCvSymbolicEx 49 Exported Function
ReBaseImage64 46 Exported Function
ReBaseImage 45 Exported Function
RemovePrivateCvSymbolic 48 Exported Function
RemoveInvalidModuleList 47 Exported Function
SetImageConfigInformation 53 Exported Function
SymAllocDiaString 2 Exported Function
SymAddrIncludeInlineTrace 59 Exported Function
SymCompareInlineTrace 61 Exported Function
SymCleanup 60 Exported Function
StackWalkEx 58 Exported Function
SplitSymbols 55 Exported Function
SetSymLoadError 54 Exported Function
StackWalk64 57 Exported Function
StackWalk 56 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: IMAGEHLP.DLL
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/68
  • VirusTotal Link: https://www.virustotal.com/gui/file/8f7a32efce7e0975e3233fb0a1e02bd2604f1cd28b3b6185b2f38a4fd87ed6c6/detection/

Possible Misuse

The following table contains possible examples of imagehlp.dll being misused. While imagehlp.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
signature-base apt_cloudduke.yar $s2 = “imagehlp.dll” fullword ascii CC BY-NC 4.0
signature-base spy_regin_fiveeyes.yar $s14 = “imagehlp.dll” fullword ascii CC BY-NC 4.0

MIT License. Copyright (c) 2020-2021 Strontic.