imagehlp.dll

  • File Path: C:\Windows\SysWOW64\imagehlp.dll
  • Description: Windows NT Image Helper

Hashes

Type Hash
MD5 5092FB406BF50C687AA474C1566159CC
SHA1 93A27975797B0A33BA5B463F4D5345BC221278DF
SHA256 85A9E7E8ABBD9220773B121E2BD0CBA2AB4F5894B527F9BA5824C4B870480B56
SHA384 C526E7C1DACD478FD33231B45EAFAA6F76D6D6E566AC94DF9DB8865E382E51323DA3E8F72CC23652F57811C1A7814387
SHA512 337715BE3B6F7EC0F920502541F950DBE5D4D9922FBB48FB98BD081C6A9F58CDBDB7CE3A79DF6CFC93D6D29F4733752B937204B85A49353D0535355E86E9A30A
SSDEEP 1536:7K8amJiWTua0LUrodTckRBCbyhF2gV4X52WauTIvVjPXzqX93jP7K:7K8amJiWTua4YodTbfOmEX5F6JPzqFjm
IMP 4C371FEDAFCC3935BEAE01693F137C74
PESHA1 656DFD7C809BFC3E3029FD2A86D732268BD44934
PE256 840C9081E4A265FBC88B7DF675E76C77F08C51D7C7FB6828601584B79CA83FE5

DLL Exports:

Function Name Ordinal Type
SymGetSourceFileFromTokenW 107 Exported Function
SymGetSourceFileChecksumW 106 Exported Function
SymGetSourceVarFromTokenW 109 Exported Function
SymGetSourceFileTokenW 108 Exported Function
SymGetSearchPath 105 Exported Function
SymGetModuleInfoW 103 Exported Function
SymGetModuleInfo64 100 Exported Function
SymGetOptions 104 Exported Function
SymGetModuleInfoW64 102 Exported Function
SymGetSymbolFile 118 Exported Function
SymGetSymNext64 114 Exported Function
SymGetSymNext 115 Exported Function
SymGetSymPrev64 116 Exported Function
SymGetSymPrev 117 Exported Function
SymGetSymFromName64 112 Exported Function
SymGetSymFromAddr 111 Exported Function
SymGetSymbolFileW 119 Exported Function
SymGetSymFromName 113 Exported Function
SymGetSymFromAddr64 110 Exported Function
SymGetModuleInfo 101 Exported Function
SymGetExtendedOption 87 Exported Function
SymGetDiaSession 4 Exported Function
SymGetLineFromAddr64 88 Exported Function
SymGetLineFromAddr 89 Exported Function
SymFunctionTableAccess64AccessRoutines 85 Exported Function
SymFromName 83 Exported Function
SymFromInlineContextW 82 Exported Function
SymFunctionTableAccess64 84 Exported Function
SymFunctionTableAccess 86 Exported Function
SymGetLineFromInlineContext 90 Exported Function
SymGetLinePrev64 96 Exported Function
SymGetLinePrev 97 Exported Function
SymGetModuleBase64 98 Exported Function
SymGetModuleBase 99 Exported Function
SymGetLineNext64 94 Exported Function
SymGetLineFromName 93 Exported Function
SymGetLineFromInlineContextW 91 Exported Function
SymGetLineNext 95 Exported Function
SymGetLineFromName64 92 Exported Function
SymSrvGetFileIndexesW 147 Exported Function
SymSrvGetFileIndexes 146 Exported Function
SymSrvGetFileIndexStringW 145 Exported Function
SymSrvGetFileIndexString 144 Exported Function
SymSetSearchPath 143 Exported Function
SymSetScopeFromAddr 140 Exported Function
SymSetOptions 139 Exported Function
SymSetScopeFromInlineContext 142 Exported Function
SymSetScopeFromIndex 141 Exported Function
SymUnDName 149 Exported Function
UnmapDebugInformation 155 Exported Function
UnMapAndLoad 154 Exported Function
UpdateDebugInfoFileEx 157 Exported Function
UpdateDebugInfoFile 156 Exported Function
UnDecorateSymbolName 153 Exported Function
SymUnloadModule 151 Exported Function
SymUnDName64 148 Exported Function
TouchFileTimes 152 Exported Function
SymUnloadModule64 150 Exported Function
SymSetExtendedOption 138 Exported Function
SymLoadModule64 125 Exported Function
SymLoadModule 126 Exported Function
SymMatchFileNameW 128 Exported Function
SymMatchFileName 127 Exported Function
SymInitialize 124 Exported Function
SymGetTypeFromNameW 121 Exported Function
SymGetTypeFromName 120 Exported Function
SymGetTypeInfoEx 123 Exported Function
SymGetTypeInfo 122 Exported Function
SymMatchString 129 Exported Function
SymRegisterFunctionEntryCallback64 135 Exported Function
SymRegisterFunctionEntryCallback 136 Exported Function
SymSetDiaSession 5 Exported Function
SymSetContext 137 Exported Function
SymRegisterCallback64 133 Exported Function
SymMatchStringW 131 Exported Function
SymMatchStringA 130 Exported Function
SymRegisterCallback 134 Exported Function
SymQueryInlineTrace 132 Exported Function
SymFromInlineContext 81 Exported Function
ImagehlpApiVersion 38 Exported Function
ImageGetDigestStream 31 Exported Function
ImageLoad 32 Exported Function
ImagehlpApiVersionEx 39 Exported Function
ImageGetCertificateHeader 30 Exported Function
ImageEnumerateCertificates 27 Exported Function
ImageDirectoryEntryToDataEx 26 Exported Function
ImageGetCertificateDataEx 29 Exported Function
ImageGetCertificateData 28 Exported Function
ImageNtHeader 33 Exported Function
MapAndLoad 42 Exported Function
MakeSureDirectoryPathExists 41 Exported Function
MapFileAndCheckSumA 44 Exported Function
MapDebugInformation 43 Exported Function
IsBufferCleanOfInvalidMarkers 40 Exported Function
ImageRvaToSection 35 Exported Function
ImageRemoveCertificate 34 Exported Function
ImageUnload 37 Exported Function
ImageRvaToVa 36 Exported Function
ImageDirectoryEntryToData 25 Exported Function
EnumerateLoadedModulesExW 12 Exported Function
EnumerateLoadedModulesEx 11 Exported Function
FindDebugInfoFile 14 Exported Function
EnumerateLoadedModulesW64 13 Exported Function
EnumerateLoadedModules64 9 Exported Function
BindImageEx 7 Exported Function
BindImage 6 Exported Function
EnumerateLoadedModules 10 Exported Function
CheckSumMappedFile 8 Exported Function
FindDebugInfoFileEx 15 Exported Function
GetSymLoadError 22 Exported Function
GetImageUnusedHeaderBytes 21 Exported Function
ImageAddCertificate 24 Exported Function
GetTimestampForLoadedLibrary 23 Exported Function
GetImageConfigInformation 20 Exported Function
FindExecutableImageEx 17 Exported Function
FindExecutableImage 16 Exported Function
FindFileInSearchPath 19 Exported Function
FindFileInPath 18 Exported Function
SymEnumSym 63 Exported Function
SymEnumerateSymbolsW64 76 Exported Function
SymEnumSymbolsEx 65 Exported Function
SymEnumSymbols 64 Exported Function
SymEnumerateSymbolsW 77 Exported Function
SymEnumerateModules64 72 Exported Function
SymEnumerateModules 73 Exported Function
SymEnumerateSymbols64 74 Exported Function
SymEnumerateSymbols 75 Exported Function
SymEnumSymbolsExW 66 Exported Function
SymFindFileInPathW 79 Exported Function
SymFindFileInPath 78 Exported Function
SymFromAddr 80 Exported Function
SymFreeDiaString 3 Exported Function
SymEnumTypesW 71 Exported Function
SymEnumTypes 68 Exported Function
SymEnumSymbolsForAddr 67 Exported Function
SymEnumTypesByNameW 70 Exported Function
SymEnumTypesByName 69 Exported Function
SymCompareInlineTrace 62 Exported Function
RemoveRelocations 1 Exported Function
RemovePrivateCvSymbolicEx 50 Exported Function
SearchTreeForFile 52 Exported Function
ReportSymbolLoadSummary 51 Exported Function
RemovePrivateCvSymbolic 49 Exported Function
ReBaseImage 47 Exported Function
MapFileAndCheckSumW 45 Exported Function
RemoveInvalidModuleList 48 Exported Function
ReBaseImage64 46 Exported Function
SetCheckUserInterruptShared 53 Exported Function
SymAddrIncludeInlineTrace 60 Exported Function
StackWalkEx 59 Exported Function
SymCleanup 61 Exported Function
SymAllocDiaString 2 Exported Function
StackWalk64 57 Exported Function
SetSymLoadError 55 Exported Function
SetImageConfigInformation 54 Exported Function
StackWalk 58 Exported Function
SplitSymbols 56 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: IMAGEHLP.DLL
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/64
  • VirusTotal Link: https://www.virustotal.com/gui/file/85a9e7e8abbd9220773b121e2bd0cba2ab4f5894b527f9ba5824c4b870480b56/detection/

Possible Misuse

The following table contains possible examples of imagehlp.dll being misused. While imagehlp.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
signature-base apt_cloudduke.yar $s2 = “imagehlp.dll” fullword ascii CC BY-NC 4.0
signature-base spy_regin_fiveeyes.yar $s14 = “imagehlp.dll” fullword ascii CC BY-NC 4.0

MIT License. Copyright (c) 2020-2021 Strontic.