ldmdump.exe

  • File Path: C:\SysinternalsSuite\ldmdump.exe

Hashes

Type Hash
MD5 202119E519DD179DE64AFD195F0DDA42
SHA1 9DFCA2C430EF0E0C618EB229D840575411FF6ABA
SHA256 980E64020CFCEB02652A2A08270B84B974F18F290E9CB798F5D46D3AA3A0EC94
SHA384 A6FC137DEEEA3FE889131A2E84B29F7705E35843E3BB43AB9D6EFF99A3C82495A12DB715F95ED86FA661A106826B2DC3
SHA512 D9015B320FD1032734DCDF35D20B9944ECD499D3C4ACF1DD885A3A12940AD951A597F4CDC9E1E4A044EB29F3D3E07C1389A34DFD945DCFC88BD1A9A5B0B32F33
SSDEEP 1536:MQVwz0C90qKVl2WcEtQdkmVnTA6uv5/Haei4:SlK72WRt0oCn4
IMP 62430F16891F2BBC3E224C30B3127F73
PESHA1 CD66FBCE3919BCB91488647C3AE0218FF0932CEA
PE256 A2F32F4396EB63E9C115C392A4DB1736F1A22BD46A55BA3C0564B4FF36409C52

Runtime Data

Usage (stdout):


Logical Disk Manager Configuration Dump v1.03
Copyright (C) 2000-2002 Mark Russinovich

usage: C:\SysinternalsSuite\ldmdump.exe /d#
   /d#   Physical disk number


Loaded Modules:

Path
C:\SysinternalsSuite\ldmdump.exe
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll

Signature

  • Status: Signature verified.
  • Serial: 61469ECB000400000065
  • Thumbprint: 564E01066387F26C912010D06BD78D3CF1E845AB
  • Issuer: CN=Microsoft Code Signing PCA, OU=Copyright (c) 2000 Microsoft Corp., O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename:
  • Product Name:
  • Company Name:
  • File Version:
  • Product Version:
  • Language:
  • Legal Copyright:
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 1/69
  • VirusTotal Link: https://www.virustotal.com/gui/file/980e64020cfceb02652a2a08270b84b974f18f290e9cb798f5d46d3aa3a0ec94/detection/

File Similarity (ssdeep match)

File Score
C:\SysinternalsSuite\AccessEnum.exe 47
C:\SysinternalsSuite\adrestore.exe 50
C:\SysinternalsSuite\Cacheset.exe 43
C:\SysinternalsSuite\ctrl2cap.exe 49
C:\SysinternalsSuite\Diskmon.exe 24
C:\SysinternalsSuite\efsdump.exe 49
C:\SysinternalsSuite\pagedfrg.exe 40

Possible Misuse

The following table contains possible examples of ldmdump.exe being misused. While ldmdump.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_false_sysinternalsuite.yml - '\ldmdump.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.