libcurl.dll

  • File Path: C:\Program Files (x86)\Microsoft Office\root\Office16\ODBC Drivers\Salesforce\lib\LibCurl32.DllA\libcurl.dll
  • Description: libcurl Shared Library

Hashes

Type Hash
MD5 3377B5C73EA94979408A04764DA39247
SHA1 F507DAD60D5EBD4E840AFBAA92BA8913CDA194EA
SHA256 B606956DAC1AC68477E9B94F14B2E24BE1D551EE0ADB6E28AF2E7D7E2D9EA706
SHA384 58DC66FF1C77A3A8362F0AB8376D261E5C2EAEA289064FAA7DF236AD0BF57F11623746E8860E72AF8E89D106167B06CB
SHA512 432701222A749FA41022DB78057F22A819963A1EA6A626F000477B10AA07829E3388A74B2426F247EF66DD65731CBE261A57BA98947983E4E4F09F4D2A87A815
SSDEEP 6144:AgQbbqD4qNmHhUyQhnxSz3W5LXt1x3jLUW2V/QyYGJbaNvgZ/MIGRAL:A7bPqNm+aKt/TLUW2GJ4bAvrAL
IMP E9FF619D5FF1FA877812692F350AF0CE
PESHA1 8E53AB69FCE6BDD623D35D4CE02BC1ACEB336B79
PE256 50B434963619B844D5331EAA9222AE6DFEF6C50390F8896974B7B8C6DE1D7D1F

DLL Exports:

Function Name Ordinal Type
curl_multi_remove_handle 49 Exported Function
curl_multi_setopt 50 Exported Function
curl_multi_init 47 Exported Function
curl_multi_perform 48 Exported Function
curl_multi_socket 51 Exported Function
curl_multi_strerror 54 Exported Function
curl_multi_timeout 55 Exported Function
curl_multi_socket_action 52 Exported Function
curl_multi_socket_all 53 Exported Function
curl_msnprintf 40 Exported Function
curl_msprintf 41 Exported Function
curl_mime_type 38 Exported Function
curl_mprintf 39 Exported Function
curl_multi_add_handle 42 Exported Function
curl_multi_fdset 45 Exported Function
curl_multi_info_read 46 Exported Function
curl_multi_assign 43 Exported Function
curl_multi_cleanup 44 Exported Function
curl_multi_wait 56 Exported Function
curl_slist_append 68 Exported Function
curl_slist_free_all 69 Exported Function
curl_share_setopt 66 Exported Function
curl_share_strerror 67 Exported Function
curl_strequal 70 Exported Function
curl_version 73 Exported Function
curl_version_info 74 Exported Function
curl_strnequal 71 Exported Function
curl_unescape 72 Exported Function
curl_mvprintf 59 Exported Function
curl_mvsnprintf 60 Exported Function
curl_mvaprintf 57 Exported Function
curl_mvfprintf 58 Exported Function
curl_mvsprintf 61 Exported Function
curl_share_cleanup 64 Exported Function
curl_share_init 65 Exported Function
curl_pushheader_byname 62 Exported Function
curl_pushheader_bynum 63 Exported Function
curl_easy_strerror 12 Exported Function
curl_easy_unescape 13 Exported Function
curl_easy_send 10 Exported Function
curl_easy_setopt 11 Exported Function
curl_escape 14 Exported Function
curl_formget 17 Exported Function
curl_free 18 Exported Function
curl_formadd 15 Exported Function
curl_formfree 16 Exported Function
curl_easy_escape 3 Exported Function
curl_easy_getinfo 4 Exported Function
curl_easy_cleanup 1 Exported Function
curl_easy_duphandle 2 Exported Function
curl_easy_init 5 Exported Function
curl_easy_recv 8 Exported Function
curl_easy_reset 9 Exported Function
curl_easy_pause 6 Exported Function
curl_easy_perform 7 Exported Function
curl_getdate 19 Exported Function
curl_mime_filedata 31 Exported Function
curl_mime_filename 32 Exported Function
curl_mime_data_cb 29 Exported Function
curl_mime_encoder 30 Exported Function
curl_mime_free 33 Exported Function
curl_mime_name 36 Exported Function
curl_mime_subparts 37 Exported Function
curl_mime_headers 34 Exported Function
curl_mime_init 35 Exported Function
curl_global_init 22 Exported Function
curl_global_init_mem 23 Exported Function
curl_getenv 20 Exported Function
curl_global_cleanup 21 Exported Function
curl_global_sslset 24 Exported Function
curl_mime_addpart 27 Exported Function
curl_mime_data 28 Exported Function
curl_maprintf 25 Exported Function
curl_mfprintf 26 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 1F0D1A395C8D377274C98DB931B67C8C
  • Thumbprint: C4BD545EE3889DB77FC69A91F89E375B8E753241
  • Issuer: CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US
  • Subject: CN=Simba Technologies Inc., O=Simba Technologies Inc., L=Vancouver, S=British Columbia, C=CA

File Metadata

  • Original Filename: libcurl.dll
  • Product Name: The curl library
  • Company Name: The curl library, https://curl.haxx.se/
  • File Version: 7.60.0
  • Product Version: 7.60.0
  • Language: English (United States)
  • Legal Copyright: 1996 - 2018 Daniel Stenberg, daniel@haxx.se.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/70
  • VirusTotal Link: https://www.virustotal.com/gui/file/b606956dac1ac68477e9b94f14b2e24be1d551ee0adb6e28af2e7d7e2d9ea706/detection/

Possible Misuse

The following table contains possible examples of libcurl.dll being misused. While libcurl.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
malware-ioc amavaldo \| 4DBA5FE842B01B641A7228A4C8F805E4627C0012 \| libcurl.dll \| Injector for email creation tool \| Win32/Spy.Amavaldo.P trojan \| © ESET 2014-2018
atomic-red-team T1574.002.md GUP is an open source signed binary used by Notepad++ for software updates, and is vulnerable to DLL Side-Loading, thus enabling the libcurl dll to be loaded. MIT License. © 2018 Red Canary

MIT License. Copyright (c) 2020-2021 Strontic.