logoncli.dll

  • File Path: C:\Windows\SysWOW64\logoncli.dll
  • Description: Net Logon Client DLL

Hashes

Type Hash
MD5 138871DBE68D0696D3D7FA91BC2873B1
SHA1 5D2C526E6121BC222D6B88F9162F457833CDE1B1
SHA256 9AC16F12023BE5F0049C9D30E86E45D65515F406269FF8821B49CDC8F03FB1DF
SHA384 5E50481FC5944F4263EC5CDDB0ED8473CECD6012E813A91901EEE382195A8442231D8C09876EBB194342FD3F5AC282A6
SHA512 E433DC37A671CE1AFD8491903E7A1E74EA8F292891AC5D6308D324FEB73D93A1E16F04A5D1CE083CF7F7BA8EFDAC0F3A64F4D0825D66FE3B5A228FB500A85B96
SSDEEP 3072:4zNbamfqW49Wv5AU/aQD6bcChD0hdBCFXYh74XWKLCUHqVzAEOAMl:oNb89IfibThDGBFh7CLCUsOF
IMP F440C693555032D2E14DD32A58C326B9
PESHA1 2CCB7D1B3294B552FE237DB2C56E3B6C4D02A18E
PE256 6833934F17592DB8A4995069A7E2867608EFF31AFD5E0A4187E9BDE5478C40DB

DLL Exports:

Function Name Ordinal Type
I_NetLogonSamLogonWithFlags 53 Exported Function
I_NetLogonSendToSam 54 Exported Function
I_NetLogonSamLogonEx 52 Exported Function
I_NetLogonSamLogoff 50 Exported Function
I_NetLogonSamLogon 51 Exported Function
I_NetServerAuthenticate 60 Exported Function
I_NetServerAuthenticate2 58 Exported Function
I_NetQuerySecureChannelDCInfo 57 Exported Function
I_NetLogonUasLogoff 55 Exported Function
I_NetLogonUasLogon 56 Exported Function
I_NetlogonGetTrustRid 71 Exported Function
I_NetlogonComputeClientSignature 68 Exported Function
I_NetlogonComputeServerDigest 69 Exported Function
I_NetlogonComputeClientDigest 67 Exported Function
I_NetGetDCList 44 Exported Function
I_NetGetForestTrustInformation 45 Exported Function
I_NetLogonGetCapabilities 48 Exported Function
I_NetLogonGetDomainInfo 49 Exported Function
I_NetLogonControl2 46 Exported Function
I_NetlogonComputeServerSignature 70 Exported Function
I_NetLogonControl 47 Exported Function
I_NetServerAuthenticate3 59 Exported Function
NetLogonSetServiceBits 80 Exported Function
NetQueryServiceAccount 81 Exported Function
NetLogonGetTimeServiceParentDomain 79 Exported Function
NetGetDCName 77 Exported Function
NetIsServiceAccount 78 Exported Function
NlBindingSetAuthInfo 85 Exported Function
NlSetDsIsCloningPDC 86 Exported Function
NlBindingRemoveServerFromCache 84 Exported Function
NetRemoveServiceAccount 82 Exported Function
NlBindingAddServerToCache 83 Exported Function
NetGetAnyDCName 76 Exported Function
I_NetServerPasswordSet2 63 Exported Function
I_NetServerReqChallenge 65 Exported Function
I_NetServerPasswordSet 64 Exported Function
I_NetServerGetTrustInfo 61 Exported Function
I_NetServerPasswordGet 62 Exported Function
NetEnumerateServiceAccounts 74 Exported Function
NetEnumerateTrustedDomains 75 Exported Function
NetAddServiceAccount 73 Exported Function
I_NetServerTrustPasswordsGet 66 Exported Function
I_RpcExtInitializeExtensionPoint 72 Exported Function
DsEnumerateDomainTrustsA 15 Exported Function
DsEnumerateDomainTrustsW 16 Exported Function
DsDeregisterDnsHostRecordsW 14 Exported Function
DsAddressToSiteNamesW 12 Exported Function
DsDeregisterDnsHostRecordsA 13 Exported Function
DsGetDcNameWithAccountA 20 Exported Function
DsGetDcNameWithAccountW 21 Exported Function
DsGetDcNameW 19 Exported Function
DsGetDcCloseW 17 Exported Function
DsGetDcNameA 18 Exported Function
DsAddressToSiteNamesExW 11 Exported Function
AuthzrExtGetInformationFromContext 4 Exported Function
AuthzrExtInitializeCompoundContext 5 Exported Function
AuthzrExtFreeResourceManager 3 Exported Function
AuthzrExtAccessCheck 1 Exported Function
AuthzrExtFreeContext 2 Exported Function
DsAddressToSiteNamesA 9 Exported Function
DsAddressToSiteNamesExA 10 Exported Function
AuthzrExtModifyClaims 8 Exported Function
AuthzrExtInitializeContextFromSid 6 Exported Function
AuthzrExtInitializeRemoteResourceManager 7 Exported Function
DsGetDcNextA 22 Exported Function
I_NetChainSetClientAttributes 38 Exported Function
I_NetChainSetClientAttributes2 37 Exported Function
I_NetAccountSync 36 Exported Function
I_DsUpdateReadOnlyServerDnsRecords 34 Exported Function
I_NetAccountDeltas 35 Exported Function
I_NetDatabaseSync2 41 Exported Function
I_NetExtendMachinePasswordExpirationTimeout 43 Exported Function
I_NetDatabaseSync 42 Exported Function
I_NetDatabaseDeltas 39 Exported Function
I_NetDatabaseRedo 40 Exported Function
DsValidateSubnetNameW 33 Exported Function
DsGetDcSiteCoverageA 26 Exported Function
DsGetDcSiteCoverageW 27 Exported Function
DsGetDcOpenW 25 Exported Function
DsGetDcNextW 23 Exported Function
DsGetDcOpenA 24 Exported Function
DsMergeForestTrustInformationW 31 Exported Function
DsValidateSubnetNameA 32 Exported Function
DsGetSiteNameW 30 Exported Function
DsGetForestTrustInformationW 28 Exported Function
DsGetSiteNameA 29 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: LOGONCLI.DLL
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.388 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.388
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/67
  • VirusTotal Link: https://www.virustotal.com/gui/file/9ac16f12023be5f0049c9d30e86e45d65515f406269ff8821b49cdc8f03fb1df/detection/

Possible Misuse

The following table contains possible examples of logoncli.dll being misused. While logoncli.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_mimikatz_inmemory_detection.yml - 'logoncli.dll' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.