logoncli.dll

  • File Path: C:\Windows\system32\logoncli.dll
  • Description: Net Logon Client DLL

Hashes

Type Hash
MD5 AA349F6065F9B91758DD0A85A27D0E01
SHA1 898EBEBEB1006DB656A1A9464037E646AC9E869A
SHA256 6D95876CA1A91BCE22D09D008976047156496CC5C85909D5C6554042FAF34D7E
SHA384 E554A4397D8AF7DF1DE5A109ACD6CA193E733B635C276D2388F6995E60775F82C0E28D36A904542CF69D6D33A8AEA7DD
SHA512 B38B661623300D5DF964C7AF69B53F28D42F23A2CCC6F11238CE0D68788DF0D575CB342827EB4845D1F261CB0093DC701D314C24204BB0D99480E133957CF33F
SSDEEP 3072:7TTCDuE/4ED0okvhw7obeG/qYDM8/zAJwrgirMzF:7TTCD0okhUqMwECGF
IMP BD4E054811FEAB07339938AF1BFB41AD
PESHA1 71DD704391CCB3E096B092ED5141B66023AAE881
PE256 5B06749080651E91828D5071BA2F862E8384B3604EB9925408EF7875AB2B97D2

DLL Exports:

Function Name Ordinal Type
I_NetLogonSamLogonWithFlags 53 Exported Function
I_NetLogonSendToSam 54 Exported Function
I_NetLogonSamLogonEx 52 Exported Function
I_NetLogonSamLogoff 50 Exported Function
I_NetLogonSamLogon 51 Exported Function
I_NetServerAuthenticate 58 Exported Function
I_NetServerAuthenticate2 59 Exported Function
I_NetQuerySecureChannelDCInfo 57 Exported Function
I_NetLogonUasLogoff 55 Exported Function
I_NetLogonUasLogon 56 Exported Function
I_NetlogonGetTrustRid 71 Exported Function
I_NetlogonComputeClientSignature 68 Exported Function
I_NetlogonComputeServerDigest 69 Exported Function
I_NetlogonComputeClientDigest 67 Exported Function
I_NetGetDCList 44 Exported Function
I_NetGetForestTrustInformation 45 Exported Function
I_NetLogonGetCapabilities 48 Exported Function
I_NetLogonGetDomainInfo 49 Exported Function
I_NetLogonControl2 47 Exported Function
I_NetlogonComputeServerSignature 70 Exported Function
I_NetLogonControl 46 Exported Function
I_NetServerAuthenticate3 60 Exported Function
NetLogonSetServiceBits 80 Exported Function
NetQueryServiceAccount 81 Exported Function
NetLogonGetTimeServiceParentDomain 79 Exported Function
NetGetDCName 77 Exported Function
NetIsServiceAccount 78 Exported Function
NlBindingSetAuthInfo 85 Exported Function
NlSetDsIsCloningPDC 86 Exported Function
NlBindingRemoveServerFromCache 84 Exported Function
NetRemoveServiceAccount 82 Exported Function
NlBindingAddServerToCache 83 Exported Function
NetGetAnyDCName 76 Exported Function
I_NetServerPasswordSet2 64 Exported Function
I_NetServerReqChallenge 65 Exported Function
I_NetServerPasswordSet 63 Exported Function
I_NetServerGetTrustInfo 61 Exported Function
I_NetServerPasswordGet 62 Exported Function
NetEnumerateServiceAccounts 74 Exported Function
NetEnumerateTrustedDomains 75 Exported Function
NetAddServiceAccount 73 Exported Function
I_NetServerTrustPasswordsGet 66 Exported Function
I_RpcExtInitializeExtensionPoint 72 Exported Function
DsEnumerateDomainTrustsA 15 Exported Function
DsEnumerateDomainTrustsW 16 Exported Function
DsDeregisterDnsHostRecordsW 14 Exported Function
DsAddressToSiteNamesW 12 Exported Function
DsDeregisterDnsHostRecordsA 13 Exported Function
DsGetDcNameWithAccountA 20 Exported Function
DsGetDcNameWithAccountW 21 Exported Function
DsGetDcNameW 19 Exported Function
DsGetDcCloseW 17 Exported Function
DsGetDcNameA 18 Exported Function
DsAddressToSiteNamesExW 11 Exported Function
AuthzrExtGetInformationFromContext 4 Exported Function
AuthzrExtInitializeCompoundContext 5 Exported Function
AuthzrExtFreeResourceManager 3 Exported Function
AuthzrExtAccessCheck 1 Exported Function
AuthzrExtFreeContext 2 Exported Function
DsAddressToSiteNamesA 9 Exported Function
DsAddressToSiteNamesExA 10 Exported Function
AuthzrExtModifyClaims 8 Exported Function
AuthzrExtInitializeContextFromSid 6 Exported Function
AuthzrExtInitializeRemoteResourceManager 7 Exported Function
DsGetDcNextA 22 Exported Function
I_NetChainSetClientAttributes 37 Exported Function
I_NetChainSetClientAttributes2 38 Exported Function
I_NetAccountSync 36 Exported Function
I_DsUpdateReadOnlyServerDnsRecords 34 Exported Function
I_NetAccountDeltas 35 Exported Function
I_NetDatabaseSync2 42 Exported Function
I_NetExtendMachinePasswordExpirationTimeout 43 Exported Function
I_NetDatabaseSync 41 Exported Function
I_NetDatabaseDeltas 39 Exported Function
I_NetDatabaseRedo 40 Exported Function
DsValidateSubnetNameW 33 Exported Function
DsGetDcSiteCoverageA 26 Exported Function
DsGetDcSiteCoverageW 27 Exported Function
DsGetDcOpenW 25 Exported Function
DsGetDcNextW 23 Exported Function
DsGetDcOpenA 24 Exported Function
DsMergeForestTrustInformationW 31 Exported Function
DsValidateSubnetNameA 32 Exported Function
DsGetSiteNameW 30 Exported Function
DsGetForestTrustInformationW 28 Exported Function
DsGetSiteNameA 29 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: LOGONCLI.DLL
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.388 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.388
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/70
  • VirusTotal Link: https://www.virustotal.com/gui/file/6d95876ca1a91bce22d09d008976047156496cc5c85909d5c6554042faf34d7e/detection/

Possible Misuse

The following table contains possible examples of logoncli.dll being misused. While logoncli.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_mimikatz_inmemory_detection.yml - 'logoncli.dll' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.