urlmon.dll

  • File Path: C:\Windows\SysWOW64\urlmon.dll
  • Description: OLE32 Extensions for Win32

Hashes

Type Hash
MD5 961C5D1259EB1423188F2B6985D0213A
SHA1 42CEA3C01C51EAC4DCEE610C51633DB4CFE61689
SHA256 869F81C986ACC06F0990E4FCF3629BFCEABD79875726AB3C263D08C940EDD0B8
SHA384 4DA45E1C1F84FCC31374EAE88E2287FCB0A7F8A364D1E3369447873FCA262B022F1B05041064117A969FF366653BBF8C
SHA512 F0EA40D3D0428FBBB5B021F3300EDC63949634791447A5C6AB9A73A16F18435F8E3074C4F2868E53917C7685BA8CC6CDB3F7F7E6254A34DFD3B0317EE5F74682
SSDEEP 24576:n5MZBgRoOoXmpenpWiTFT2EYudyPWY4zEA7VmbIfDxc+h0c2ipS5Bu2TjbRm4vBu:niBuoXpt0aEUjrxchBh80lVjsM5HMa
IMP 130E04704619C14FB49C98CD06A065F6
PESHA1 73F7B017B3F479B02F4F5FFD5AC946371CB141B0
PE256 67E8829C82895F0D7A2BFB515BF56E601D216116FFF4093E2BA3D8B18DE7439D

DLL Exports:

Function Name Ordinal Type
IsIntranetAvailable 202 Exported Function
IsDWORDProperty 119 Exported Function
IsLoggingEnabledA 204 Exported Function
IsJITInProgress 203 Exported Function
IEInstallScope 199 Exported Function
IEGetUserPrivateNamespaceName 198 Exported Function
IsAsyncMoniker 201 Exported Function
IntlPercentEncodeNormalize 200 Exported Function
PrivateCoInstall 209 Exported Function
ObtainUserAgentString 208 Exported Function
QueryClsidAssociation 211 Exported Function
QueryAssociations 210 Exported Function
IsStringProperty 120 Exported Function
IsLoggingEnabledW 205 Exported Function
MkParseDisplayNameEx 207 Exported Function
IsValidURL 206 Exported Function
GetPropertyName 118 Exported Function
GetPropertyFromName 117 Exported Function
GetUrlmonThreadNotificationHwnd 190 Exported Function
GetSoftwareUpdateInfo 189 Exported Function
GetLabelsFromNamedHost 187 Exported Function
GetIUriPriv2 185 Exported Function
GetPortFromUrlScheme 110 Exported Function
GetMarkOfTheWeb 188 Exported Function
HlinkSimpleNavigateToMoniker 196 Exported Function
HlinkNavigateString 195 Exported Function
IECompatLogCSSFix 322 Exported Function
HlinkSimpleNavigateToString 197 Exported Function
HlinkGoBack 192 Exported Function
GetZoneFromAlternateDataStreamEx 191 Exported Function
HlinkNavigateMoniker 194 Exported Function
HlinkGoForward 193 Exported Function
RegisterBindStatusCallback 212 Exported Function
UrlMkGetSessionOption 240 Exported Function
UrlMkBuildVersion 239 Exported Function
UrlmonCleanupCurrentThread 242 Exported Function
UrlMkSetSessionOption 241 Exported Function
URLDownloadToFileA 229 Exported Function
URLDownloadToCacheFileW 228 Exported Function
URLDownloadW 231 Exported Function
URLDownloadToFileW 230 Exported Function
URLOpenStreamW 237 Exported Function
URLOpenStreamA 236 Exported Function
ZonesReInit 244 Exported Function
WriteHitLogging 243 Exported Function
URLOpenBlockingStreamW 233 Exported Function
URLOpenBlockingStreamA 232 Exported Function
URLOpenPullStreamW 235 Exported Function
URLOpenPullStreamA 234 Exported Function
RestrictHTTP2 218 Exported Function
ReleaseBindInfo 217 Exported Function
RevokeFormatEnumerator 220 Exported Function
RevokeBindStatusCallback 219 Exported Function
RegisterMediaTypeClass 214 Exported Function
RegisterFormatEnumerator 213 Exported Function
RegisterWebPlatformPermanentSecurityManager 216 Exported Function
RegisterMediaTypes 215 Exported Function
UnregisterWebPlatformPermanentSecurityManager 238 Exported Function
ShowTrustAlertDialog 225 Exported Function
URLDownloadToCacheFileA 227 Exported Function
URLDownloadA 226 Exported Function
SetSoftwareUpdateAdvertisementState 222 Exported Function
SetAccessForIEAppContainer 221 Exported Function
ShouldShowIntranetWarningSecband 224 Exported Function
ShouldDisplayPunycodeForUri 223 Exported Function
GetIUriPriv 186 Exported Function
CoInternetGetSession 143 Exported Function
CoInternetGetSecurityUrlEx 142 Exported Function
CoInternetIsFeatureEnabledForIUri 145 Exported Function
CoInternetIsFeatureEnabled 144 Exported Function
CoInternetGetMobileBrowserForceDesktopMode 139 Exported Function
CoInternetGetMobileBrowserAppCompatMode 138 Exported Function
CoInternetGetSecurityUrl 141 Exported Function
CoInternetGetProtocolFlags 140 Exported Function
CoInternetSetFeatureEnabled 151 Exported Function
CoInternetQueryInfo 150 Exported Function
CoInternetSetMobileBrowserForceDesktopMode 153 Exported Function
CoInternetSetMobileBrowserAppCompatMode 152 Exported Function
CoInternetIsFeatureZoneElevationEnabled 147 Exported Function
CoInternetIsFeatureEnabledForUrl 146 Exported Function
CoInternetParseUrl 149 Exported Function
CoInternetParseIUri 148 Exported Function
CDLGetLongPathNameW 126 Exported Function
CDLGetLongPathNameA 125 Exported Function
CoInstall 129 Exported Function
CoGetClassObjectFromURL 128 Exported Function
AsyncInstallDistributionUnit 122 Exported Function
AsyncGetClassBits 121 Exported Function
CAuthenticateHostUI_CreateInstance 124 Exported Function
BindAsyncMoniker 123 Exported Function
CoInternetCreateSecurityManager 135 Exported Function
CoInternetCompareUrl 134 Exported Function
CoInternetFeatureSettingsChanged 137 Exported Function
CoInternetCreateZoneManager 136 Exported Function
CoInternetCombineIUri 131 Exported Function
CoInternetCanonicalizeIUri 130 Exported Function
CoInternetCombineUrlEx 133 Exported Function
CoInternetCombineUrl 132 Exported Function
CompareSecurityIds 154 Exported Function
Extract 175 Exported Function
DllUnregisterServer 174 Exported Function
FileBearsMarkOfTheWeb 109 Exported Function
FaultInIEFeature 176 Exported Function
DllInstall 171 Exported Function
DllGetClassObject 170 Exported Function
DllRegisterServerEx 173 Exported Function
DllRegisterServer 172 Exported Function
GetClassURL 182 Exported Function
GetClassFileOrMime 181 Exported Function
GetIDNFlagsForUri 184 Exported Function
GetComponentIDFromCLSSPEC 183 Exported Function
FindMediaTypeClass 178 Exported Function
FindMediaType 177 Exported Function
GetAddSitesFileUrl 180 Exported Function
FindMimeFromData 179 Exported Function
CreateAsyncBindCtxEx 159 Exported Function
CreateAsyncBindCtx 158 Exported Function
CreateIUriBuilder 161 Exported Function
CreateFormatEnumerator 160 Exported Function
CopyBindInfo 156 Exported Function
CompatFlagsFromClsid 155 Exported Function
CORPolicyProvider 127 Exported Function
CopyStgMedium 157 Exported Function
CreateURLMonikerEx 164 Exported Function
CreateURLMoniker 162 Exported Function
DllCanUnloadNow 169 Exported Function
CreateURLMonikerEx2 163 Exported Function
CreateUriFromMultiByteString 166 Exported Function
CreateUri 165 Exported Function
CreateUriWithFragment 168 Exported Function
CreateUriPriv 167 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: UrlMon.dll.mui
  • Product Name: Internet Explorer
  • Company Name: Microsoft Corporation
  • File Version: 11.00.19041.1 (WinBuild.160101.0800)
  • Product Version: 11.00.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/70
  • VirusTotal Link: https://www.virustotal.com/gui/file/869f81c986acc06f0990e4fcf3629bfceabd79875726ab3c263d08c940edd0b8/detection/

Possible Misuse

The following table contains possible examples of urlmon.dll being misused. While urlmon.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
signature-base apt_putterpanda.yar $s3 = “urlmon.dll” fullword ascii /* PEStudio Blacklist: strings / / score: ‘5’ / / Goodware String - occured 471 times */ CC BY-NC 4.0
signature-base apt_uboat_rat.yar $s5 = “urlmon.dll” ascii CC BY-NC 4.0

MIT License. Copyright (c) 2020-2021 Strontic.