urlmon.dll

  • File Path: C:\Windows\system32\urlmon.dll
  • Description: OLE32 Extensions for Win32

Hashes

Type Hash
MD5 DF0E7E262F4E6B279B161CDC02194DEB
SHA1 9AB65B81B6A2C75CC8C580D2483C0E667C12CB0C
SHA256 B5A4F52A72E8B04800DB609D9F7DF5F22AD1610DAD1014282CF37083BDD9407E
SHA384 61F83D006D14621EB3F717A61C7F3DBD86584F1B00CC468E4A86031C5F52DFE01C87F22C84B9C95D7CE01270747D29CA
SHA512 36AE6BF9B52909393B023BF6E39290EFB7B8597A018DF5DCEF67CD60F0E27C452EFCB0C9DF15843B4E29C19FD56C7739AE019DCA5DBFD0A3F60DA12D8C8804AE
SSDEEP 49152:3T91sAPa+/v3GL+043N36Wd/Y0K3rsM5H:5r6WB
IMP 9A11A923506713BB8A5ABA3F830DDE03
PESHA1 78721AB7B484A71F77CAD295A4CD66C63F74C021
PE256 F6991FE1B1B2F531C1D9803443C3E15A67EF237812666662DD89BA3E1B580657

DLL Exports:

Function Name Ordinal Type
IsIntranetAvailable 202 Exported Function
IsDWORDProperty 119 Exported Function
IsLoggingEnabledA 204 Exported Function
IsJITInProgress 203 Exported Function
IEInstallScope 199 Exported Function
IEGetUserPrivateNamespaceName 198 Exported Function
IsAsyncMoniker 201 Exported Function
IntlPercentEncodeNormalize 200 Exported Function
PrivateCoInstall 209 Exported Function
ObtainUserAgentString 208 Exported Function
QueryClsidAssociation 211 Exported Function
QueryAssociations 210 Exported Function
IsStringProperty 120 Exported Function
IsLoggingEnabledW 205 Exported Function
MkParseDisplayNameEx 207 Exported Function
IsValidURL 206 Exported Function
GetPropertyName 118 Exported Function
GetPropertyFromName 117 Exported Function
GetUrlmonThreadNotificationHwnd 190 Exported Function
GetSoftwareUpdateInfo 189 Exported Function
GetLabelsFromNamedHost 187 Exported Function
GetIUriPriv2 186 Exported Function
GetPortFromUrlScheme 110 Exported Function
GetMarkOfTheWeb 188 Exported Function
HlinkSimpleNavigateToMoniker 196 Exported Function
HlinkNavigateString 195 Exported Function
IECompatLogCSSFix 322 Exported Function
HlinkSimpleNavigateToString 197 Exported Function
HlinkGoBack 192 Exported Function
GetZoneFromAlternateDataStreamEx 191 Exported Function
HlinkNavigateMoniker 194 Exported Function
HlinkGoForward 193 Exported Function
RegisterBindStatusCallback 212 Exported Function
UrlMkGetSessionOption 240 Exported Function
UrlMkBuildVersion 239 Exported Function
UrlmonCleanupCurrentThread 242 Exported Function
UrlMkSetSessionOption 241 Exported Function
URLDownloadToFileA 229 Exported Function
URLDownloadToCacheFileW 228 Exported Function
URLDownloadW 231 Exported Function
URLDownloadToFileW 230 Exported Function
URLOpenStreamW 237 Exported Function
URLOpenStreamA 236 Exported Function
ZonesReInit 244 Exported Function
WriteHitLogging 243 Exported Function
URLOpenBlockingStreamW 233 Exported Function
URLOpenBlockingStreamA 232 Exported Function
URLOpenPullStreamW 235 Exported Function
URLOpenPullStreamA 234 Exported Function
RestrictHTTP2 218 Exported Function
ReleaseBindInfo 217 Exported Function
RevokeFormatEnumerator 220 Exported Function
RevokeBindStatusCallback 219 Exported Function
RegisterMediaTypeClass 214 Exported Function
RegisterFormatEnumerator 213 Exported Function
RegisterWebPlatformPermanentSecurityManager 216 Exported Function
RegisterMediaTypes 215 Exported Function
UnregisterWebPlatformPermanentSecurityManager 238 Exported Function
ShowTrustAlertDialog 225 Exported Function
URLDownloadToCacheFileA 227 Exported Function
URLDownloadA 226 Exported Function
SetSoftwareUpdateAdvertisementState 222 Exported Function
SetAccessForIEAppContainer 221 Exported Function
ShouldShowIntranetWarningSecband 224 Exported Function
ShouldDisplayPunycodeForUri 223 Exported Function
GetIUriPriv 185 Exported Function
CoInternetGetSession 143 Exported Function
CoInternetGetSecurityUrlEx 142 Exported Function
CoInternetIsFeatureEnabledForIUri 145 Exported Function
CoInternetIsFeatureEnabled 144 Exported Function
CoInternetGetMobileBrowserForceDesktopMode 139 Exported Function
CoInternetGetMobileBrowserAppCompatMode 138 Exported Function
CoInternetGetSecurityUrl 141 Exported Function
CoInternetGetProtocolFlags 140 Exported Function
CoInternetSetFeatureEnabled 151 Exported Function
CoInternetQueryInfo 150 Exported Function
CoInternetSetMobileBrowserForceDesktopMode 153 Exported Function
CoInternetSetMobileBrowserAppCompatMode 152 Exported Function
CoInternetIsFeatureZoneElevationEnabled 147 Exported Function
CoInternetIsFeatureEnabledForUrl 146 Exported Function
CoInternetParseUrl 149 Exported Function
CoInternetParseIUri 148 Exported Function
CDLGetLongPathNameW 126 Exported Function
CDLGetLongPathNameA 125 Exported Function
CoInstall 129 Exported Function
CoGetClassObjectFromURL 128 Exported Function
AsyncInstallDistributionUnit 122 Exported Function
AsyncGetClassBits 121 Exported Function
CAuthenticateHostUI_CreateInstance 124 Exported Function
BindAsyncMoniker 123 Exported Function
CoInternetCreateSecurityManager 135 Exported Function
CoInternetCompareUrl 134 Exported Function
CoInternetFeatureSettingsChanged 137 Exported Function
CoInternetCreateZoneManager 136 Exported Function
CoInternetCombineIUri 131 Exported Function
CoInternetCanonicalizeIUri 130 Exported Function
CoInternetCombineUrlEx 133 Exported Function
CoInternetCombineUrl 132 Exported Function
CompareSecurityIds 154 Exported Function
Extract 175 Exported Function
DllUnregisterServer 174 Exported Function
FileBearsMarkOfTheWeb 109 Exported Function
FaultInIEFeature 176 Exported Function
DllInstall 171 Exported Function
DllGetClassObject 170 Exported Function
DllRegisterServerEx 173 Exported Function
DllRegisterServer 172 Exported Function
GetClassURL 182 Exported Function
GetClassFileOrMime 181 Exported Function
GetIDNFlagsForUri 184 Exported Function
GetComponentIDFromCLSSPEC 183 Exported Function
FindMediaTypeClass 178 Exported Function
FindMediaType 177 Exported Function
GetAddSitesFileUrl 180 Exported Function
FindMimeFromData 179 Exported Function
CreateAsyncBindCtxEx 159 Exported Function
CreateAsyncBindCtx 158 Exported Function
CreateIUriBuilder 161 Exported Function
CreateFormatEnumerator 160 Exported Function
CopyBindInfo 156 Exported Function
CompatFlagsFromClsid 155 Exported Function
CORPolicyProvider 127 Exported Function
CopyStgMedium 157 Exported Function
CreateURLMonikerEx 163 Exported Function
CreateURLMoniker 162 Exported Function
DllCanUnloadNow 169 Exported Function
CreateURLMonikerEx2 164 Exported Function
CreateUriFromMultiByteString 166 Exported Function
CreateUri 165 Exported Function
CreateUriWithFragment 168 Exported Function
CreateUriPriv 167 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: UrlMon.dll.mui
  • Product Name: Internet Explorer
  • Company Name: Microsoft Corporation
  • File Version: 11.00.19041.1 (WinBuild.160101.0800)
  • Product Version: 11.00.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/70
  • VirusTotal Link: https://www.virustotal.com/gui/file/b5a4f52a72e8b04800db609d9f7df5f22ad1610dad1014282cf37083bdd9407e/detection/

Possible Misuse

The following table contains possible examples of urlmon.dll being misused. While urlmon.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
signature-base apt_putterpanda.yar $s3 = “urlmon.dll” fullword ascii /* PEStudio Blacklist: strings / / score: ‘5’ / / Goodware String - occured 471 times */ CC BY-NC 4.0
signature-base apt_uboat_rat.yar $s5 = “urlmon.dll” ascii CC BY-NC 4.0

MIT License. Copyright (c) 2020-2021 Strontic.