winhttp.dll

  • File Path: C:\Windows\SysWOW64\winhttp.dll
  • Description: Windows HTTP Services

Hashes

Type Hash
MD5 13FF834E4585C70CA9F6CD9A4B89090F
SHA1 C3E5BF65B3C9D09077526347688CB85953EFB066
SHA256 A792C1E4FCB7D6D2A9A58B6560CFDC2C2E3B5746B4F8178F7024C1EF673581DC
SHA384 41C674BFEA7AE6B1214ED3872AF11A64E821F396177564F82C620BC15D8C63FA18DCB0E280113D3AD7FE72A4144D882A
SHA512 78BF3358FC015F2412ADA98388BD9B483A0BCB924C4F2B3532265D9857A84106CAF7C7BAD447DF870910DAB0E2D170624781C9E5C6253025CC850DE378556AA8
SSDEEP 24576:T3GR2DcGRSv9mvcYNU+XtCkVy66Ied4UIs76Hg5XCYgh:T3GRiRSMvcodf64ZA0g5XHgh
IMP 2495D62D5FACA5609F59D258A873D263
PESHA1 61D6EB33894270E5942A5C6853A8186E39FADAFE
PE256 7F1E4ACE6497653987E4959CCE301EB084AEA18B24AC403FFB0E4A28F4CC5A87

DLL Exports:

Function Name Ordinal Type
WinHttpReadData 47 Exported Function
WinHttpReadProxySettings 48 Exported Function
WinHttpQueryHeaders 45 Exported Function
WinHttpQueryOption 46 Exported Function
WinHttpResetAutoProxy 51 Exported Function
WinHttpSaveProxyCredentials 52 Exported Function
WinHttpReadProxySettingsHvsi 49 Exported Function
WinHttpReceiveResponse 50 Exported Function
WinHttpQueryDataAvailable 44 Exported Function
WinHttpGetTunnelSocket 39 Exported Function
WinHttpOpen 40 Exported Function
WinHttpGetProxyResultEx 37 Exported Function
WinHttpGetProxySettingsVersion 38 Exported Function
WinHttpProbeConnectivity 42 Exported Function
WinHttpQueryAuthSchemes 43 Exported Function
WinHttpOpenRequest 41 Exported Function
WinHttpPacJsWorkerMain 1 Exported Function
WinHttpWebSocketQueryCloseStatus 64 Exported Function
WinHttpWebSocketReceive 65 Exported Function
WinHttpWebSocketClose 62 Exported Function
WinHttpWebSocketCompleteUpgrade 63 Exported Function
WinHttpWriteData 68 Exported Function
WinHttpWriteProxySettings 69 Exported Function
WinHttpWebSocketSend 66 Exported Function
WinHttpWebSocketShutdown 67 Exported Function
WinHttpTimeToSystemTime 61 Exported Function
WinHttpSetDefaultProxyConfiguration 55 Exported Function
WinHttpSetOption 56 Exported Function
WinHttpSendRequest 53 Exported Function
WinHttpSetCredentials 54 Exported Function
WinHttpSetTimeouts 59 Exported Function
WinHttpTimeFromSystemTime 60 Exported Function
WinHttpSetProxySettingsPerUser 57 Exported Function
WinHttpSetStatusCallback 58 Exported Function
WinHttpGetProxyResult 36 Exported Function
WinHttpConnectionDeleteProxyInfo 13 Exported Function
WinHttpConnectionFreeNameList 14 Exported Function
WinHttpConnect 11 Exported Function
WinHttpConnectionDeletePolicyEntries 12 Exported Function
WinHttpConnectionGetNameList 17 Exported Function
WinHttpConnectionGetProxyInfo 18 Exported Function
WinHttpConnectionFreeProxyInfo 15 Exported Function
WinHttpConnectionFreeProxyList 16 Exported Function
WinHttpCloseHandle 10 Exported Function
Private1 4 Exported Function
SvchostPushServiceGlobals 5 Exported Function
DllCanUnloadNow 2 Exported Function
DllGetClassObject 3 Exported Function
WinHttpAutoProxySvcMain 8 Exported Function
WinHttpCheckPlatform 9 Exported Function
WinHttpAddRequestHeaders 6 Exported Function
WinHttpAddRequestHeadersEx 7 Exported Function
WinHttpGetDefaultProxyConfiguration 30 Exported Function
WinHttpGetIEProxyConfigForCurrentUser 31 Exported Function
WinHttpFreeProxyResultEx 28 Exported Function
WinHttpFreeProxySettings 29 Exported Function
WinHttpGetProxyForUrlEx2 33 Exported Function
WinHttpGetProxyForUrlHvsi 35 Exported Function
WinHttpGetProxyForUrl 32 Exported Function
WinHttpGetProxyForUrlEx 34 Exported Function
WinHttpFreeProxyResult 27 Exported Function
WinHttpConnectionSetProxyInfo 21 Exported Function
WinHttpConnectionUpdateIfIndexTable 22 Exported Function
WinHttpConnectionGetProxyList 19 Exported Function
WinHttpConnectionSetPolicyEntries 20 Exported Function
WinHttpCreateUrl 25 Exported Function
WinHttpDetectAutoProxyConfigUrl 26 Exported Function
WinHttpCrackUrl 23 Exported Function
WinHttpCreateProxyResolver 24 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: winhttp.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.264 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.264
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/61
  • VirusTotal Link: https://www.virustotal.com/gui/file/a792c1e4fcb7d6d2a9a58b6560cfdc2c2e3b5746b4f8178f7024c1ef673581dc/detection/

Possible Misuse

The following table contains possible examples of winhttp.dll being misused. While winhttp.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
malware-ioc rtm winhttp.dll © ESET 2014-2018
signature-base apt_lazarus_jun18.yar $s1 = “Winhttp.dll” fullword ascii CC BY-NC 4.0
signature-base crime_icedid.yar $string6 = “WINHTTP.dll” fullword CC BY-NC 4.0
signature-base crime_ransom_darkside.yar $knownDLLs1 = “WINHTTP.dll” fullword CC BY-NC 4.0

MIT License. Copyright (c) 2020-2021 Strontic.