rcdll.exe
First submission 2024-10-14 16:17:03
File details
File type: | PE32+ executable (console) x86-64, for MS Windows |
Mime type: | application/x-dosexec |
File size: | 68.47 KB (70112 bytes) |
Compile time: | 2025-09-23 16:13:25 |
MD5: | d20afbb8f3aef32336906762dd5496f1 |
SHA1: | e956c318db4d5d9344672ee8bd9cca73ec32fc84 |
SHA256: | a182e516ba0cd2c38600c6f4eab17666da12ae485c5537050e0191aaedd7dade |
Import Hash : | 14364fd8f9fe355c6dc3ab49d1f37ab6 |
Sections 6 | .text .rdata .data .pdata .rsrc .reloc |
Directories 5 | import resource debug relocation security |
File features detected
URLs, FQDN and IP indicators 1
PE Sections 0 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
.text | 0x1000 | 0x9549 | 38400 | a8bfa2311e8faf44cc7e5fb3f78e72b9cff223ef | 9b8e5fe109b4f774d19be647b994317f | |
.rdata | 0xb000 | 0x3286 | 13312 | a51623290625c571d8044e7d0ec489cdbf900eea | b6453509ec5a5459750ae7a3a3f14226 | |
.data | 0xf000 | 0x31c0 | 4608 | 5c7f0f8c2e0ab98c2da9569148e372ed7bc46f2d | 5f343dddcaa0fdd57e170f5162386634 | |
.pdata | 0x13000 | 0x7bc | 2048 | 304cf0d26119f6a17124613a4b0cfb0a236ccd78 | d8798b753aaacfd9ba7c951a2f8d0ad7 | |
.rsrc | 0x14000 | 0x5e8 | 1536 | ce58bdad045b0a971a4205e8f1f6f651fe5174a6 | c97283f2e3176b96104e41f76d08d439 | |
.reloc | 0x15000 | 0x160 | 512 | 5a47a691d5ec8fea272b68a102bcade9d6875c7f | 5baacfceda7672aa17247c8e620162d2 |
PE Resources 2
Name | Language | Sublanguage | Offset | Size | Data |
---|---|---|---|---|---|
RT_VERSION | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x14250 | 916 | |
RT_MANIFEST | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x140a0 | 427 |
Meta infos 9
LegalCopyright: | \xa9 Microsoft Corporation. All rights reserved. |
InternalName: | rc.exe |
FileVersion: | 10.0.19041.685 (WinBuild.160101.0800) |
CompanyName: | Microsoft Corporation |
ProductVersion: | 10.0.19041.685 |
FileDescription: | Microsoft Resource Compiler |
Translation: | 0x0409 0x04b0 |
OriginalFilename: | rc.exe |
ProductName: | Microsoft\xae Windows\xae Operating System |
Packers detected 1
Microsoft Visual C++ 8.0 (DLL) |
Anti debug functions 4
GetLastError |
OutputDebugStringA |
TerminateProcess |
UnhandledExceptionFilter |
File signature
MD5 | SHA1 | Block size | Virtual Address |
---|---|---|---|
972d7185d4914efbf8ac1b0e3648fca9 | 4cef3f631379e2ebe0e19a6a005b3799d1607678 | 8672 | 61440 |
Strings analysis - File found
Library |
USER32.dll |
mscoree.dll |
RCDLL.dll |
KERNEL32.dll |
Strings analysis - Possible URLs found 8
http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0 |
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z |
http://www.microsoft.com/pki/certs/MicCodSigPCA_2010-07-06.crt0 |
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl0Z |
http://www.microsoft.com/windows0 |
http://www.microsoft.com/PKI/docs/CPS/default.htm0@ |
http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0 |
http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl0Z |