Microsoft.Practices.EnterpriseLibrary.Common.dll

Microsoft Enterprise Library for .NET

Iminent

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The module Microsoft.Practices.EnterpriseLibrary.Common.dll, “Enterprise Library Shared Library” by Iminent has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Iminent)

Product:
Microsoft Enterprise Library for .NET

Description:
Enterprise Library Shared Library

Version:
5.0.414.0

MD5:
d5917a0cf89d23147ca39dde9edbf28f

SHA-1:
1c8556fa1a1441006bb36185796907601defe656

SHA-256:
5b6e674e6ee6402286dd37d6c42107bb41b47d10523e0451bb2b25ec03df74a6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/20/2024 5:32:25 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien.Iminent (M)
16.2.12.8

File size:
326 KB (333,800 bytes)

Product version:
5.0.414.0

Original file name:
Microsoft.Practices.EnterpriseLibrary.Common.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\iminent\microsoft.practices.enterpriselibrary.common.dll

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/26/2010 4:31:06 PM

Valid to:
1/27/2012 4:31:03 PM

Subject:
CN=Iminent, O=Iminent, L=Paris, S=France, C=FR

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001266AC7D81A

File PE Metadata
Compilation timestamp:
4/17/2010 1:11:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:oruHKLs3lXqh91pAEGn962ebvKQkOTuBuyRRc/Ik5GqsXJcr64z61ViJXKXROi2b:8uHRwBGnYpY9XJ461ViJXKNlsTji

Entry address:
0x4E4BE

Entry point:
FF, 25, 00, 20, 00, 11, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.4459

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
308 KB (315,392 bytes)