rundll32.exe

Run a DLL as an App

Microsoft Corporation

Rundll allows various libraries (DLL files) to be loaded as a process by allowing the operating system to invoke a function exported from a DLL. It is included with Windows Server 2003 (SP1). The file has been seen being downloaded from www.goofwear.com and multiple other hosts.
Publisher:
Microsoft Corporation

Product:
Microsoft® Windows® Operating System

Description:
Run a DLL as an App

 
Part of the Windows Server 2003 (Service Pack 1) Operating System

Version:
5.2.3790.1830 (srv03_sp1_rtm.050324-1447)

MD5:
f9a942758040b5b60fb6315753ce94c3

SHA-1:
42effc11f97e7e8744e216f7a859a12baaeb4b8c

SHA-256:
28ebfe91ace0da7b9484690491e167ca514b26023ac679f5f2a12b2bd3a451e9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/16/2024 10:08:22 AM UTC  (today)

File size:
36.5 KB (37,376 bytes)

Product version:
5.2.3790.1830

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
RUNDLL.EXE

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\rundll32.exe

File PE Metadata
Compilation timestamp:
3/24/2005 6:43:11 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
384:6HFTB1fgeAs10I24IR11Ic2NRhbHeJh8+oXBjxJd5IyYQGSbdkDjkoebjDISMWq5:utGvsLoLYbSEln5IyYpamDjobj8SIrN

Entry address:
0x2500

Entry point:
48, 8B, C4, 48, 81, EC, C8, 00, 00, 00, 48, 89, 58, 18, 48, 89, 78, 20, 48, 8D, 48, 88, FF, 15, 5C, EB, FF, FF, 66, 81, 3D, DB, DA, FF, FF, 4D, 5A, 74, 15, 33, DB, 89, 9C, 24, D0, 00, 00, 00, 48, 8D, 3D, C9, DA, FF, FF, E9, 8E, 00, 00, 00, 48, 63, 05, F9, DA, FF, FF, 48, 8D, 3D, B6, DA, FF, FF, 48, 03, C7, 81, 38, 50, 45, 00, 00, 74, 0B, 33, DB, 89, 9C, 24, D0, 00, 00, 00, EB, 6A, 0F, B7, 48, 18, 81, F9, 0B, 01, 00, 00, 74, 3B, 81, F9, 0B, 02, 00, 00, 74, 0B, 33, DB, 89, 9C, 24, D0, 00, 00, 00, EB, 4B, 83...
 
[+]

Entropy:
5.7221

Code size:
8.5 KB (8,704 bytes)

The file rundll32.exe has been seen being distributed by the following 2 URLs.