URL.DLL

Windows Internet Explorer

Microsoft Corporation

The URL (Shortcut Shell Extension) library provides Internet Explorer the ability to create URL shortcuts. It is included with Windows 7.
Publisher:
Microsoft Corporation

Product:
Windows® Internet Explorer

Description:
Internet Shortcut Shell Extension DLL

 
Part of the Windows 7 (for Internet Explorer 9) Operating System

Version:
9.00.8112.16555 (WIN7_IE9_GDR_ESCROW.140528-1048)

MD5:
96a7f98f7ffdc105f3772bf008d3387f

SHA-1:
0dc14c7962567bc85b26c03195917f740848d5d9

SHA-256:
f050dbf464df55f1133ac3d5db7314ed52dcf5ba0db4c376249b367a341bd906

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
12/9/2016 4:43:14 AM UTC  (a few moments ago)

File size:
231.5 KB (237,056 bytes)

Product version:
9.00.8112.16555

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
URL.DLL

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\Windows\System32\url.dll

File PE Metadata
Compilation timestamp:
5/28/2014 7:30:06 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:aMMHMMMyMMMZMMMVcRMebzDq0DKF/2Ar++X:aMMHMMMyMMMZMMMVcR9bzOco2ArZX

Entry address:
0x1070

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 0F, 84, 22, 02, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, EB, 07, 00, 90, 90, 90, 90, 90, 90, 4C, 89, 44, 24, 18, 89, 54, 24, 10, 48, 89, 4C, 24, 08, 53, 56, 57, 48, 81, EC, 40, 01, 00, 00, 8B, FA, 48, 8B, F1, BB, 01, 00, 00, 00, 89, 5C, 24, 20, 89, 15, E4, 34, 00, 00, 85, D2, 0F, 84, BC, 03, 00, 00, 83, FA, 01, 74, 05, 83, FA, 02, 75, 33, 48, 8B...
 
[+]

Entropy:
5.5620

Code size:
6 KB (6,144 bytes)

Shell Open Command
Open type:
telnet

Command:
"C:\Windows\System32\rundll32.exe" "C:\Windows\System32\url.dll",telnetprotocolhandler %l