The libvlccore(MALWARE) dll (VLC media player) VideoLAN File Malware Analysis
Gridinsoft Logo

The libvlccore(MALWARE)_dll (VLC media player) File Analysis

Technical Analysis

File Name libvlccore(MALWARE)_dll
File Type
PE32+ executable (DLL) (console) x86-64, for MS Windows
Scanner Version 1.0.210.174
Database Version 2025-03-05 20:00:37 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
2,806,392
File Size (bytes)
2025-03-05
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
01f6f807faf190a38bded7bb1c105c18
SHA1
22c9fbe9a92be74fe857aaea020025a78c52365f
SHA256
1fed66191a0cda73b37ba2bc58f6ebad3ee1ec4f8193608f3ac1d8ad2b97640d
SHA512
e35201ce08d51cf3c7580ec390e4eee228dbe17b51ee0885f748a65f36f2bb6a1c4deee10ce9be92d6b6d58db8a59b8d1f93dc8108e9ae7ef0f059c62d2faee9
ImpHash
dce96bc6319a78e5eaf9315128c98209

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x1400013d0
Compilation Time 2060-11-11 05:00:16
Checksum 0x002af735 (Actual: 0x002af735)
OS Version 4.0
PEiD Signatures PE32+ executable (DLL) (console) x86-64, for MS Windows
Digital Signature OK
Imports 6 libraries
ADVAPI32, KERNEL32, msvcrt, SHELL32, USER32, WS2_32
Exports 764 functions
Resources 2 Resources
Sections 14 Sections

Version Information

CompanyName VideoLAN
ProductName VLC media player
ProductVersion 3,0,18,0
FileVersion 3.0.18
FileDescription VLC media player
LegalCopyright Copyright © 1996-2022 VideoLAN and VLC Authors
LegalTrademarks VLC media player, VideoLAN and x264 are registered trademarks from VideoLAN
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 1,490,920 bytes 1,490,944 bytes 6.41 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_64BYTES 0811ED7D3AE028239EE2A3AA503ADF28
.data 0x0016d000 18,136 bytes 18,432 bytes 4.57 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_64BYTES 072D6D61D210A2EF6090E1030DE65D9B
.rdata 0x00172000 1,144,752 bytes 1,144,832 bytes 7.09 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_32BYTES F9B2BDAF8C2F508E6868A2AFF16FA3B8
.buildid 0x0028a000 53 bytes 512 bytes 0.57 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES C309C6A0E4B2462057A691FA0AC2F367
.pdata 0x0028b000 43,860 bytes 44,032 bytes 6.10 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES 14A223F8997D1C75D37F4CF1A97836E1
.xdata 0x00296000 43,368 bytes 43,520 bytes 4.40 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES 5A96C084B1806C8534979F9A9BF7F5FD
.bss 0x002a1000 18,784 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_32BYTES D41D8CD98F00B204E9800998ECF8427E
.edata 0x002a6000 21,880 bytes 22,016 bytes 5.82 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES 35B7D87582999ABBE05C1C29B03514BE
.idata 0x002ac000 10,908 bytes 11,264 bytes 4.55 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES CB09DC81544925B66ED274DC27B6F1BD
.CRT 0x002af000 88 bytes 512 bytes 0.24 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_8BYTES 2D12877EB7256D34C7F7F6B6486E2FEF
.tls 0x002b0000 104 bytes 512 bytes 0.31 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_32BYTES AFE61E906C7B5966C893BBA61A88451A
.rsrc 0x002b1000 1,608 bytes 2,048 bytes 3.68 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES 1F1A347049D1B8C25D97E028B916AC9E
.reloc 0x002b2000 5,948 bytes 6,144 bytes 5.40 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES 4E060D9C966EA4B3DD11D12A64B35FED
/4 0x002b4000 24 bytes 512 bytes 0.42 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_4BYTES A18B71916B5A01FD2922BDBC36741DD4
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 2 (1,441 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 844 bytes
58.6%
RT_MANIFEST 1 597 bytes
41.4%

Certificate Chain Analysis

Certificate Information
Product VLC media player
Description VLC media player
File Version 3.0.18
Signing Date 09:32 PM 11/08/2022 (1131 days ago)
Verification Status Signed
Signers VideoLAN; DigiCert SHA2 Assured ID Code Signing CA; DigiCert
Counter Signers DigiCert Timestamp 2022 - 2; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert
Copyright Copyright © 1996-2022 VideoLAN and VLC Authors
Certificate Chain Summary
DigiCert Assured ID Root CA #1 Primary
Validity Period: 2006-11-10 00:00:00 → 2031-11-10 00:00:00
Signature Algorithm: sha1RSA
Serial Number: 0C E7 E0 E5 17 D8 46 FE 8F E5 60 FC 1B F0 30 39
DigiCert SHA2 Assured ID Code Signing CA #2 Chain
Validity Period: 2013-10-22 12:00:00 → 2028-10-22 12:00:00
Signature Algorithm: sha256RSA
Serial Number: 04 09 18 1B 5F D5 BB 66 75 53 43 B5 6F 95 50 08
VideoLAN #3 Chain
Validity Period: 2020-12-14 00:00:00 → 2023-12-18 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 04 07 AB B6 4E 99 90 18 07 89 EA CB 81 F5 F9 14
DigiCert Trusted Root G4 #4 Chain
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #5 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Timestamp 2022 - 2 #6 Chain
Validity Period: 2022-09-21 00:00:00 → 2033-11-21 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0C 4D 69 72 4B 94 FA 3C 2A 4A 3D 29 07 80 3D 5A

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware