Skip to content

Glossary

Rich header

An undocumented, XOR-masked block written by Microsoft linkers into the DOS stub, listing the compiler and linker builds used to produce a PE file.

Between the DOS stub and the PE signature, Microsoft's linker writes a block that starts with DanS and ends with Rich followed by a 32-bit key. In between, masked with that key, are comp.id values — product id and build number of each tool that produced objects — with a count for each. The key is a checksum of the DOS header and of the entries (Daniel Pistelli).

It identifies the Visual Studio version and helps cluster samples; its MD5 is the Rich header hash. It can be copied from another file to mislead attribution, which a key that no longer matches the checksum may reveal. See imphash, Rich header hash and TLSH.