Architecture |
IMAGE_FILE_MACHINE_I386
|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date |
2023-Sep-22 08:14:12
|
Detected languages |
English - United States
|
Debug artifacts |
C:\Buildbot\ad-windows-32\build\release\app-32\win_loader\AnyDesk.pdb
|
CompanyName |
AnyDesk Software GmbH
|
FileDescription |
AnyDesk
|
FileVersion |
8.0.3
|
ProductName |
AnyDesk
|
ProductVersion |
8.0
|
LegalCopyright |
(C) 2022 AnyDesk Software GmbH
|
Suspicious |
The PE is possibly packed. |
Unusual section name found: .itext
The PE only has 0 import(s).
|
Info |
The PE is digitally signed. |
Signer: philandro Software GmbH
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
|
Suspicious |
VirusTotal score: 1/70 (Scanned on 2024-03-06 11:29:12) |
Google:
Detected
|
MD5 |
37e172be64b12f3207300d11b74656b8
|
SHA1 |
1895d7c4f785f92e48b5191fd812822593cbc73f
|
SHA256 |
bc747e3bf7b6e02c09f3d18bdd0e64eef62b940b2f16c9c72e647eec85cf0138
|
SHA3 |
6951f9ecc24d7584df728af2d27eb9f76d4b3389d93671a505b0dbab4fece236
|
SSDeep |
98304:pgBOLscYr9NrQO6lSdAd7qvlyBhbUhrZsTY3ycd8izlxGhzAqK3:KOoc+dQO6+Ad7qdriTYlfzlIhMt
|
Imports Hash |
d41d8cd98f00b204e9800998ecf8427e
|
e_magic |
MZ
|
e_cblp |
0x90
|
e_cp |
0x3
|
e_crlc |
0
|
e_cparhdr |
0x4
|
e_minalloc |
0
|
e_maxalloc |
0xffff
|
e_ss |
0
|
e_sp |
0xb8
|
e_csum |
0
|
e_ip |
0
|
e_cs |
0
|
e_ovno |
0
|
e_oemid |
0
|
e_oeminfo |
0
|
e_lfanew |
0xd0
|
Signature |
PE
|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections |
6
|
TimeDateStamp |
2023-Sep-22 08:14:12
|
PointerToSymbolTable |
0
|
NumberOfSymbols |
0
|
SizeOfOptionalHeader |
0xe0
|
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic |
PE32
|
LinkerVersion |
10.0
|
SizeOfCode |
0x2a00
|
SizeOfInitializedData |
0x534600
|
SizeOfUninitializedData |
0x125ee00
|
AddressOfEntryPoint |
0x00001CE5 (Section: .text)
|
BaseOfCode |
0x1000
|
BaseOfData |
0x4000
|
ImageBase |
0x400000
|
SectionAlignment |
0x1000
|
FileAlignment |
0x200
|
OperatingSystemVersion |
5.1
|
ImageVersion |
0.0
|
SubsystemVersion |
5.1
|
Win32VersionValue |
0
|
SizeOfImage |
0x179a000
|
SizeOfHeaders |
0x400
|
Checksum |
0x5464db
|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve |
0x100000
|
SizeofStackCommit |
0x1000
|
SizeofHeapReserve |
0x100000
|
SizeofHeapCommit |
0x1000
|
LoaderFlags |
0
|
NumberOfRvaAndSizes |
16
|
MD5 |
d901b1d0588f2cda80fc5b9aae6f9756
|
SHA1 |
587f299c88aee747820ca30f04e3e6128271de71
|
SHA256 |
f0fbfac8f2a6e06462ed09e7f035fb598c91ab62781b53b83794d3c5293fe68d
|
SHA3 |
f2ca86052744c4cbe4f8982033bb961834ea90d9c9e1390433d295106329ea66
|
VirtualSize |
0x2877
|
VirtualAddress |
0x1000
|
SizeOfRawData |
0x2a00
|
PointerToRawData |
0x400
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
Entropy |
6.54637
|
MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
VirtualSize |
0x125ee00
|
VirtualAddress |
0x4000
|
SizeOfRawData |
0
|
PointerToRawData |
0
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
MD5 |
1401c3744edf3cf7dc0d88b8a7cb778d
|
SHA1 |
2300830113b74da4e325e5b441491b3263feb028
|
SHA256 |
f4f6bcd23e337be54ef8f6caa54dd269561d060dbe5525b603ed6d35ccdf43da
|
SHA3 |
e83459bca4d51c29e72f3b65fd7d3c1a19adc64938ab60b9fb04ac0f7057ff0d
|
VirtualSize |
0x2fa
|
VirtualAddress |
0x1263000
|
SizeOfRawData |
0x400
|
PointerToRawData |
0x2e00
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
Entropy |
5.64375
|
MD5 |
3647ba93f35e60587aa292272a4cceb7
|
SHA1 |
0def77dfe9de1132b500e1641508785dd6d61fe1
|
SHA256 |
fb6eae121816d4feb2b3506217ab6a8d3b9bbcf50934a940f26cf73263962008
|
SHA3 |
557a40fbb0c314cbcd789ab6eab509bc25b1cd21389783d98717bdb7a8251e98
|
VirtualSize |
0x52f2fc
|
VirtualAddress |
0x1264000
|
SizeOfRawData |
0x52f000
|
PointerToRawData |
0x3200
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
Entropy |
7.99997
|
MD5 |
366a579464f0b3be1b23a234d1e758b5
|
SHA1 |
ce9825792d920cd46f81120159da74facfe22f16
|
SHA256 |
191c13b83275e4902597f15fa603477d466ce7df55d8d9fdee3d7a5e694cf2ad
|
SHA3 |
9ad279153f8b441572d80f8bc22eb86de605da23dd5730422dfd16c8f1236cd1
|
VirtualSize |
0x4850
|
VirtualAddress |
0x1794000
|
SizeOfRawData |
0x4a00
|
PointerToRawData |
0x532200
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
Entropy |
6.01745
|
MD5 |
dff545c0291c6bb280bbfb0224bbecb4
|
SHA1 |
bd2c00da7a469cb7cd7b105443249a4c9a2adae8
|
SHA256 |
e1343c68c7231a9135d394e87dae657c7575212f11196e6d6d05124021ff8825
|
SHA3 |
fcb555a0311f3770f22004c8ec0e1e12e4a485250378fa0e932797f61e0b72d2
|
VirtualSize |
0x300
|
VirtualAddress |
0x1799000
|
SizeOfRawData |
0x400
|
PointerToRawData |
0x536c00
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
Entropy |
1.22037
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x1b8e
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
7.83901
|
Detected Filetype |
PNG graphic file
|
MD5 |
c88936dd1a7d59c4403d6babb04dd87e
|
SHA1 |
cc33904defad90d05ccec92b7fff7d5902941795
|
SHA256 |
ea057e896209478d8290a1b526cae84f2509678d866d08382614707f3b710d47
|
SHA3 |
28528f7316cb893a622c6611bbd967fcc40de2bf615e7332dee0fbd31997398e
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x668
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.29968
|
MD5 |
092bef43014ecb8adbaf06131ce5e40b
|
SHA1 |
1b15bd67961afbecb0cbbd1183c2d0dc9ed9e7cf
|
SHA256 |
f50850ec3e997252b5533691868d04c15e923efe4f694c0ea8126f612e60404c
|
SHA3 |
cab0b87867861997a7a03b362811b9052b40dea25bcd54a88c60956b6f6e9968
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x2e8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.6735
|
MD5 |
3a69266d6258e81e65a29138c95fe2a8
|
SHA1 |
606560abf36b292f238d7ad4aa6c09ec8a21f8a3
|
SHA256 |
bc1cb94bcc63c8541ff535da88ed153ff3346db3fb93fc27fe87d414b2038dc4
|
SHA3 |
4204359c479df05357b6bf705b0d2961c1a4317d43977784fcf2835e25209f54
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x1e8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.73746
|
MD5 |
75705b8eedfc400d14f7ae9c8f40935b
|
SHA1 |
ebecc73c1403107ce631cc21a6c4262a4c0ee1aa
|
SHA256 |
c433628ee32bb8698e81f2ebb23d615e4bcf34ba954055410c64c3638c95503c
|
SHA3 |
3b0525e50fdad680ebf6318fef60a34ffd36ae26a82fa7bb4675d27b0227a0e2
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x128
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.69265
|
MD5 |
76b057741da4577549a4b9ef8f585bb3
|
SHA1 |
4d4f6f821507639f8214bae9aa2be1f480b7e844
|
SHA256 |
b008246dad106e522b98810ce6bc1212c8f12e78a6f77506283782438ea5b65d
|
SHA3 |
acce4c5df16010fce31dd43cfe4645d11a9aadc7ccd5da162bdbd154c1ac9b78
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x10a8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.82573
|
MD5 |
2610c05771e702a41ecb8da0b04d0ab5
|
SHA1 |
31364061514f28d5a1d705779e53813dac0b3a33
|
SHA256 |
b971ae520635a90d11feec73c6569c869fa253b30f2f5c48e5db9a53a3011a0c
|
SHA3 |
65e991a0af2d28102ed025ead37c462f1c771a67aec8a9daad72e7a5713c3104
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x468
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.12201
|
MD5 |
24e8eca8ba394adf26140b977971f9a1
|
SHA1 |
880457cd2862996cb8048208345fd97572d414c4
|
SHA256 |
9756f73802f079675e55f855935060a2fa1a6760ff95a6da7d172637c31068a9
|
SHA3 |
7e11475c5b7b6c0ca005e766cefc783671f31a18bb33fae09b647e8e80dd51c5
|
Type |
RT_GROUP_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x4c
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.78538
|
Detected Filetype |
Icon file
|
MD5 |
53975c41e7520296015f9db3f16a6c74
|
SHA1 |
03aad254664361f296e2c982968d4afb537a573e
|
SHA256 |
4041084c14f8f142bf7919feedf1437c9bdb5c3040db4a2bd2b0cf387f006fcf
|
SHA3 |
79879cd09c0a4a1d24967b53fe230d9ae0fc1613299a75561402de6ad65509c7
|
Type |
RT_GROUP_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x22
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.36486
|
Detected Filetype |
Icon file
|
MD5 |
f450601c55ed21618c3f1a5ba1f27a4f
|
SHA1 |
06f1824063568ba0dd86aacd8159af2cf3a47f54
|
SHA256 |
bd48b5685ffe8ec4a32dc5da2aff7b279e3ad02a2671beb80d1b8f44cf7e416f
|
SHA3 |
45ca28fd4210bca3d6a7a16d8f069db4d8b04dd5c88b05ed882aa5f0f570c7a2
|
Type |
RT_VERSION
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x24c
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.34795
|
MD5 |
ddad477bbb8a248f566907a1eabd2a11
|
SHA1 |
068d011397fcfa176c6f61eccb1bdc518dba79e5
|
SHA256 |
0a42fa310c73c456839a7b5b83c94f10b6e2caf7fd08669076a7bc57fee74694
|
SHA3 |
7958232e3d9fab37bce39fb9af21e45d40740c819f027851fe09aa0999204912
|
Type |
RT_MANIFEST
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x605
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
5.39732
|
MD5 |
f08ffe45cc8684f572d59391a03da781
|
SHA1 |
41cf0c42ad8e394eca516eb8f5f5c63662cf4110
|
SHA256 |
d214ad728b5a7ee8f519ac544a3553b2ca744ffc566d7228dab7d316f8358140
|
SHA3 |
632ee66f7e873a8724b8d6031c8cdbe24f1face588f92e8aa9d2bfea9b2c1607
|
Signature |
0xfeef04bd
|
StructVersion |
0x10000
|
FileVersion |
8.0.3.0
|
ProductVersion |
0.0.0.0
|
FileFlags |
(EMPTY)
|
FileOs |
(EMPTY)
|
FileType |
VFT_APP
|
Language |
English - United States
|
CompanyName |
AnyDesk Software GmbH
|
FileDescription |
AnyDesk
|
FileVersion (#2) |
8.0.3
|
ProductName |
AnyDesk
|
ProductVersion (#2) |
8.0
|
LegalCopyright |
(C) 2022 AnyDesk Software GmbH
|
Resource LangID |
English - United States
|
Characteristics |
0
|
TimeDateStamp |
2023-Sep-22 08:14:12
|
Version |
0.0
|
SizeofData |
94
|
AddressOfRawData |
0x126329c
|
PointerToRawData |
0x309c
|
Referenced File |
C:\Buildbot\ad-windows-32\build\release\app-32\win_loader\AnyDesk.pdb
|
XOR Key |
0x3b897dad
|
Unmarked objects |
0
|
C++ objects (VS2010 build 30319) |
8
|
C objects (VS2010 build 30319) |
3
|
Resource objects (VS2010 SP1 build 40219) |
1
|
Linker (VS2010 build 30319) |
1
|
[*] Warning: Section .itext has a size of 0!