×
This file seems to be a .NET executable .
Sadly, Manalyzer's analysis techniques were designed for native code, so it's likely that this report won't tell you much.
Sorry!
Architecture
IMAGE_FILE_MACHINE_I386
Subsystem
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date
2044-Nov-26 21:11:11
Debug artifacts
ScreenConnect.WindowsClient.pdb
CompanyName
ScreenConnect Software
FileDescription
ScreenConnect Client
FileVersion
26.1.18.9566
InternalName
ScreenConnect.WindowsClient.exe
LegalCopyright
OriginalFilename
ScreenConnect.WindowsClient.exe
ProductName
ScreenConnect
ProductVersion
26.1.18.9566
Assembly Version
26.1.18.9566
Info
Matching compiler(s):
Microsoft Visual C# v7.0 / Basic .NET
Info
The PE is digitally signed.
Signer: ConnectWise
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe
VirusTotal score: 0/71 (Scanned on 2026-05-18 22:44:20)
All the AVs think this file is safe.
MD5
02912dc303c8bf5ff0bdc58578b9d7a2
SHA1
56217ea0d371438e170bc380ac6a3d9bc2a0ffad
SHA256
0a46625ec3f41f4a7821a88e1b7edc0fe3062c92f982a5e8dd4258c4a169c052
SHA3
ef55ffd79ace29fd5f5811841384f4222f1657de7d01b290f55fb890119885af
SSDeep
24576:Q0QES6I7KPzDpKzN4Nzs1GLQdQ/tq1zwJk0BfBxzA9ZEEzn1p:hQCIUtWwvoEExp
Imports Hash
f34d5f2d4577ed6d9ceec516c1f5a744
e_magic
MZ
e_cblp
0x90
e_cp
0x3
e_crlc
0
e_cparhdr
0x4
e_minalloc
0
e_maxalloc
0xffff
e_ss
0
e_sp
0xb8
e_csum
0
e_ip
0
e_cs
0
e_ovno
0
e_oemid
0
e_oeminfo
0
e_lfanew
0x80
Signature
PE
Machine
IMAGE_FILE_MACHINE_I386
NumberofSections
3
TimeDateStamp
2044-Nov-26 21:11:11
PointerToSymbolTable
0
NumberOfSymbols
0
SizeOfOptionalHeader
0xe0
Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
Magic
PE32
LinkerVersion
48.0
SizeOfCode
0x182800
SizeOfInitializedData
0x600
SizeOfUninitializedData
0
AddressOfEntryPoint
0x0018461E (Section: .text)
BaseOfCode
0x2000
BaseOfData
0x186000
ImageBase
0x400000
SectionAlignment
0x2000
FileAlignment
0x200
OperatingSystemVersion
4.0
ImageVersion
0.0
SubsystemVersion
4.0
Win32VersionValue
0
SizeOfImage
0x18a000
SizeOfHeaders
0x200
Checksum
0x190b45
Subsystem
IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve
0x100000
SizeofStackCommit
0x1000
SizeofHeapReserve
0x100000
SizeofHeapCommit
0x1000
LoaderFlags
0
NumberOfRvaAndSizes
16
MD5
2c845fb6f030fe903ca3205d2115eb71
SHA1
00372b807c43123aa90be84123f79d537baece8d
SHA256
89ad46ac5cdce724d440464332f670c63fd22b5f7e8514f7fbea36589866dedf
SHA3
accb64eda8b318df8ee00c9ef8bfdc4bef29bd3cbd7c1b4d171bfb8525ee8680
VirtualSize
0x182624
VirtualAddress
0x2000
SizeOfRawData
0x182800
PointerToRawData
0x200
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy
6.83066
MD5
335ff5d8a27409326eb8f7f49d86413e
SHA1
309349ce07a432e419212cb18acf681c02e6eeb5
SHA256
209ed0f795a5e5c4bc3b44b92dabb76635cc4602f974492daf269491e9217074
SHA3
75557d3c9455f2d39ef7ee2c0b6a99944111cf7f50ab0ba400ce7d1633673bd3
VirtualSize
0x3c2
VirtualAddress
0x186000
SizeOfRawData
0x400
PointerToRawData
0x182a00
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy
3.13979
MD5
a19c949ebf246e792f0cbc9a344ec46a
SHA1
2072635379f0e7b285e63d6b61289ba9599dd7f3
SHA256
9821ec2ffc92d7eb355935efae48ad7d63382c727f8fa36afa3ac736c40ddde0
SHA3
d5ac4d87867608103f925bdad6b48efe8c039a931bdfec33d49c221b27937ab0
VirtualSize
0xc
VirtualAddress
0x188000
SizeOfRawData
0x200
PointerToRawData
0x182e00
PointerToRelocations
0
PointerToLineNumbers
0
NumberOfLineNumbers
0
NumberOfRelocations
0
Characteristics
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy
0.10191
Type
RT_VERSION
Language
UNKNOWN
Codepage
UNKNOWN
Size
0x36a
TimeDateStamp
1980-Jan-01 00:00:00
Entropy
3.40353
MD5
ca010e30d423f04d8b170e0763b26e0a
SHA1
35f73cb00285c04ac8923188eb2998387ccc95d2
SHA256
c0d6eb677498cf844b519ec0e5e30ee48a2d805f54bacd23df292a89243bbe8e
SHA3
2600fd38be29a2348061c361580df405747079e9eef0e6b3ec2743a096828787
Signature
0xfeef04bd
StructVersion
0x10000
FileVersion
26.1.18.9566
ProductVersion
26.1.18.9566
FileFlags
(EMPTY)
FileOs
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType
VFT_APP
Language
UNKNOWN
CompanyName
ScreenConnect Software
FileDescription
ScreenConnect Client
FileVersion (#2)
26.1.18.9566
InternalName
ScreenConnect.WindowsClient.exe
LegalCopyright
OriginalFilename
ScreenConnect.WindowsClient.exe
ProductName
ScreenConnect
ProductVersion (#2)
26.1.18.9566
Assembly Version
26.1.18.9566
Characteristics
0
TimeDateStamp
2045-Mar-11 03:21:21
Version
0.0
SizeofData
56
AddressOfRawData
0x184598
PointerToRawData
0x182798
Referenced File
ScreenConnect.WindowsClient.pdb
Characteristics
0
TimeDateStamp
1970-Jan-01 00:00:00
Version
0.0
SizeofData
0
AddressOfRawData
0
PointerToRawData
0