Architecture |
IMAGE_FILE_MACHINE_I386
|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date |
2021-May-06 13:00:57
|
Detected languages |
English - United States
|
Debug artifacts |
C:\Buildbot\ad-windows-32\build\release\app-32\win_loader\AnyDesk.pdb
|
CompanyName |
AnyDesk Software GmbH
|
FileDescription |
AnyDesk
|
FileVersion |
6.3.0
|
ProductName |
AnyDesk
|
ProductVersion |
6.3
|
LegalCopyright |
(C) 2021 AnyDesk Software GmbH
|
Suspicious |
The PE is possibly packed. |
Unusual section name found: .itext
The PE only has 0 import(s).
|
Info |
The PE is digitally signed. |
Signer: philandro Software GmbH
Issuer: DigiCert SHA2 Assured ID Code Signing CA
|
Safe |
VirusTotal score: 0/67 (Scanned on 2021-11-23 13:19:02) |
All the AVs think this file is safe.
|
MD5 |
6bfba96eef35d07616e64d4035576427
|
SHA1 |
cc8c1e4536e4db2d0e8748f6f5ff5740c203fbff
|
SHA256 |
a2e447f3cb8265e7365922a41c4489a757e5079b5203d97ff4a3597fcd9a6a88
|
SHA3 |
9878c36f9cefb155903dd0659af7f9e61492ae011f9e0fa3950a3636c3d5f9bd
|
SSDeep |
98304:eSbCfrdGroZi41SF8h88tkCgmE1D9s9EGlAv+FzNE:hworwSggBnilhu
|
Imports Hash |
d41d8cd98f00b204e9800998ecf8427e
|
e_magic |
MZ
|
e_cblp |
0x90
|
e_cp |
0x3
|
e_crlc |
0
|
e_cparhdr |
0x4
|
e_minalloc |
0
|
e_maxalloc |
0xffff
|
e_ss |
0
|
e_sp |
0xb8
|
e_csum |
0
|
e_ip |
0
|
e_cs |
0
|
e_ovno |
0
|
e_oemid |
0
|
e_oeminfo |
0
|
e_lfanew |
0xd0
|
Signature |
PE
|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections |
6
|
TimeDateStamp |
2021-May-06 13:00:57
|
PointerToSymbolTable |
0
|
NumberOfSymbols |
0
|
SizeOfOptionalHeader |
0xe0
|
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic |
PE32
|
LinkerVersion |
10.0
|
SizeOfCode |
0x2a00
|
SizeOfInitializedData |
0x390800
|
SizeOfUninitializedData |
0xa63800
|
AddressOfEntryPoint |
0x00001CE9 (Section: .text)
|
BaseOfCode |
0x1000
|
BaseOfData |
0x4000
|
ImageBase |
0x400000
|
SectionAlignment |
0x1000
|
FileAlignment |
0x200
|
OperatingSystemVersion |
5.1
|
ImageVersion |
0.0
|
SubsystemVersion |
5.1
|
Win32VersionValue |
0
|
SizeOfImage |
0xdfb000
|
SizeOfHeaders |
0x400
|
Checksum |
0x39a97a
|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve |
0x100000
|
SizeofStackCommit |
0x1000
|
SizeofHeapReserve |
0x100000
|
SizeofHeapCommit |
0x1000
|
LoaderFlags |
0
|
NumberOfRvaAndSizes |
16
|
MD5 |
31a7c4a1c8f37e3c079924355a0af907
|
SHA1 |
b0bf573b6bebc48742a833106a05e29a2b3bfb46
|
SHA256 |
78cec89b06dd2010cb25ec52427589f1bd5bda8e86b29332626c34a941fb6da0
|
SHA3 |
9f6e920541a05e5e2c8d304dcf09369cd5bcbfc87e6164628a8bf81178c591a1
|
VirtualSize |
0x2835
|
VirtualAddress |
0x1000
|
SizeOfRawData |
0x2a00
|
PointerToRawData |
0x400
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
Entropy |
6.50843
|
MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
VirtualSize |
0xa63800
|
VirtualAddress |
0x4000
|
SizeOfRawData |
0
|
PointerToRawData |
0
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
MD5 |
e1ceeeb674e4726ab3c65650e6ef13a4
|
SHA1 |
2c924613feb38f4c99fcdb59f59700a86952d879
|
SHA256 |
1eda224a368b70f8a078e2340b494cc2039f8de3c884dfd8ef1438658cf32150
|
SHA3 |
6fd0e3c01cd68c56f808aeb25c2dca3567ef1f6406b1e6d846045232bfc26802
|
VirtualSize |
0x2fa
|
VirtualAddress |
0xa68000
|
SizeOfRawData |
0x400
|
PointerToRawData |
0x2e00
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
Entropy |
5.64203
|
MD5 |
3bd6ab8922aca04ea26331e411fb03aa
|
SHA1 |
54334e58e14ea9053dcab131fd5bca74e660a058
|
SHA256 |
3570034db96bc24e927c42b35c602c0035ff38ed59bc2873e571ef6a34bd74eb
|
SHA3 |
fb3935636c36bba124737a8b2b316be033b475ef77b3e059789582cbaed132db
|
VirtualSize |
0x38cb7c
|
VirtualAddress |
0xa69000
|
SizeOfRawData |
0x38c800
|
PointerToRawData |
0x3200
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
Entropy |
7.99995
|
MD5 |
570d0e1a7bbab77e74005c6b32990de4
|
SHA1 |
087cbc73e5e3c0ea5ef0ab06a61074f93378ff02
|
SHA256 |
3b768cfaa276b31fde3f52cb78094796fe4286be2997f070cfe17a135089d792
|
SHA3 |
bcf61bb23d05f52eb63cec44c02cc4160e132ebab3dc794a85329bbc2eac1fd1
|
VirtualSize |
0x3288
|
VirtualAddress |
0xdf6000
|
SizeOfRawData |
0x3400
|
PointerToRawData |
0x38fa00
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
Entropy |
6.68172
|
MD5 |
95aa79c39ba19e7065545a9504efb057
|
SHA1 |
0b146f6223287e78734c21d004fd6e2764080bdb
|
SHA256 |
d909b4b19ef8c89005170ccce336cef3c4390d831c9dd2480dd95cceeeba9382
|
SHA3 |
8a336fa1a4212c3f4a719a03b8b4136c86a4d57a1cf343ec42422a5f6b60c59b
|
VirtualSize |
0x300
|
VirtualAddress |
0xdfa000
|
SizeOfRawData |
0x400
|
PointerToRawData |
0x392e00
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
Entropy |
1.18127
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x1b8e
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
7.83901
|
Detected Filetype |
PNG graphic file
|
MD5 |
c88936dd1a7d59c4403d6babb04dd87e
|
SHA1 |
cc33904defad90d05ccec92b7fff7d5902941795
|
SHA256 |
ea057e896209478d8290a1b526cae84f2509678d866d08382614707f3b710d47
|
SHA3 |
28528f7316cb893a622c6611bbd967fcc40de2bf615e7332dee0fbd31997398e
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x668
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.29968
|
MD5 |
092bef43014ecb8adbaf06131ce5e40b
|
SHA1 |
1b15bd67961afbecb0cbbd1183c2d0dc9ed9e7cf
|
SHA256 |
f50850ec3e997252b5533691868d04c15e923efe4f694c0ea8126f612e60404c
|
SHA3 |
cab0b87867861997a7a03b362811b9052b40dea25bcd54a88c60956b6f6e9968
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x2e8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.6735
|
MD5 |
3a69266d6258e81e65a29138c95fe2a8
|
SHA1 |
606560abf36b292f238d7ad4aa6c09ec8a21f8a3
|
SHA256 |
bc1cb94bcc63c8541ff535da88ed153ff3346db3fb93fc27fe87d414b2038dc4
|
SHA3 |
4204359c479df05357b6bf705b0d2961c1a4317d43977784fcf2835e25209f54
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x1e8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.73746
|
MD5 |
75705b8eedfc400d14f7ae9c8f40935b
|
SHA1 |
ebecc73c1403107ce631cc21a6c4262a4c0ee1aa
|
SHA256 |
c433628ee32bb8698e81f2ebb23d615e4bcf34ba954055410c64c3638c95503c
|
SHA3 |
3b0525e50fdad680ebf6318fef60a34ffd36ae26a82fa7bb4675d27b0227a0e2
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x128
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.69265
|
MD5 |
76b057741da4577549a4b9ef8f585bb3
|
SHA1 |
4d4f6f821507639f8214bae9aa2be1f480b7e844
|
SHA256 |
b008246dad106e522b98810ce6bc1212c8f12e78a6f77506283782438ea5b65d
|
SHA3 |
acce4c5df16010fce31dd43cfe4645d11a9aadc7ccd5da162bdbd154c1ac9b78
|
Type |
RT_GROUP_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x4c
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.78538
|
Detected Filetype |
Icon file
|
MD5 |
53975c41e7520296015f9db3f16a6c74
|
SHA1 |
03aad254664361f296e2c982968d4afb537a573e
|
SHA256 |
4041084c14f8f142bf7919feedf1437c9bdb5c3040db4a2bd2b0cf387f006fcf
|
SHA3 |
79879cd09c0a4a1d24967b53fe230d9ae0fc1613299a75561402de6ad65509c7
|
Type |
RT_VERSION
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x24c
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.36225
|
MD5 |
5ccf99747a872e1a391449aa59978f5f
|
SHA1 |
84ea56c8db1d14293e127cbeac39124b5305794d
|
SHA256 |
1019fe8c8c6fae8b88964940b0913831a88ad307cea9aaebd96c19cb4441c7a8
|
SHA3 |
9940d49378b94257b1e8140713ad613c41ca65a3dcd3701f6df0a6616c23003b
|
Type |
RT_MANIFEST
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x605
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
5.3975
|
MD5 |
dd9ff22bbd51458518445ab806ce6874
|
SHA1 |
4fca8cbaf6bbd2607e3d810610cbd96e3a527403
|
SHA256 |
f69744975959dbcd2bba0771650ba0445115ffecc87358ceac8096648f8fd144
|
SHA3 |
a2222a93b700dc777b94e0c0a75a5af6721c1525fee18007c20a7ce3578cd838
|
Signature |
0xfeef04bd
|
StructVersion |
0x10000
|
FileVersion |
6.3.0.0
|
ProductVersion |
0.0.0.0
|
FileFlags |
(EMPTY)
|
FileOs |
(EMPTY)
|
FileType |
VFT_APP
|
Language |
English - United States
|
CompanyName |
AnyDesk Software GmbH
|
FileDescription |
AnyDesk
|
FileVersion (#2) |
6.3.0
|
ProductName |
AnyDesk
|
ProductVersion (#2) |
6.3
|
LegalCopyright |
(C) 2021 AnyDesk Software GmbH
|
Resource LangID |
English - United States
|
Characteristics |
0
|
TimeDateStamp |
2021-May-06 13:00:57
|
Version |
0.0
|
SizeofData |
94
|
AddressOfRawData |
0xa6829c
|
PointerToRawData |
0x309c
|
Referenced File |
C:\Buildbot\ad-windows-32\build\release\app-32\win_loader\AnyDesk.pdb
|
XOR Key |
0x3b897dad
|
Unmarked objects |
0
|
C++ objects (VS2010 build 30319) |
8
|
C objects (VS2010 build 30319) |
3
|
Resource objects (VS2010 SP1 build 40219) |
1
|
Linker (VS2010 build 30319) |
1
|
[*] Warning: Section .itext has a size of 0!