Architecture |
IMAGE_FILE_MACHINE_I386
|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date |
2021-Sep-06 09:32:54
|
Detected languages |
English - United States
|
Debug artifacts |
C:\Buildbot\ad-windows-32\build\release\app-32\win_loader\AnyDesk.pdb
|
CompanyName |
AnyDesk Software GmbH
|
FileDescription |
AnyDesk
|
FileVersion |
6.3.3
|
ProductName |
AnyDesk
|
ProductVersion |
6.3
|
LegalCopyright |
(C) 2021 AnyDesk Software GmbH
|
Suspicious |
The PE is possibly packed. |
Unusual section name found: .itext
The PE only has 0 import(s).
|
Info |
The PE is digitally signed. |
Signer: philandro Software GmbH
Issuer: DigiCert SHA2 Assured ID Code Signing CA
|
Suspicious |
VirusTotal score: 1/66 (Scanned on 2021-11-10 00:08:05) |
Zillya:
Trojan.Convagent.Win32.7241
|
MD5 |
bd1c7369830ebd781ed5eade64f8f9e4
|
SHA1 |
4f65118960bd8bcc744d62e6f464f8bc82c85a9e
|
SHA256 |
4a9dde3979c2343c024c6eeeddff7639be301826dd637c006074e04a1e4e9fe7
|
SHA3 |
593d15310061d8de92a5e0a3468d58baaf51cfd4b97ce8f60315e56e256f5cea
|
SSDeep |
98304:jd4d0XlQTMYKcmV540bSdjvDrE1nM7ecLtuM6lyUI:jd4d6oMUmVC0s7YM7x4M1
|
Imports Hash |
d41d8cd98f00b204e9800998ecf8427e
|
e_magic |
MZ
|
e_cblp |
0x90
|
e_cp |
0x3
|
e_crlc |
0
|
e_cparhdr |
0x4
|
e_minalloc |
0
|
e_maxalloc |
0xffff
|
e_ss |
0
|
e_sp |
0xb8
|
e_csum |
0
|
e_ip |
0
|
e_cs |
0
|
e_ovno |
0
|
e_oemid |
0
|
e_oeminfo |
0
|
e_lfanew |
0xd0
|
Signature |
PE
|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections |
6
|
TimeDateStamp |
2021-Sep-06 09:32:54
|
PointerToSymbolTable |
0
|
NumberOfSymbols |
0
|
SizeOfOptionalHeader |
0xe0
|
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic |
PE32
|
LinkerVersion |
10.0
|
SizeOfCode |
0x2a00
|
SizeOfInitializedData |
0x391a00
|
SizeOfUninitializedData |
0xa67200
|
AddressOfEntryPoint |
0x00001CE9 (Section: .text)
|
BaseOfCode |
0x1000
|
BaseOfData |
0x4000
|
ImageBase |
0x400000
|
SectionAlignment |
0x1000
|
FileAlignment |
0x200
|
OperatingSystemVersion |
5.1
|
ImageVersion |
0.0
|
SubsystemVersion |
5.1
|
Win32VersionValue |
0
|
SizeOfImage |
0xe00000
|
SizeOfHeaders |
0x400
|
Checksum |
0x3a350e
|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve |
0x100000
|
SizeofStackCommit |
0x1000
|
SizeofHeapReserve |
0x100000
|
SizeofHeapCommit |
0x1000
|
LoaderFlags |
0
|
NumberOfRvaAndSizes |
16
|
MD5 |
2b22ea145ff0c990d0b46f54de99fa99
|
SHA1 |
156448224a2ba4380d47539f39cf5206c27732a8
|
SHA256 |
9dbbb5f593115818df45b9a0b0d87d531c138b41b988cdc5bd143e12761d61d2
|
SHA3 |
dcc2b864bc7cddb584d9f1884bbf8002a2d890cd3f518b2b255644143af12f26
|
VirtualSize |
0x2835
|
VirtualAddress |
0x1000
|
SizeOfRawData |
0x2a00
|
PointerToRawData |
0x400
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
Entropy |
6.50483
|
MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
VirtualSize |
0xa67200
|
VirtualAddress |
0x4000
|
SizeOfRawData |
0
|
PointerToRawData |
0
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
MD5 |
e18de6f98bb029a5f2cf4c3b10b4428a
|
SHA1 |
0270493137085c4d98e85c23207069657ceccde6
|
SHA256 |
106c8ec4c6c0a822c6cd76de5be55e27d935b6e6e80ea9f85caf025b4aeac0f7
|
SHA3 |
b18bd6526f010c5f5803533a94055b2289d73cae0e4a4904eb6838e29befda2a
|
VirtualSize |
0x2fa
|
VirtualAddress |
0xa6c000
|
SizeOfRawData |
0x400
|
PointerToRawData |
0x2e00
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
Entropy |
5.63319
|
MD5 |
99d731e7065f6dd6ec430b96af7e3389
|
SHA1 |
26ed53205ac9295d9ab2151fa88ceb0988393479
|
SHA256 |
c56744a1e15526995f0c25f9ca744b98c2d569812f07f2c41db1581bb9d7eff2
|
SHA3 |
6789f6128b166f689f8c03d5657ab8a07025b01bf2f0c93ac9d32d6e103149a7
|
VirtualSize |
0x38dd6c
|
VirtualAddress |
0xa6d000
|
SizeOfRawData |
0x38da00
|
PointerToRawData |
0x3200
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
Entropy |
7.99996
|
MD5 |
1df23326f997dda110a012830059b273
|
SHA1 |
296d60d0131ad81e93451a54ccb0435dd9594da6
|
SHA256 |
e68f9bcb7d709ff42fe5e94491415663d8f99a1672b722a52fd774c6548771f1
|
SHA3 |
f1f2282d41e992ea0ac3606e0ab25cdac3c92930b142bdb6c83f1af40844cea5
|
VirtualSize |
0x3288
|
VirtualAddress |
0xdfb000
|
SizeOfRawData |
0x3400
|
PointerToRawData |
0x390c00
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
Entropy |
6.68273
|
MD5 |
95aa79c39ba19e7065545a9504efb057
|
SHA1 |
0b146f6223287e78734c21d004fd6e2764080bdb
|
SHA256 |
d909b4b19ef8c89005170ccce336cef3c4390d831c9dd2480dd95cceeeba9382
|
SHA3 |
8a336fa1a4212c3f4a719a03b8b4136c86a4d57a1cf343ec42422a5f6b60c59b
|
VirtualSize |
0x300
|
VirtualAddress |
0xdff000
|
SizeOfRawData |
0x400
|
PointerToRawData |
0x394000
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
Entropy |
1.18127
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x1b8e
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
7.83901
|
Detected Filetype |
PNG graphic file
|
MD5 |
c88936dd1a7d59c4403d6babb04dd87e
|
SHA1 |
cc33904defad90d05ccec92b7fff7d5902941795
|
SHA256 |
ea057e896209478d8290a1b526cae84f2509678d866d08382614707f3b710d47
|
SHA3 |
28528f7316cb893a622c6611bbd967fcc40de2bf615e7332dee0fbd31997398e
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x668
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.29968
|
MD5 |
092bef43014ecb8adbaf06131ce5e40b
|
SHA1 |
1b15bd67961afbecb0cbbd1183c2d0dc9ed9e7cf
|
SHA256 |
f50850ec3e997252b5533691868d04c15e923efe4f694c0ea8126f612e60404c
|
SHA3 |
cab0b87867861997a7a03b362811b9052b40dea25bcd54a88c60956b6f6e9968
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x2e8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.6735
|
MD5 |
3a69266d6258e81e65a29138c95fe2a8
|
SHA1 |
606560abf36b292f238d7ad4aa6c09ec8a21f8a3
|
SHA256 |
bc1cb94bcc63c8541ff535da88ed153ff3346db3fb93fc27fe87d414b2038dc4
|
SHA3 |
4204359c479df05357b6bf705b0d2961c1a4317d43977784fcf2835e25209f54
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x1e8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.73746
|
MD5 |
75705b8eedfc400d14f7ae9c8f40935b
|
SHA1 |
ebecc73c1403107ce631cc21a6c4262a4c0ee1aa
|
SHA256 |
c433628ee32bb8698e81f2ebb23d615e4bcf34ba954055410c64c3638c95503c
|
SHA3 |
3b0525e50fdad680ebf6318fef60a34ffd36ae26a82fa7bb4675d27b0227a0e2
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x128
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.69265
|
MD5 |
76b057741da4577549a4b9ef8f585bb3
|
SHA1 |
4d4f6f821507639f8214bae9aa2be1f480b7e844
|
SHA256 |
b008246dad106e522b98810ce6bc1212c8f12e78a6f77506283782438ea5b65d
|
SHA3 |
acce4c5df16010fce31dd43cfe4645d11a9aadc7ccd5da162bdbd154c1ac9b78
|
Type |
RT_GROUP_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x4c
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.78538
|
Detected Filetype |
Icon file
|
MD5 |
53975c41e7520296015f9db3f16a6c74
|
SHA1 |
03aad254664361f296e2c982968d4afb537a573e
|
SHA256 |
4041084c14f8f142bf7919feedf1437c9bdb5c3040db4a2bd2b0cf387f006fcf
|
SHA3 |
79879cd09c0a4a1d24967b53fe230d9ae0fc1613299a75561402de6ad65509c7
|
Type |
RT_VERSION
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x24c
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.37753
|
MD5 |
f19d46c11ecfde3c37f3fbf9cb0a8a8f
|
SHA1 |
fccede77650010c142f98eda5cdcb6ad8970ec20
|
SHA256 |
29f0fbdd365ea1abad1aeb00cc54a62a3a12c3f43e012c1bd12aed210c312b85
|
SHA3 |
cb049d539d887e62bc146119f387df50a2180280fda8093c4fd9d4eee59dcd21
|
Type |
RT_MANIFEST
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x605
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
5.39741
|
MD5 |
79df463cdd32c8e4f32cbf12ff9063af
|
SHA1 |
ce16e9c512b3e31262d50ba5c9d192ee95e3ef51
|
SHA256 |
854041881fec2c0ca5d9c21d14c252253a67e1834c6c2ea6aa70f1bbd9d2b8fb
|
SHA3 |
271c1295106ada1060f14e3c6087879d5071d3b45b4f3c4481ae0c6480fcbf65
|
Signature |
0xfeef04bd
|
StructVersion |
0x10000
|
FileVersion |
6.3.3.0
|
ProductVersion |
0.0.0.0
|
FileFlags |
(EMPTY)
|
FileOs |
(EMPTY)
|
FileType |
VFT_APP
|
Language |
English - United States
|
CompanyName |
AnyDesk Software GmbH
|
FileDescription |
AnyDesk
|
FileVersion (#2) |
6.3.3
|
ProductName |
AnyDesk
|
ProductVersion (#2) |
6.3
|
LegalCopyright |
(C) 2021 AnyDesk Software GmbH
|
Resource LangID |
English - United States
|
Characteristics |
0
|
TimeDateStamp |
2021-Sep-06 09:32:54
|
Version |
0.0
|
SizeofData |
94
|
AddressOfRawData |
0xa6c29c
|
PointerToRawData |
0x309c
|
Referenced File |
C:\Buildbot\ad-windows-32\build\release\app-32\win_loader\AnyDesk.pdb
|
XOR Key |
0x3b897dad
|
Unmarked objects |
0
|
C++ objects (VS2010 build 30319) |
8
|
C objects (VS2010 build 30319) |
3
|
Resource objects (VS2010 SP1 build 40219) |
1
|
Linker (VS2010 build 30319) |
1
|
[*] Warning: Section .itext has a size of 0!