c34015e715a5b08fb4f0b10d6097c897

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2010-Apr-10 12:19:38
Detected languages English - United States
CompanyName Logitech Europe S.A.
FileDescription Logitech BRIO for Windows Hello
FileVersion 1.0.62.0
LegalCopyright Copyright 2016
ProductName Logitech BRIO for Windows Hello
ProductVersion 1.0.62.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://nsis.sf.net
  • http://nsis.sf.net/NSIS_Error
  • nsis.sf.net
Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
Can access the registry:
  • RegEnumKeyW
  • RegOpenKeyExW
  • RegCloseKey
  • RegDeleteKeyW
  • RegDeleteValueW
  • RegCreateKeyExW
  • RegSetValueExW
  • RegQueryValueExW
  • RegEnumValueW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Manipulates other processes:
  • OpenProcess
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE is digitally signed. Signer: Logitech Inc
Issuer: DigiCert EV Code Signing CA (SHA2)
Safe VirusTotal score: 0/72 (Scanned on 2020-03-04 08:14:04) All the AVs think this file is safe.

Hashes

MD5 c34015e715a5b08fb4f0b10d6097c897
SHA1 b480741b9f7512aa52d230f0b2cdacf0cc7dbad7
SHA256 f89f333da41dc45106a34907b61456619bdcc52ca3d948215fb2536378f6605c
SHA3 b63da0740e0c1020c3ad4f8d063022fb94865c3f6729c8fa3309a377fd438164
SSDeep 786432:pVj+uQcT+4QS3SIx34nbjeDflXdn2p+g6ONcir5JjtgQog:p03cT+4QS3Si34nner2p+g6ONca5Jjt
Imports Hash 9b1688171e53fe150c16c17a7df4d77c

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2010-Apr-10 12:19:38
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 9.0
SizeOfCode 0x6800
SizeOfInitializedData 0x74000
SizeOfUninitializedData 0x4200
AddressOfEntryPoint 0x00003415 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x8000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 6.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x18f000
SizeOfHeaders 0x400
Checksum 0x1c5e91a
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 cb807804553819b70f6e16b8a094d327
SHA1 8e0ec650fc101b2c2e33e4d8b269a6dc9499e8d0
SHA256 d674b70f973771c0350e72498477b9240a4b3e2d6489b05afe00cae642769774
SHA3 a5e6dc762d983a4f73ceac316f5cab8f07d287eeef72a704f0cae07e111726c6
VirtualSize 0x671c
VirtualAddress 0x1000
SizeOfRawData 0x6800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50461

.rdata

MD5 161b329b4c70ce4fbd9c1143e738896b
SHA1 e08fa356a7aa0040d1da68b8c9850ce54da2371c
SHA256 a77eb42b295842c84c670ef56bf57f17c08ce14ffca324ee0d3b90eea2b7369f
SHA3 25aa2bfc5c46eac6702538c0193a47f665cd624cc0ed59d8789d6b89af7f4d70
VirtualSize 0x19d6
VirtualAddress 0x8000
SizeOfRawData 0x1a00
PointerToRawData 0x6c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.02684

.data

MD5 140876ba314e7bc36379ee5c6db80876
SHA1 a2ea157dd321d7f51b80aba4e82c27755871d6c0
SHA256 4c2b857f81503b2f51b6632165e5123e9b5f3c0a902ba0f77441a4c9e7d53575
SHA3 0e203e8f560fb03153fe9a7e6d668bb088f3e83df442317869a0b92c226be2c3
VirtualSize 0x7139c
VirtualAddress 0xa000
SizeOfRawData 0x200
PointerToRawData 0x8600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.73601

.ndata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x10d000
VirtualAddress 0x7c000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rsrc

MD5 32bab2fcdeacb4857f52c4e0fbca85af
SHA1 0fa95fb19033564f6924f1e717bf14bd1a550821
SHA256 228550d05f046ee2a225d3dd7d99780f1c1cd63f7ae0c6066087ced523eed939
SHA3 e4d4361bc5c91351ca1ac0f544f7bb49bfcba56a360f3079f90c2a83d61b585b
VirtualSize 0x54c8
VirtualAddress 0x189000
SizeOfRawData 0x5600
PointerToRawData 0x8800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.24204

Imports

KERNEL32.dll SetFileTime
CompareFileTime
SearchPathW
GetShortPathNameW
GetFullPathNameW
MoveFileW
SetCurrentDirectoryW
GetFileAttributesW
GetLastError
CreateDirectoryW
SetFileAttributesW
Sleep
GetTickCount
GetFileSize
GetModuleFileNameW
GetCurrentProcess
CopyFileW
ExitProcess
GetWindowsDirectoryW
GetTempPathW
GetCommandLineW
SetErrorMode
lstrcpynA
CloseHandle
lstrcpynW
GetDiskFreeSpaceW
GlobalUnlock
GlobalLock
CreateThread
LoadLibraryW
CreateProcessW
lstrcmpiA
CreateFileW
GetTempFileNameW
lstrcatW
GetProcAddress
LoadLibraryA
GetModuleHandleA
OpenProcess
lstrcpyW
GetVersionExW
GetSystemDirectoryW
GetVersion
lstrcpyA
RemoveDirectoryW
lstrcmpiW
lstrcmpW
ExpandEnvironmentStringsW
GlobalAlloc
WaitForSingleObject
GetExitCodeProcess
GlobalFree
GetModuleHandleW
LoadLibraryExW
FreeLibrary
WritePrivateProfileStringW
GetPrivateProfileStringW
WideCharToMultiByte
MulDiv
lstrlenA
WriteFile
ReadFile
MultiByteToWideChar
SetFilePointer
FindClose
FindNextFileW
FindFirstFileW
DeleteFileW
lstrlenW
USER32.dll ScreenToClient
GetMessagePos
CallWindowProcW
IsWindowVisible
LoadBitmapW
CloseClipboard
SetClipboardData
EmptyClipboard
OpenClipboard
TrackPopupMenu
GetWindowRect
AppendMenuW
CreatePopupMenu
GetSystemMetrics
EndDialog
EnableMenuItem
GetSystemMenu
SetClassLongW
IsWindowEnabled
SetWindowPos
DialogBoxParamW
CheckDlgButton
CreateWindowExW
SystemParametersInfoW
RegisterClassW
SetDlgItemTextW
GetDlgItemTextW
MessageBoxIndirectW
CharNextA
CharUpperW
CharPrevW
DispatchMessageW
PeekMessageW
wsprintfA
DestroyWindow
CreateDialogParamW
SetTimer
SetWindowTextW
PostQuitMessage
SetForegroundWindow
ShowWindow
wsprintfW
SendMessageTimeoutW
LoadCursorW
SetCursor
GetWindowLongW
GetSysColor
CharNextW
GetClassInfoW
ExitWindowsEx
FindWindowExW
GetDlgItem
SetWindowLongW
LoadImageW
GetDC
EnableWindow
InvalidateRect
SendMessageW
DefWindowProcW
BeginPaint
GetClientRect
FillRect
DrawTextW
EndPaint
IsWindow
GDI32.dll SetBkColor
GetDeviceCaps
DeleteObject
CreateBrushIndirect
CreateFontIndirectW
SetBkMode
SetTextColor
SelectObject
SHELL32.dll SHBrowseForFolderW
SHGetPathFromIDListW
SHGetFileInfoW
ShellExecuteW
SHFileOperationW
SHGetSpecialFolderLocation
ADVAPI32.dll RegEnumKeyW
RegOpenKeyExW
RegCloseKey
RegDeleteKeyW
RegDeleteValueW
RegCreateKeyExW
RegSetValueExW
RegQueryValueExW
RegEnumValueW
COMCTL32.dll ImageList_AddMasked
ImageList_Destroy
#17
ImageList_Create
ole32.dll CoTaskMemFree
OleInitialize
OleUninitialize
CoCreateInstance
VERSION.dll GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1ca8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.10446
MD5 a17f2e482ca58e5361636dafa734736f
SHA1 91b635b7d9d58b89c2c0bf68f1725acbe7346639
SHA256 d36e5d147808deced0fd2f4fe1c4b865bead4dcd5b040dde0942e806b84390f7
SHA3 521beece853a820fb83660ea1db65bae729ed7392a77817d348ae041da5bf33c

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xca8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.3097
MD5 769be8a78fac9d997268d50200ab464d
SHA1 2a4dc818345cd79a303ad9347011277328bb05cd
SHA256 0ec017a62ca688a832c25c071fec9a48e104b8c619166f517c162a719717a7ec
SHA3 1789feebc6dde60278314b200c820e133c6a6dca7111f68d959a3fc0a28a5b12

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x748
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67814
MD5 ff0985584594fa5e403fd14905afe232
SHA1 d8a586691abfb13a16afdcb820348024b40d5273
SHA256 a54e6c424e34ac1824ba678ca03faaf48c689a4ec30741100af0bc386cfc52ce
SHA3 dc98f38a7f9787890ab2c0a5685fad914e08557e2c700b75bc624afa1e2759dc

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.7008
MD5 3a58887b8c496556be40e57faf2a226f
SHA1 6246c5ab923bedd6a5f6ebd231e6885386223fbc
SHA256 7677c850d317ab224ca8198ed5671cbb93eea3ce839e8655d53eb8023f7ba55b
SHA3 d7efe28913a555cf504bd0244b330afd51b2ffd9cdb1569484ec941ad6561adc

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x368
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.08015
MD5 e5ae683008c1ad2bb68858367fce9ce1
SHA1 a4da13a08751a153919f820313bb3eb573956539
SHA256 42b4cac425a68ccc878300845681be5217265d87613f9dba47385c7440ca3ea1
SHA3 2d7122bce344f8d5129baaf9a9b3eb68b91f2809cb31bfb802173a90ce456867

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.98366
MD5 ae8c07ec5b2a661d6c504a50823cbada
SHA1 596e4ae86c1b82fc14aa2cf24a693a117b3460a3
SHA256 00867aef51234722257039fe86d1f9d67c1172807c32d381ffde3074430e2ec6
SHA3 bf35efca0b882005f7e0aa79a5ec9a7fc9d69fd22b455723ba1edae37508ade5

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.1232
MD5 e0a23250e36378b562d99c9bc902af0b
SHA1 e98992633154ab1d5a468540b65f9e06d8de791f
SHA256 a4dc8aeca6e7554b9fa31ac89e5e0d21c96c63581c7e31e3b841388b2c303704
SHA3 b4c9739f1e37e2e8f9fc21516b4ef40288fdfdb196878730f78d491e7712e84f

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.13848
MD5 cfc9a0fb39477bbd5f8e12a9c0a0f8bf
SHA1 9b31b4aaedc672066fbdec48c4be9c97491a53f7
SHA256 29612db231beb57400006a9b8ea3fd6edbd5262c03d72712f8624c04e1905c4b
SHA3 234b1449cf85b8a53f60c7f88aaf430ae944f93435a58385893aeec4dede29be

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x202
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.73893
MD5 386770584473e271f23dced36427f4ff
SHA1 d14ce95f784b35e4e3ebee535476ebcd3e380c19
SHA256 425b8270f7ca42a927eae6bea468acf414a3e4b58b5ba2c56aaae4d1b2c11014
SHA3 db13e5969376b27e8443eebff685230e2b74685aeb2fba73973f06e5cddc8662

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91148
MD5 fa83652660409e90e0db9731ad2adb17
SHA1 0a8f0af67723c87fe26ccf676b8e19ec6357b4dc
SHA256 4a55bd714f5d50cd8eabba10e57f0618f1842717dcfa582d73a917b1933cd1d4
SHA3 5b3e1cb25be7a2dbae4f08f0d4794ed23dbd6ea37a3f9702be12dba588f42a7b

109

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xd4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70146
MD5 2768de5a1178b35d871ea4e120169292
SHA1 6715343b0bc368c77c986db6f7829186b8081310
SHA256 210ea5d77428dc5cfc3f57ab6f20db5abafdd12cfb3dcd78b77a0acc80331d21
SHA3 97e2f9a4f74c5a08545d01bb2de2c4c183db1a42dd3faaa74620636b87a79f6f

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92787
MD5 5dfa289639a3bcc0497da8db163f01fe
SHA1 6e2c6ea1e2594b66f563fb589276642c127e875f
SHA256 18466509968c3c0bf92ba410fea075def2b257a5a799a113cbc60f13e75f4b01
SHA3 85abdc8c431d91c72f3595a39881c96637ead09a0278d3cec0c1c9a8d873f031

205

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x1fa
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.78574
MD5 2c1f44c0a248a53a50a661eb9a65cdcf
SHA1 69a0418cac4aaa30203faa1f0bdbe74fe1cc29c6
SHA256 1382f1e9260b7e203ceafc6936ef1dae48898fcf8fb04a446cd27a4384bc40c3
SHA3 2391f29b4bbdb35210160bdff0e5454a66809bd69915f6c5af5ec10cbbf057aa

206

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04696
MD5 c7239ce55362dabbe3887e5fc4bdf5fe
SHA1 a2908207ffb889a12da3cbdbe7446e04b254e7ed
SHA256 012557f58e68234d4a88df0b713c59800f798ecce19dfd589d326b458dddcbd8
SHA3 34f4adf15b3169820de0c298735a1ea7bc4e5c9737c5baac458a5fbfb356b1f6

209

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xcc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82628
MD5 c845f6d736a4128fd844b01fedf50cfa
SHA1 0b1d7c8fc22fae77b304f6b0d174e1cad0e5dd62
SHA256 5edcae5279b46d3d969f22aaa150f73d193bace4a225368a4a09b2c3f4232a3f
SHA3 75d4b1aa041154ca40ee5f34bd469ac7a3f4dc12c50fb57eadbe4adf10beb157

211

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xe6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.09674
MD5 30dab3583979c2008e8de9295ab7c36b
SHA1 186cd9560b358bbf8b523d1050573f22bb00264d
SHA256 8c64a2341dc473a7d8ab4956af589e9a7257c4f05a8dc229f862c16d49ba37e5
SHA3 4449f57b4725dc59d7d66dc9b817250112828d0f5d6b31cba247cd36ff544268

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x76
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.78426
Detected Filetype Icon file
MD5 1fc50b3fce70ef2d0036c59b388babeb
SHA1 1c16ce82c7cebdd5cb21011d5abfdd478c68552c
SHA256 358fd177a9a3665f2f939831a3ad4d3bc2fb2ec1d304d309cfc80fe76fe999ef
SHA3 f40b13d1c0e3e721983a843f57b8549a2333ca4bff046e0b9ebd018f42696b3b

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x2a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29612
MD5 a5baef820c9285270d5c8c138f19d890
SHA1 9d27e88dcf385fb5aab91fd37d08214b97849f0a
SHA256 beb2e6e03f019bedf99270e105b4690ae9fc2dcf5baa7003d90c370bfcd97271
SHA3 40e92f95e65f8cbed76d40fdd52db9fea6b18092da4e9bb1437805d5556da2f1

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x3c6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.21494
MD5 98e3e14528b61fe20c6bcac5aff75e8e
SHA1 a190daa7d40786b8a07e804c640f220502a887b2
SHA256 e07d7fa88eac47bf707d9cabd85df18a4696a209750a5e6ad1401b0dc2db31bf
SHA3 352b2f397c2aa589b550663b877b5ca1dcb2e74ef6df543282c4b76df0df80b5

Version Info

Signature 0xfeef04bd
StructVersion 0
FileVersion 1.0.62.0
ProductVersion 1.0.62.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName Logitech Europe S.A.
FileDescription Logitech BRIO for Windows Hello
FileVersion (#2) 1.0.62.0
LegalCopyright Copyright 2016
ProductName Logitech BRIO for Windows Hello
ProductVersion (#2) 1.0.62.0
Resource LangID UNKNOWN

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x37178e78
Unmarked objects 0
C objects (VS2012 build 50727 / VS2005 build 50727) 3
Imports (VS2012 build 50727 / VS2005 build 50727) 17
Total imports 168
C objects (VS2008 SP1 build 30729) 11
Linker (VS2008 SP1 build 30729) 1
Resource objects (VS2008 SP1 build 30729) 1

Errors

[*] Warning: Section .ndata has a size of 0!
<-- -->