Architecture |
IMAGE_FILE_MACHINE_I386
|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date |
2020-Dec-07 16:54:18
|
Detected languages |
English - United States
|
Debug artifacts |
C:\Buildbot\ad-windows-32\build\release\app-32\win_loader\AnyDesk.pdb
|
CompanyName |
philandro Software GmbH
|
FileDescription |
AnyDesk
|
FileVersion |
6.1.0.0
|
ProductName |
AnyDesk
|
ProductVersion |
6.1
|
LegalCopyright |
(C) 2020 philandro Software GmbH
|
Suspicious |
The PE is possibly packed. |
Unusual section name found: .itext
The PE only has 0 import(s).
|
Info |
The PE is digitally signed. |
Signer: philandro Software GmbH
Issuer: DigiCert SHA2 Assured ID Code Signing CA
|
Safe |
VirusTotal score: 0/75 (Scanned on 2024-08-26 13:54:35) |
All the AVs think this file is safe.
|
MD5 |
f001df5b52fbca29d9e5afa2e6f3de33
|
SHA1 |
49b58f88e05c30f8b2c13e2f899a6d3baad8ef59
|
SHA256 |
8d7a66b358a2aa010b3eca61f1881daa0a3a480b620cf1704361ce956f5b3a08
|
SHA3 |
1a96aefbddf0d8f30d72b826ecc6f992e5fb178b986d14bd44ddeaa4c9e3a7d1
|
SSDeep |
98304:NkH7Nybm7mWWyD0UHvTEAUwTDfpKgXBo6XZaMA:ibwbQWyDHLEOpXXZat
|
Imports Hash |
d41d8cd98f00b204e9800998ecf8427e
|
e_magic |
MZ
|
e_cblp |
0x90
|
e_cp |
0x3
|
e_crlc |
0
|
e_cparhdr |
0x4
|
e_minalloc |
0
|
e_maxalloc |
0xffff
|
e_ss |
0
|
e_sp |
0xb8
|
e_csum |
0
|
e_ip |
0
|
e_cs |
0
|
e_ovno |
0
|
e_oemid |
0
|
e_oeminfo |
0
|
e_lfanew |
0xd0
|
Signature |
PE
|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections |
6
|
TimeDateStamp |
2020-Dec-07 16:54:18
|
PointerToSymbolTable |
0
|
NumberOfSymbols |
0
|
SizeOfOptionalHeader |
0xe0
|
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic |
PE32
|
LinkerVersion |
10.0
|
SizeOfCode |
0x2a00
|
SizeOfInitializedData |
0x382e00
|
SizeOfUninitializedData |
0xa19200
|
AddressOfEntryPoint |
0x00001CE9 (Section: .text)
|
BaseOfCode |
0x1000
|
BaseOfData |
0x4000
|
ImageBase |
0x400000
|
SectionAlignment |
0x1000
|
FileAlignment |
0x200
|
OperatingSystemVersion |
5.1
|
ImageVersion |
0.0
|
SubsystemVersion |
5.1
|
Win32VersionValue |
0
|
SizeOfImage |
0xda4000
|
SizeOfHeaders |
0x400
|
Checksum |
0x394712
|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve |
0x100000
|
SizeofStackCommit |
0x1000
|
SizeofHeapReserve |
0x100000
|
SizeofHeapCommit |
0x1000
|
LoaderFlags |
0
|
NumberOfRvaAndSizes |
16
|
MD5 |
61415f7e410e6aec8482c7f4d3d6396b
|
SHA1 |
36b11c093ae4086be7645df9f9880563c040a6e1
|
SHA256 |
8b9bfe2ae2c30381efae1d644e50260b309208b803e2a4dfb7aac4edbb186027
|
SHA3 |
4480c379748c41fc8d20596e0ffd7e90e4e1de1d2933ffd05608be5bf4c8324e
|
VirtualSize |
0x2835
|
VirtualAddress |
0x1000
|
SizeOfRawData |
0x2a00
|
PointerToRawData |
0x400
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
Entropy |
6.50761
|
MD5 |
d41d8cd98f00b204e9800998ecf8427e
|
SHA1 |
da39a3ee5e6b4b0d3255bfef95601890afd80709
|
SHA256 |
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
|
SHA3 |
a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
|
VirtualSize |
0xa19200
|
VirtualAddress |
0x4000
|
SizeOfRawData |
0
|
PointerToRawData |
0
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
MD5 |
88ff5f8dfa016d5e7a93b199bfabed45
|
SHA1 |
56824b02171a242cc04e6e1fbf67fc817b989b7f
|
SHA256 |
faec0afc1774bfa7f4f13edeb2fb8313821c3734a0ed79160271461bfa2a3d1d
|
SHA3 |
a9a1efe4d749327f574e9deca5c8d938fa0eeb5a6ed808127c2a96bfc2c68e26
|
VirtualSize |
0x2fe
|
VirtualAddress |
0xa1e000
|
SizeOfRawData |
0x400
|
PointerToRawData |
0x2e00
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
Entropy |
5.66732
|
MD5 |
e6839446dfce3acc8f2d19c54a969630
|
SHA1 |
bc4ad7b872e0aa21c3de7eb1885dee5f1ee4254f
|
SHA256 |
4cfd53d85fd7be4dc9bc8040430eb339f2f4208a7b9a37c2c150cab0c838559a
|
SHA3 |
e85f3eb5cafd7a889aa079f5f5a553d9532b1fa15e676aa3200f471b3334728f
|
VirtualSize |
0x37f11c
|
VirtualAddress |
0xa1f000
|
SizeOfRawData |
0x37ee00
|
PointerToRawData |
0x3200
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
Entropy |
7.99996
|
MD5 |
c4a5cbc84ca241898a82e4259e68b3a0
|
SHA1 |
aa392e6d39325af724410015e379e9fb8b44a443
|
SHA256 |
855e509959ae79e0c4397bad6d31464a4221e64103d1fff9be9fce54ea16be53
|
SHA3 |
fd96d625225e1d83c5308daf147da5306cfdc8cfc481aed6b7948d4d66e77232
|
VirtualSize |
0x3290
|
VirtualAddress |
0xd9f000
|
SizeOfRawData |
0x3400
|
PointerToRawData |
0x382000
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
Entropy |
6.68429
|
MD5 |
95aa79c39ba19e7065545a9504efb057
|
SHA1 |
0b146f6223287e78734c21d004fd6e2764080bdb
|
SHA256 |
d909b4b19ef8c89005170ccce336cef3c4390d831c9dd2480dd95cceeeba9382
|
SHA3 |
8a336fa1a4212c3f4a719a03b8b4136c86a4d57a1cf343ec42422a5f6b60c59b
|
VirtualSize |
0x300
|
VirtualAddress |
0xda3000
|
SizeOfRawData |
0x400
|
PointerToRawData |
0x385400
|
PointerToRelocations |
0
|
PointerToLineNumbers |
0
|
NumberOfLineNumbers |
0
|
NumberOfRelocations |
0
|
Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
Entropy |
1.18127
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x1b8e
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
7.83901
|
Detected Filetype |
PNG graphic file
|
MD5 |
c88936dd1a7d59c4403d6babb04dd87e
|
SHA1 |
cc33904defad90d05ccec92b7fff7d5902941795
|
SHA256 |
ea057e896209478d8290a1b526cae84f2509678d866d08382614707f3b710d47
|
SHA3 |
28528f7316cb893a622c6611bbd967fcc40de2bf615e7332dee0fbd31997398e
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x668
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.29968
|
MD5 |
092bef43014ecb8adbaf06131ce5e40b
|
SHA1 |
1b15bd67961afbecb0cbbd1183c2d0dc9ed9e7cf
|
SHA256 |
f50850ec3e997252b5533691868d04c15e923efe4f694c0ea8126f612e60404c
|
SHA3 |
cab0b87867861997a7a03b362811b9052b40dea25bcd54a88c60956b6f6e9968
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x2e8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.6735
|
MD5 |
3a69266d6258e81e65a29138c95fe2a8
|
SHA1 |
606560abf36b292f238d7ad4aa6c09ec8a21f8a3
|
SHA256 |
bc1cb94bcc63c8541ff535da88ed153ff3346db3fb93fc27fe87d414b2038dc4
|
SHA3 |
4204359c479df05357b6bf705b0d2961c1a4317d43977784fcf2835e25209f54
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x1e8
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.73746
|
MD5 |
75705b8eedfc400d14f7ae9c8f40935b
|
SHA1 |
ebecc73c1403107ce631cc21a6c4262a4c0ee1aa
|
SHA256 |
c433628ee32bb8698e81f2ebb23d615e4bcf34ba954055410c64c3638c95503c
|
SHA3 |
3b0525e50fdad680ebf6318fef60a34ffd36ae26a82fa7bb4675d27b0227a0e2
|
Type |
RT_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x128
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.69265
|
MD5 |
76b057741da4577549a4b9ef8f585bb3
|
SHA1 |
4d4f6f821507639f8214bae9aa2be1f480b7e844
|
SHA256 |
b008246dad106e522b98810ce6bc1212c8f12e78a6f77506283782438ea5b65d
|
SHA3 |
acce4c5df16010fce31dd43cfe4645d11a9aadc7ccd5da162bdbd154c1ac9b78
|
Type |
RT_GROUP_ICON
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x4c
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
2.78538
|
Detected Filetype |
Icon file
|
MD5 |
53975c41e7520296015f9db3f16a6c74
|
SHA1 |
03aad254664361f296e2c982968d4afb537a573e
|
SHA256 |
4041084c14f8f142bf7919feedf1437c9bdb5c3040db4a2bd2b0cf387f006fcf
|
SHA3 |
79879cd09c0a4a1d24967b53fe230d9ae0fc1613299a75561402de6ad65509c7
|
Type |
RT_VERSION
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x258
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
3.34483
|
MD5 |
8824579a779d422607a389e23709376f
|
SHA1 |
70b43c5c7b398ce3eae24d70adec586062195fc6
|
SHA256 |
c65b684cff4dc51993b2e0f7d528faea66380c88a0997d5ca2d755c66986e6cc
|
SHA3 |
fc39e2b76fee1d545222c6fda83803056b6cabc6146b145bf0b2518a0688d755
|
Type |
RT_MANIFEST
|
Language |
English - United States
|
Codepage |
UNKNOWN
|
Size |
0x607
|
TimeDateStamp |
1980-Jan-01 00:00:00
|
Entropy |
5.39322
|
MD5 |
4c62402341eba95313db87d93536ebfc
|
SHA1 |
14a2b6b042e719b5dad2230311b7ed63f8f455d1
|
SHA256 |
5a897111b23fc3c6ee8b2d494c0f3ae6d76da2cfd8f2cd92670c0b08569fb2d9
|
SHA3 |
99a9f4268379f6ff484fdd75f3108db843a54155071906bf89b2f47deb422eae
|
Signature |
0xfeef04bd
|
StructVersion |
0x10000
|
FileVersion |
6.1.0.0
|
ProductVersion |
0.0.0.0
|
FileFlags |
(EMPTY)
|
FileOs |
(EMPTY)
|
FileType |
VFT_APP
|
Language |
English - United States
|
CompanyName |
philandro Software GmbH
|
FileDescription |
AnyDesk
|
FileVersion (#2) |
6.1.0.0
|
ProductName |
AnyDesk
|
ProductVersion (#2) |
6.1
|
LegalCopyright |
(C) 2020 philandro Software GmbH
|
Resource LangID |
English - United States
|
Characteristics |
0
|
TimeDateStamp |
2020-Dec-07 16:54:18
|
Version |
0.0
|
SizeofData |
94
|
AddressOfRawData |
0xa1e2a0
|
PointerToRawData |
0x30a0
|
Referenced File |
C:\Buildbot\ad-windows-32\build\release\app-32\win_loader\AnyDesk.pdb
|
XOR Key |
0x3b897dad
|
Unmarked objects |
0
|
C++ objects (VS2010 build 30319) |
8
|
C objects (VS2010 build 30319) |
3
|
Resource objects (VS2010 SP1 build 40219) |
1
|
Linker (VS2010 build 30319) |
1
|
[*] Warning: Section .itext has a size of 0!