Suspicious
Suspect

Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
220276c76c19a3f01b9fa8f172b96407
Sha1
9936aff2f3df1286f67bb3853c045d9674b99d5c
Sha256
5d37c15512685f518e28b8f1094b112e8f3cff619d6f0b6ef74d87f79466fa33
Sha384
ff8cf232c7d6f3f445843bb2292792e6b796b74655085896f71d8e29795226335d45c44cbccc968693cc3ac3ca3900e8
Sha512
adb9d4d0d637e9775c7965b4c3804a402e38b5a0c18b11431e6dad9c188863002cdabacea9443b2c63d89a27a97af6ce874056f2742ee922ee75771cbd2eee3f
SSDeep
49152:XjET0+TL3Z0Mi963PSuArmh69eWbVypVCTgGu/aYmn1gC:Tb16Co69eWb0pnGpYmnx
TLSH
EAE5EF01B3E44136D5BF0635DDBA66229B75BC190364C7AF57C879A92E737C08A323A3

PeID

Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ 7.0 - 8.0
Microsoft Visual C++ 8
Microsoft Visual C++ v6.0 DLL
File Structure
[Authenticode]_a0cb53e0.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
FILES
ID:0000
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.rsrc
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1036
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
Root Entry
䡀䆒䑲
䡀䌏䈯
䡀䈖䌧䠤
䡀䌋䄱䜵
䡀䕎䒵䠵
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䓞䕪䇤䠨
䡀䕙䓲䕨䜷
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
ScreenConnect.Properties.CommandSendWindowSystemCommandClose.png
ScreenConnect.Properties.CommandSendWindowSystemCommandClose.png-preview.png
ScreenConnect.Properties.CommandSendWindowSystemCommandMinimize.png
ScreenConnect.Properties.CommandSendWindowSystemCommandMinimize.png-preview.png
ScreenConnect.Properties.CommandSendWindowSystemCommandMaximize.png
ScreenConnect.Properties.CommandSendWindowSystemCommandMaximize.png-preview.png
ScreenConnect.Properties.CommandUndockControlPanel.png
ScreenConnect.Properties.CommandUndockControlPanel.png-preview.png
ScreenConnect.Properties.CommandDockControlPanel.png
ScreenConnect.Properties.CommandDockControlPanel.png-preview.png
ScreenConnect.Properties.ControlPanelView.png
ScreenConnect.Properties.ControlPanelView.png-preview.png
ScreenConnect.Properties.ControlPanelStatus.png
ScreenConnect.Properties.ControlPanelStatus.png-preview.png
ScreenConnect.Properties.ControlPanelToolbox.png
ScreenConnect.Properties.ControlPanelToolbox.png-preview.png
ScreenConnect.Properties.ControlPanelFileTransfer.png
ScreenConnect.Properties.ControlPanelFileTransfer.png-preview.png
ScreenConnect.Properties.ControlPanelScreenCapture.png
ScreenConnect.Properties.ControlPanelScreenCapture.png-preview.png
ScreenConnect.Properties.ControlPanelParticipants.png
ScreenConnect.Properties.ControlPanelParticipants.png-preview.png
ScreenConnect.Properties.ControlPanelMessages.png
ScreenConnect.Properties.ControlPanelMessages.png-preview.png
ScreenConnect.Properties.ControlPanelMiscellaneous.png
ScreenConnect.Properties.ControlPanelMiscellaneous.png-preview.png
ScreenConnect.Properties.CommandOpenFolder.png
ScreenConnect.Properties.CommandOpenFolder.png-preview.png
ScreenConnect.Properties.CommandSelectQualityMedium.png
ScreenConnect.Properties.CommandSelectQualityMedium.png-preview.png
ScreenConnect.Properties.CommandBlankGuestMonitorTrue.png
ScreenConnect.Properties.CommandBlankGuestMonitorTrue.png-preview.png
ScreenConnect.Properties.CommandBlankGuestMonitorFalse.png
ScreenConnect.Properties.CommandBlankGuestMonitorFalse.png-preview.png
ScreenConnect.Properties.CommandSendMessage.png
ScreenConnect.Properties.CommandSendMessage.png-preview.png
ScreenConnect.Properties.CommandTakeScreenshotToFile.png
ScreenConnect.Properties.CommandTakeScreenshotToFile.png-preview.png
ScreenConnect.Properties.CommandTakeScreenshotToClipboard.png
ScreenConnect.Properties.CommandTakeScreenshotToClipboard.png-preview.png
ScreenConnect.Properties.CommandVideoRecord.png
ScreenConnect.Properties.CommandVideoRecord.png-preview.png
ScreenConnect.Properties.CommandVideoPause.png
ScreenConnect.Properties.CommandVideoPause.png-preview.png
ScreenConnect.Properties.CommandSelectQualityLow.png
ScreenConnect.Properties.CommandSelectQualityLow.png-preview.png
ScreenConnect.Properties.CommandChangeFolder.png
ScreenConnect.Properties.CommandChangeFolder.png-preview.png
ScreenConnect.Properties.CommandSendSystemKeyCode.png
ScreenConnect.Properties.CommandSendSystemKeyCode.png-preview.png
ScreenConnect.Properties.CommandRebootToSafeMode.png
ScreenConnect.Properties.CommandRebootToSafeMode.png-preview.png
ScreenConnect.Properties.CommandRebootToNormalMode.png
ScreenConnect.Properties.CommandRebootToNormalMode.png-preview.png
ScreenConnect.Properties.CommandSuspendMyInputTrue.png
ScreenConnect.Properties.CommandSuspendMyInputTrue.png-preview.png
ScreenConnect.Properties.CommandSuspendMyInputFalse.png
ScreenConnect.Properties.CommandSuspendMyInputFalse.png-preview.png
ScreenConnect.Properties.CommandAcquireWakeLockTrue.png
ScreenConnect.Properties.CommandAcquireWakeLockTrue.png-preview.png
ScreenConnect.Properties.CommandSelectQualityHigh.png
ScreenConnect.Properties.CommandSelectQualityHigh.png-preview.png
ScreenConnect.Properties.CommandVideoStop.png
ScreenConnect.Properties.CommandVideoStop.png-preview.png
ScreenConnect.Properties.CommandManageSharedToolbox.png
ScreenConnect.Properties.CommandManageSharedToolbox.png-preview.png
ScreenConnect.Properties.CommandSendFiles.png
ScreenConnect.Properties.CommandSendFiles.png-preview.png
ScreenConnect.Properties.CommandReceiveFiles.png
ScreenConnect.Properties.CommandReceiveFiles.png-preview.png
ScreenConnect.Properties.CommandReceiveFolder.png
ScreenConnect.Properties.CommandReceiveFolder.png-preview.png
ScreenConnect.Properties.CommandSendFolder.png
ScreenConnect.Properties.CommandSendFolder.png-preview.png
ScreenConnect.Properties.ShareMask.png
ScreenConnect.Properties.ShareMask.png-preview.png
ScreenConnect.Properties.ShareGlyph.png
ScreenConnect.Properties.ShareGlyph.png-preview.png
ScreenConnect.Properties.DropDownGlyph.png
ScreenConnect.Properties.DropDownGlyph.png-preview.png
ScreenConnect.Properties.CommandShareMyDesktop.png
ScreenConnect.Properties.CommandShareMyDesktop.png-preview.png
ScreenConnect.Properties.ParticipantRequesting.png
ScreenConnect.Properties.ParticipantRequesting.png-preview.png
ScreenConnect.Properties.CommandDisconnectParticipant.png
ScreenConnect.Properties.CommandDisconnectParticipant.png-preview.png
ScreenConnect.Properties.CommandSendWindowSystemCommandRestore.png
ScreenConnect.Properties.CommandSendWindowSystemCommandRestore.png-preview.png
ScreenConnect.Properties.ControlPanelShare.png
ScreenConnect.Properties.ControlPanelShare.png-preview.png
ScreenConnect.Properties.ParticipantSendingInput.png
ScreenConnect.Properties.ParticipantSendingInput.png-preview.png
ScreenConnect.Properties.ParticipantGuest.png
ScreenConnect.Properties.ParticipantGuest.png-preview.png
ScreenConnect.Properties.ParticipantHost.png
ScreenConnect.Properties.ParticipantHost.png-preview.png
ScreenConnect.Properties.CommandManageCredentialsSendToScreen.png
ScreenConnect.Properties.CommandManageCredentialsSendToScreen.png-preview.png
ScreenConnect.Properties.ControlPanelSound.png
ScreenConnect.Properties.ControlPanelSound.png-preview.png
ScreenConnect.Properties.CommandSelectSoundCaptureModeSpeakers.png
ScreenConnect.Properties.CommandSelectSoundCaptureModeSpeakers.png-preview.png
ScreenConnect.Properties.CommandSelectSoundCaptureModeSilent.png
ScreenConnect.Properties.CommandSelectSoundCaptureModeSilent.png-preview.png
ScreenConnect.Properties.CommandSelectSoundCaptureModeHostMicrophone.png
ScreenConnect.Properties.CommandSelectSoundCaptureModeHostMicrophone.png-preview.png
ScreenConnect.Properties.CommandSelectSoundCaptureModeAllMicrophones.png
ScreenConnect.Properties.CommandSelectSoundCaptureModeAllMicrophones.png-preview.png
ScreenConnect.Properties.ParticipantMicrophoneSending.png
ScreenConnect.Properties.ParticipantMicrophoneSending.png-preview.png
ScreenConnect.Properties.ParticipantSpeakers.png
ScreenConnect.Properties.ParticipantSpeakers.png-preview.png
ScreenConnect.Properties.ParticipantSpeakersSending.png
ScreenConnect.Properties.ParticipantSpeakersSending.png-preview.png
ScreenConnect.Properties.CommandRegenerateParticipantColor.png
ScreenConnect.Properties.CommandRegenerateParticipantColor.png-preview.png
ScreenConnect.Properties.ControlPanelAnnotation.png
ScreenConnect.Properties.ControlPanelAnnotation.png-preview.png
ScreenConnect.Properties.CommandSelectAnnotationStrokeThicknessMedium.png
ScreenConnect.Properties.CommandSelectAnnotationStrokeThicknessMedium.png-preview.png
ScreenConnect.Properties.CommandSelectAnnotationStrokeThicknessThick.png
ScreenConnect.Properties.CommandSelectAnnotationStrokeThicknessThick.png-preview.png
ScreenConnect.Properties.CommandSelectAnnotationStrokeThicknessThin.png
ScreenConnect.Properties.CommandSelectAnnotationStrokeThicknessThin.png-preview.png
ScreenConnect.Properties.ParticipantAnnotating.png
ScreenConnect.Properties.ParticipantAnnotating.png-preview.png
ScreenConnect.Properties.CommandSelectAnnotationModeAllDraw.png
ScreenConnect.Properties.CommandSelectAnnotationModeAllDraw.png-preview.png
ScreenConnect.Properties.CommandSelectAnnotationModeHostDraw.png
ScreenConnect.Properties.CommandSelectAnnotationModeHostDraw.png-preview.png
ScreenConnect.Properties.CommandSelectAnnotationModeInvisible.png
ScreenConnect.Properties.CommandSelectAnnotationModeInvisible.png-preview.png
ScreenConnect.Properties.CommandSelectAnnotationModeViewOnly.png
ScreenConnect.Properties.CommandSelectAnnotationModeViewOnly.png-preview.png
ScreenConnect.Properties.CommandSelectAnnotationToolEllipse.png
ScreenConnect.Properties.CommandSelectAnnotationToolEllipse.png-preview.png
ScreenConnect.Properties.CommandSelectAnnotationToolLine.png
ScreenConnect.Properties.CommandSelectAnnotationToolLine.png-preview.png
ScreenConnect.Properties.CommandSelectAnnotationToolRectangle.png
ScreenConnect.Properties.CommandSelectAnnotationToolRectangle.png-preview.png
ScreenConnect.Properties.ControlPanelHelper.png
ScreenConnect.Properties.ControlPanelHelper.png-preview.png
ScreenConnect.Properties.CommandSelectHelperHighlightToolNone.png
ScreenConnect.Properties.CommandSelectHelperHighlightToolNone.png-preview.png
ScreenConnect.Properties.CommandSelectHelperHighlightToolCross.png
ScreenConnect.Properties.CommandSelectHelperHighlightToolCross.png-preview.png
ScreenConnect.Properties.CommandSelectHelperHighlightToolLasso.png
ScreenConnect.Properties.CommandSelectHelperHighlightToolLasso.png-preview.png
ScreenConnect.Properties.CommandSendClipboardKeystrokes.png
ScreenConnect.Properties.CommandSendClipboardKeystrokes.png-preview.png
ScreenConnect.Properties.NotificationOptionsIcon.png
ScreenConnect.Properties.NotificationOptionsIcon.png-preview.png
ScreenConnect.Properties.StatusGlyphGuestNotConnected.png
ScreenConnect.Properties.StatusGlyphGuestNotConnected.png-preview.png
ScreenConnect.Properties.StatusGlyphGuestAndHostConnected.png
ScreenConnect.Properties.StatusGlyphGuestAndHostConnected.png-preview.png
ScreenConnect.Properties.StatusGlyphBlankMonitor.png
ScreenConnect.Properties.StatusGlyphBlankMonitor.png-preview.png
ScreenConnect.Properties.StatusGlyphMask.png
ScreenConnect.Properties.StatusGlyphMask.png-preview.png
ScreenConnect.Properties.FeedbackBannerLogo.png
ScreenConnect.Properties.FeedbackBannerLogo.png-preview.png
ScreenConnect.Properties.Lasso.cur
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
[Authenticode]_5d6205b9.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
ScreenConnect.WindowsClient.exe.config
ServiceExeWithoutService
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
䡀䈛㵪䆲䗤䕲
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀䓊㼳䄨䆵䠫
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䕌䄨䈷䒏䇯䕨
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䆒䑲㭾䉨䘤䗯䆒䑲
䡀䈜䘦䈵䅘䈭䗦䠶
䡀䈜䙵䆬㬨䑲䌩䠪
䡀䈜䙵䆬㬨䑲䕷䏲
䡀䈜䙵䆬㲨䖱䄷䏯
䡀䄕䑸䋦䒌䇱䗬䒬䠱
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
Overlay_7d669e13.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
ID:1033
RT_MANIFEST
ID:0002
ID:1033
CustomAction.config
SummaryInformation
[Authenticode]_319e55aa.p7b
RT_MANIFEST
ID:0001
ID:1033
ScreenConnect.ClientService.dll
ScreenConnect.Core.dll
ScreenConnect.Windows.dll
ScreenConnect.WindowsClient.exe
ScreenConnect.WindowsClient.exe.config
ServiceExeWithoutService
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
.Net Resources
Microsoft.Deployment.WindowsInstaller.Errors.resources
CustomAction.config
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x2F2000 size 50456 bytes

Info

PDB Path: C:\Users\jmorgan\Source\ScreenConnectWork\Custom\DotNetRunner\Release\DotNetRunner.pdb

Artefacts
Name
Value
PE Layout

MemoryMapped (process dump suspected)

PE Layout

MemoryMapped (process dump suspected)

220276c76c19a3f01b9fa8f172b96407 (3.14 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙