TeamViewer_Desktop.exe

  • File Path: C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
  • Description: TeamViewer

Hashes

Type Hash
MD5 7640D511299BB6A30953C2A718EA0FF1
SHA1 BF6DEE11212D24D470F5A0B6DD826E47ED2438C3
SHA256 E2D3C2C379A50A3B9121EBA1D1E5A465B30F6F3819D844DD884585EF6122C7EC
SHA384 DA710B8AFFCDAD0FFE678D6E92330874B6C0E2C6AC37571DF84CE5E402744BFC4C50FC652E699506C460F0C59E134B2C
SHA512 B640CC1EAB40FC9AA5D90BD9DAFB8AE4E03BAD1664D8D6F47980797623989B2B49A42806F6796DD9B661BB904E16E5E67FE02CFAD967BAD300ACA95132AB3BF7
SSDEEP 98304:BSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSvSSSSSSSSSSSSSSSlwwwwwwwwwwwwwwD:s+tOz5tgtnDzh7cOvYE6W4mAxeRgAWW
IMP FF588FD33C85889D93D3BCE8DB47C223
PESHA1 6C1F214A00B745C1D9363D36A1EF6C6A0E3AEAAA
PE256 7C5D19CD2C2B1D5C573D3181C1FE6888378476AFD052B94D1BE7F22C9071933F

Runtime Data

Open Handles:

Path Type
(R-D) C:\Windows\System32\en-US\crypt32.dll.mui File
(RW-) C:\Program Files (x86)\TeamViewer\TeamViewer15_Logfile.log File
(RW-) C:\Windows File
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627 File
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.508_none_429cdbca8a8ffa94 File
(RW-) C:\xCyclopedia File
\BaseNamedObjects__ComCatalogCache__ Section
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section
\BaseNamedObjects\windows_shell_global_counters Section
\Sessions\1\BaseNamedObjects\TeamViewerHooks7_SharedMemory Section
\Sessions\1\BaseNamedObjects\windows_shell_global_counters Section
\Sessions\1\Windows\Theme2547664911 Section
\Windows\Theme3854699184 Section

Loaded Modules:

Path
C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll

Signature

  • Status: Signature verified.
  • Serial: 0B446546C36525BF5F084F6BBBBA7097
  • Thumbprint: 05CDF79B0EFFFF361DAC0363ADAA75B066C49DE0
  • Issuer: CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US
  • Subject: CN=TeamViewer Germany GmbH, O=TeamViewer Germany GmbH, L=Gppingen, S=Baden-Wrttemberg, C=DE

File Metadata

  • Original Filename: TeamViewer_Desktop.exe
  • Product Name: TeamViewer
  • Company Name: TeamViewer Germany GmbH
  • File Version: 15.10.5.0
  • Product Version: 15.10.5.0
  • Language: English (United Kingdom)
  • Legal Copyright: TeamViewer Germany GmbH
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/69
  • VirusTotal Link: https://www.virustotal.com/gui/file/e2d3c2c379a50a3b9121eba1d1e5a465b30f6f3819d844dd884585ef6122c7ec/detection/

Possible Misuse

The following table contains possible examples of TeamViewer_Desktop.exe being misused. While TeamViewer_Desktop.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma file_event_win_install_teamviewer_desktop.yml description: TeamViewer_Desktop.exe is create during install DRL 1.0
sigma file_event_win_install_teamviewer_desktop.yml TargetFilename\|endswith: \TeamViewer_Desktop.exe DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.