TeamViewer_Desktop.exe

  • File Path: C:\program files (x86)\TeamViewer\TeamViewer_Desktop.exe
  • Description: TeamViewer

Hashes

Type Hash
MD5 F082AFE82D758F11F32CA620B673C984
SHA1 06DA9D729AF0C43608C3E57208A2B29E737725C6
SHA256 C8DC943DB46326906B95C3A072EBBD43C32CEC41494A263720304A422A3AF14C
SHA384 5E11828953B8C5E7BDD935160970BC0A5E2E267F7F5BE950CCCAA52376F273B7D7BB1D0C40B6D37F6C4B91F5A63D030A
SHA512 024DEBFE5ED4525681A2DF3F8B693BB2FEB4CCDBD9EC0A999C76D18702BACFBD347196E984704174B02AD06E66A8806C7763CA20DA1541A0F78054CFE09793B3
SSDEEP 196608:BqtOz5t/L3T1tfe5L44Uq5ZkfhoE2IRRH1NoIhL:BqtOz5tTDeL44qhflsIhL

Runtime Data

Open Handles:

Path Type
(R-D) C:\Windows\System32\en-US\crypt32.dll.mui File
(RW-) C:\Program Files (x86)\TeamViewer\TeamViewer15_Logfile.log File
(RW-) C:\Users\user\Documents File
(RW-) C:\Windows File
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1_none_fd031af45b0106f2 File
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.450_none_4294d6e08a97344a File
\BaseNamedObjects__ComCatalogCache__ Section
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section
\BaseNamedObjects\windows_shell_global_counters Section
\Sessions\1\BaseNamedObjects\TeamViewerHooks7_SharedMemory Section
\Sessions\1\BaseNamedObjects\windows_shell_global_counters Section
\Sessions\1\Windows\Theme4048709601 Section
\Windows\Theme603176458 Section

Loaded Modules:

Path
C:\program files (x86)\TeamViewer\TeamViewer_Desktop.exe
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll

Signature

  • Status: Signature verified.
  • Serial: 0B446546C36525BF5F084F6BBBBA7097
  • Thumbprint: 05CDF79B0EFFFF361DAC0363ADAA75B066C49DE0
  • Issuer: CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US
  • Subject: CN=TeamViewer Germany GmbH, O=TeamViewer Germany GmbH, L=Gppingen, S=Baden-Wrttemberg, C=DE

File Metadata

  • Original Filename: TeamViewer_Desktop.exe
  • Product Name: TeamViewer
  • Company Name: TeamViewer Germany GmbH
  • File Version: 15.9.4.0
  • Product Version: 15.9.4.0
  • Language: English (United Kingdom)
  • Legal Copyright: TeamViewer Germany GmbH

Possible Misuse

The following table contains possible examples of TeamViewer_Desktop.exe being misused. While TeamViewer_Desktop.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma file_event_win_install_teamviewer_desktop.yml description: TeamViewer_Desktop.exe is create during install DRL 1.0
sigma file_event_win_install_teamviewer_desktop.yml TargetFilename\|endswith: \TeamViewer_Desktop.exe DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.