ZoomDocConverter.exe

  • File Path: C:\Program Files (x86)\Zoom\bin\ZoomDocConverter.exe
  • Description: Zoom
  • Comments: Zoom

Hashes

Type Hash
MD5 8697E1745C1F8819A3B35611FA3B5694
SHA1 90311AA801A1919AD59950499FFA674814EE8FF6
SHA256 7BAFC7820E0B2F6389081C9B732590B29293D79A923601ED97FB4D3823B5DB18
SHA384 A8DF8C1455E2C88A6EF58AA10C540BDD7D66EE4C7D79D139B2659277E67C2DE458E562FBC8E7519E585D02F3099B2453
SHA512 4830AF179BF5A63513E9DE24C4D6EEEAD7ACB7C6B35600453424F36251F4A19B9797C19C4D94560A3106A608B1BE31382761D005999A916298A86F31C35E07BF
SSDEEP 1536:CnyjgbPpwbAo9fSTbzJB6Z1+Sjh20Ec+oTypABD9Y2DA4LghRqidd1HOg/iQo270:J0bjz+9h9HMpkhYsmlp3vKpRBA+BH
IMP FD3BBB6E0EBFAFF2835E8C73C75461FC
PESHA1 A8FE8F411DFE4ACE298C36B9175E47FE715E9482
PE256 C6FF52A4DC459A8B8493DD4342B4E184999399D19A936AA8C153783514A1DA6A

Runtime Data

Open Handles:

Path Type
(R-D) C:\Windows\System32\en-US\basecsp.dll.mui File
(R-D) C:\Windows\System32\en-US\crypt32.dll.mui File
(RW-) C:\Users\user File
(RW-) C:\Users\user\AppData\Roaming\Zoom\appsafecheck.txt File
(RW-) C:\Windows File
\BaseNamedObjects__ComCatalogCache__ Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2 Section
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section
\Sessions\1\BaseNamedObjects\869a4a93-6b81-4d0a-a454-02531317c9a4 Section
\Sessions\1\BaseNamedObjects\windows_shell_global_counters Section

Loaded Modules:

Path
C:\Program Files (x86)\Zoom\bin\ZoomDocConverter.exe
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll

Signature

  • Status: Signature verified.
  • Serial: 03B4BC5EE79D842C03930B8619EDEAE4
  • Thumbprint: 6BA9EF6EB60103B1912B9E79F3EEF4C6F662C4F7
  • Issuer: CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US
  • Subject: CN=”Zoom Video Communications, Inc.”, O=”Zoom Video Communications, Inc.”, L=San Jose, S=California, C=US, SERIALNUMBER=4969967, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US, OID.2.5.4.15=Private Organization

File Metadata

  • Original Filename: Zoom
  • Product Name: Zoom
  • Company Name: Zoom Video Communications, Inc.
  • File Version: 5,8,3,1581
  • Product Version: 5,8,3,1581
  • Language: English (United States)
  • Legal Copyright: Zoom Video Communications, Inc. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/73
  • VirusTotal Link: https://www.virustotal.com/gui/file/7bafc7820e0b2f6389081c9b732590b29293d79a923601ed97fb4d3823b5db18/detection

File Similarity (ssdeep match)

File Score
C:\Program Files (x86)\Zoom\bin\Zoom.exe 44
C:\Program Files (x86)\Zoom\bin\Zoom.exe 32
C:\program files (x86)\Zoom\bin\Zoom.exe 33
C:\Program Files (x86)\Zoom\bin\Zoom.exe 36
C:\Program Files (x86)\Zoom\bin\ZoomDocConverter.exe 38
C:\program files (x86)\Zoom\bin\ZoomDocConverter.exe 46
C:\Program Files (x86)\Zoom\bin\ZoomDocConverter.exe 43
C:\Program Files (x86)\Zoom\bin\zTscoder.exe 40
C:\Program Files (x86)\Zoom\bin\zTscoder.exe 38
C:\program files (x86)\Zoom\bin\zTscoder.exe 44
C:\Program Files (x86)\Zoom\bin\zTscoder.exe 41

MIT License. Copyright (c) 2020-2021 Strontic.