ZoomOutlookIMPlugin.exe

  • File Path: C:\Program Files (x86)\Zoom\bin\ZoomOutlookIMPlugin.exe
  • Description: Zoom
  • Comments: Zoom

Hashes

Type Hash
MD5 B1642BF29E1F2306DD1089AD9586AEA2
SHA1 A707BF9D0959E3086CE20057F5AEC5A046BBBE4E
SHA256 F1844C50CC2FE4364A953E93D46E430738125C6C00366327645A41F82F3CB3A1
SHA384 7B905E1790FEF1258776205CD389FA2CB870C0764EB5FDD76C2F57B438CAD53626AFCB5176FF49BC3878DF78E1FF917A
SHA512 D1A24EBBC9D968D40017B1890F63C3CD3AF3FC01A841D811FDA4296E664A859C62A4767DACF0989238203F15F358DDBA8987CE95C2BB89381A4952D96E72327D
SSDEEP 6144:kHDE3++v7yKC+GJAtlkbsuz+ocFDEufDZtfby4vCpRB70F0RFbV:amC+GJQlO+HIuZhbg1zHbV
IMP 9A9A5C3C9E3DD2D180D3F28A4A0AB29D
PESHA1 51CCA728C962A9DEE93EFED0707449F987423C98
PE256 800879EA7731365F77950D3093B8A3AA891729160A7C2511D01B64D5C9D0025D

Runtime Data

Open Handles:

Path Type
(R-D) C:\Windows\System32\en-US\basecsp.dll.mui File
(R-D) C:\Windows\System32\en-US\crypt32.dll.mui File
(RW-) C:\Users\user File
(RW-) C:\Users\user\AppData\Roaming\Zoom\appsafecheck.txt File
(RW-) C:\Windows File
\BaseNamedObjects__ComCatalogCache__ Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2 Section
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section
\Sessions\1\BaseNamedObjects\ecf80f23-d01a-4787-96b6-429e6a92e0de Section
\Sessions\1\BaseNamedObjects\windows_shell_global_counters Section

Loaded Modules:

Path
C:\Program Files (x86)\Zoom\bin\ZoomOutlookIMPlugin.exe
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll

Signature

  • Status: Signature verified.
  • Serial: 03B4BC5EE79D842C03930B8619EDEAE4
  • Thumbprint: 6BA9EF6EB60103B1912B9E79F3EEF4C6F662C4F7
  • Issuer: CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US
  • Subject: CN=”Zoom Video Communications, Inc.”, O=”Zoom Video Communications, Inc.”, L=San Jose, S=California, C=US, SERIALNUMBER=4969967, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US, OID.2.5.4.15=Private Organization

File Metadata

  • Original Filename: Zoom
  • Product Name: Zoom
  • Company Name: Zoom Video Communications, Inc.
  • File Version: 5,8,3,1581
  • Product Version: 5,8,3,1581
  • Language: English (United States)
  • Legal Copyright: Zoom Video Communications, Inc. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/73
  • VirusTotal Link: https://www.virustotal.com/gui/file/f1844c50cc2fe4364a953e93d46e430738125c6c00366327645a41f82f3cb3a1/detection

MIT License. Copyright (c) 2020-2021 Strontic.