airhost.exe

  • File Path: C:\program files (x86)\Zoom\bin\airhost.exe
  • Description: AirHost

Hashes

Type Hash
MD5 961A4A973104609B8F66665899743A47
SHA1 6CF25C5FAEBFA3A5099787DB0586A609FD3B8402
SHA256 FBF4051FE75A94A89D06D191408C17C2AD7FF26F3D8BBADE0AB4A33B98E5521F
SHA384 B440066E064D428E51875D9D18C0801D090E5F4DB8568EC3C6F6C5B249F5941EEF332DF8580ED3ACC2ABD92C20E501E6
SHA512 9976EF79CD6A8409983F37847A89724A342E380AC2596064E7583348591A856E8FE5DAFA8DF3E81F08F50868CC4C73DA9BE26A5D9E30C45EF7B4FD6AFBE2CC63
SSDEEP 196608:RRB1n96KtsIWoxacwjp3EQDFSQ9Fb8XUx+vuKRtFz8w99Mlrb:oKtsixi3EKJbAluKzz98b

Runtime Data

Open Handles:

Path Type
(R-D) C:\Windows\System32\en-US\crypt32.dll.mui File
(RW-) C:\Users\user\AppData\Roaming\Zoom\appsafecheck.txt File
(RW-) C:\Users\user\Documents File
(RW-) C:\Windows File
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.450_none_4294d6e08a97344a File
\BaseNamedObjects__ComCatalogCache__ Section
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section
\Sessions\1\BaseNamedObjects\e3ed355c-3928-488b-8636-c0148b81bc31 Section
\Sessions\1\BaseNamedObjects\windows_shell_global_counters Section

Loaded Modules:

Path
C:\program files (x86)\Zoom\bin\airhost.exe
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll

Signature

  • Status: Signature verified.
  • Serial: 0510C6B2FF7AB71C786EF572239B1243
  • Thumbprint: 0F9ADA46756C17EFFFD467D10654E2A766566CB3
  • Issuer: CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US
  • Subject: CN=”Zoom Video Communications, Inc.”, O=”Zoom Video Communications, Inc.”, L=San Jose, S=California, C=US, SERIALNUMBER=4969967, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US

File Metadata

  • Original Filename: airhost.exe
  • Product Name: AirHost
  • Company Name: Zoom Video Communications, Inc.
  • File Version: 5.2.44052.0816
  • Product Version: 5.2.44052.0816
  • Language: English (United States)
  • Legal Copyright: Zoom Video Communications, Inc. All rights reserved.

MIT License. Copyright (c) 2020-2021 Strontic.