| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Feb-16 00:51:55 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\Default.DESKTOP-9CGK2DI\Desktop\AmtWebApp\MeshAgent\Release\MeshService64.pdb
|
| FileDescription | MeshCentral Background Service Agent |
| FileVersion | 2026-Feb-15 16:43:44-0800 |
| LegalCopyright | Apache 2.0 License |
| ProductName | MeshCentral Agent |
| ProductVersion | Commit: 2026-Feb-15 16:43:44-0800 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 Uses constants related to AES Uses known Diffie-Helman primes Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: mesh.jg06.co.uk-e74a85
Issuer: MeshCentralRoot-850c87 |
| Malicious | VirusTotal score: 11/71 (Scanned on 2026-09-24 19:04:41) |
Antiy-AVL:
RiskWare[RemoteAdmin]/Win32.MeshAgent
CAT-QuickHeal: PUA.MeshAgent.S37934379 CrowdStrike: win/grayware_confidence_70% (D) DeepInstinct: MALICIOUS Elastic: malicious (high confidence) Gridinsoft: Adware.Win64.Agent.oa!s1 McAfeeD: ti!99A7ABAD0F4E Rising: HackTool.MeshAgent!8.13A31 (TFE:5:0A0XrBYvp8M) SentinelOne: Static AI - Suspicious PE Skyhigh: BehavesLike.Win64.Dropper.wh Sophos: Generic ML PUA (PUA) |
| MD5 | 87a2b0957bcc2cf4706213ad94ac0bec 🔍 |
|---|---|
| SHA1 | 736df824f4ec1b9b9c996fdbb7ef9cf2b599e41e 🔍 |
| SHA256 | 99a7abad0f4e79fc9120f2ae250bb716d57e8b130c9f81f403cba0839aeed216 🔍 |
| SHA3 | 6ef096702231b490cae05831b6e5b09885fc096bc3486743a6b8691f2a449f33 🔍 |
| SSDeep | 49152:EMSGj9zai9bsddr7AaPcZumeRQyKpzSPQBcnMFvf8AC4Z78bRwlI5fT:xd9AddBcryO3cICgI9T 🔍 |
| Imports Hash | 1beb656f21b9419cba7deef0272fc88b 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x130 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Feb-16 00:51:55 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x206600 |
| SizeOfInitializedData | 0x16b000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000001DA25C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x376000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x34dd90 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 0ea6011698baa4cca3ea30913f7e9a80 🔍 |
|---|---|
| SHA1 | 02dca970acf1955968534775b89192aca3c9e274 🔍 |
| SHA256 | 2f42501aaca97f1918715d972fd25aa0eb8f94d1269450b994926477f74bf215 🔍 |
| SHA3 | f811145920d78f8076eacb80d2aeb2d899d027ed0da500a7f5a51147518ed8f0 🔍 |
| VirtualSize | 0x2065ca |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x206600 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.45895 |
| MD5 | 617b949fda6cf5819be6063bdca36ea2 🔍 |
|---|---|
| SHA1 | 5b9e57787e1d38b5cf079acaa9325f2e71328353 🔍 |
| SHA256 | ad07bcbe5d542190b2c75295495dcedb3fa191a518651e3977004cff82ae9128 🔍 |
| SHA3 | ff4ae0afdb1100df044e2eb1b321347f4f1addb368f62f9ed2a126464474a625 🔍 |
| VirtualSize | 0xf8376 |
| VirtualAddress | 0x208000 |
| SizeOfRawData | 0xf8400 |
| PointerToRawData | 0x206a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.45197 |
| MD5 | 5ae3b2c0e600ed194ee505112c0cba99 🔍 |
|---|---|
| SHA1 | 8bd2c66196c1b0c3a212b86fa3968f81c952f3a1 🔍 |
| SHA256 | 4dbb4b538265ce91ec69bac872e947dc9ed32e236e87043f8ddc4a6f6715c1ed 🔍 |
| SHA3 | 5799bfb201921f446fcc94113a109c35cd9f33643eab6431c934f5fd42f73a03 🔍 |
| VirtualSize | 0x325b8 |
| VirtualAddress | 0x301000 |
| SizeOfRawData | 0x9c00 |
| PointerToRawData | 0x2fee00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 5.67635 |
| MD5 | f9d439007557662f2d12baafb5f8f3f1 🔍 |
|---|---|
| SHA1 | 31ada94bb743a0ce7d2470b0cb37b20549d3d9ba 🔍 |
| SHA256 | c0d71b6f46265354e299e84911e5838f937542b999a14138fb7e42a332b8fb93 🔍 |
| SHA3 | 203ffe9b4db0bee0a5e38524dadc85e49b033d4df8859fe04d01ff452622e139 🔍 |
| VirtualSize | 0x196e0 |
| VirtualAddress | 0x334000 |
| SizeOfRawData | 0x19800 |
| PointerToRawData | 0x308a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.2474 |
| MD5 | 45e75f900b562af889f84d8193886df4 🔍 |
|---|---|
| SHA1 | f9d82c2742769f4fad0cadfb67aa3d00af79019f 🔍 |
| SHA256 | 81782a558b2a44b3b19dd2df7653770e464ed3b7384faa743eaf5ea6591ed8d7 🔍 |
| SHA3 | ef69cb76c929cd542da544f6e535a2ed3c3e8b4b4660ef365e5ef0e3cfe1c6e0 🔍 |
| VirtualSize | 0xc4 |
| VirtualAddress | 0x34e000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x322200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 1.90546 |
| MD5 | 81387d3ede4e109ae4c0ac181e3a61a0 🔍 |
|---|---|
| SHA1 | 687c756cf1555449619c64600b7370bb4ea0f19a 🔍 |
| SHA256 | ca8d3a9e6afa9fcf193f4570012a4616d16de2466fcd56c80c7a7cddcb3efee9 🔍 |
| SHA3 | b46a65e5a7916c702f51959baf1ddae50de106a3e6c4039311a2ea5f3d94a723 🔍 |
| VirtualSize | 0x22000 |
| VirtualAddress | 0x34f000 |
| SizeOfRawData | 0x22000 |
| PointerToRawData | 0x322400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.02801 |
| MD5 | 3f772e015cc7e629bce6ed0ecaa05ddd 🔍 |
|---|---|
| SHA1 | e26c13c099ab1f98adb227ce95b338e5cfa07c9f 🔍 |
| SHA256 | d03939d6b82068ebf2ee4f534f8b3061e8ff298d0ded151ee783944793e1ea69 🔍 |
| SHA3 | f38515d67d022966fd613cacc1d6e9b90229bba9919ec613f3cf1799ec1fa242 🔍 |
| VirtualSize | 0x4b8c |
| VirtualAddress | 0x371000 |
| SizeOfRawData | 0x4c00 |
| PointerToRawData | 0x344400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.45228 |
| COMCTL32.dll |
InitCommonControlsEx
|
|---|---|
| dbghelp.dll |
SymInitialize
SymGetModuleBase64 SymGetLineFromAddr64 SymFunctionTableAccess64 SymFromAddr StackWalk64 MiniDumpWriteDump |
| IPHLPAPI.DLL |
GetAdaptersAddresses
SendARP ConvertLengthToIpv4Mask GetAdaptersInfo |
| WS2_32.dll |
WSACloseEvent
htons htonl gethostname ntohs ntohl WSAGetLastError ioctlsocket recv send WSASetLastError getsockname WSASocketW listen closesocket bind accept __WSAFDIsSet setsockopt socket sendto getsockopt recvfrom connect shutdown WSAIoctl GetAddrInfoW WSAResetEvent WSAEventSelect WSAStartup WSACreateEvent WSACleanup FreeAddrInfoW select |
| CRYPT32.dll |
CryptMsgCalculateEncodedLength
CertDuplicateCertificateContext CertDeleteCertificateFromStore CryptAcquireCertificatePrivateKey CertAddEncodedCertificateToStore CryptMsgClose CryptMsgUpdate CryptExportPublicKeyInfo CertCreateSelfSignCertificate CertFreeCertificateContext CryptMsgOpenToEncode CertAddCertificateContextToStore PFXExportCertStore CryptSignAndEncodeCertificate CertCloseStore CertStrToNameA CryptMsgGetParam CryptEncodeObject CertSetCertificateContextProperty CertFindCertificateInStore CertGetCertificateContextProperty CertOpenStore CertStrToNameW CertOpenSystemStoreW CertEnumCertificatesInStore |
| gdiplus.dll |
GdipGetImageEncoders
GdiplusShutdown GdipCloneImage GdipAlloc GdipDisposeImage GdipFree GdipGetImageEncodersSize GdipLoadImageFromStream GdipSaveImageToStream GdiplusStartup |
| ncrypt.dll |
NCryptCreatePersistedKey
NCryptSetProperty NCryptFreeObject BCryptCloseAlgorithmProvider BCryptGenRandom NCryptOpenStorageProvider BCryptOpenAlgorithmProvider NCryptFinalizeKey |
| KERNEL32.dll |
InitializeSListHead
GetStartupInfoW RtlUnwindEx GetFullPathNameW GetStdHandle WriteFile LoadLibraryExA GetModuleFileNameW GetSystemPowerStatus OpenProcess MultiByteToWideChar Sleep GetLastError CloseHandle GetCurrentDirectoryW SetCurrentDirectoryW GetProcAddress SetEnvironmentVariableA CreateProcessW FreeLibrary WideCharToMultiByte GetCurrentThreadId GetModuleHandleA WaitForSingleObjectEx CreateThread QueueUserAPC OpenThread ReadFile LoadLibraryA SleepEx SetSystemPowerState GetCurrentProcess SetThreadExecutionState HeapFree HeapAlloc GetProcessHeap SystemTimeToFileTime EnterCriticalSection FileTimeToSystemTime QueryPerformanceFrequency SystemTimeToTzSpecificLocalTime QueryPerformanceCounter ReleaseSemaphore WaitForSingleObject CreateSemaphoreA CancelIo FindFirstFileW FindNextFileW RemoveDirectoryW GetFinalPathNameByHandleW GetDriveTypeA SetFilePointer FindFirstVolumeA FindClose CreateFileW GetVolumePathNamesForVolumeNameA GetFileAttributesExW ReadDirectoryChangesW FindNextVolumeA FindVolumeClose GetDiskFreeSpaceExA CreateEventA GetModuleHandleExA WaitForMultipleObjectsEx CreateNamedPipeA DisconnectNamedPipe CreateFileA CancelIoEx LocalFree ConnectNamedPipe SetConsoleMode GetConsoleMode SetConsoleOutputCP IsDebuggerPresent TerminateProcess GetTempPathW CancelSynchronousIo SetEvent IsProcessorFeaturePresent GetThreadId GetCurrentProcessId GetEnvironmentStrings FreeEnvironmentStringsA CopyFileW RtlCaptureContext SuspendThread ResumeThread DuplicateHandle GetTickCount64 GetCurrentThread GetOverlappedResult GetThreadContext WTSGetActiveConsoleSessionId GetExitCodeProcess SetEndOfFile DeleteFileW SetFilePointerEx SetConsoleCtrlHandler FreeConsole LoadLibraryExW SetLastError GetFileType GetModuleHandleW SwitchToFiber DeleteFiber CreateFiber GetSystemTimeAsFileTime ConvertFiberToThread ConvertThreadToFiber GetEnvironmentVariableW ReadConsoleA ReadConsoleW LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree ExitProcess GetModuleHandleExW CreateDirectoryW GetConsoleCP MoveFileExW SetEnvironmentVariableW GetTimeZoneInformation SetStdHandle GetDriveTypeW PeekNamedPipe GetCommandLineA GetCommandLineW GetACP GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetStringTypeW HeapReAlloc FlushFileBuffers WriteConsoleW GetCPInfo FindFirstFileExW SetUnhandledExceptionFilter RtlLookupFunctionEntry RtlVirtualUnwind ResetEvent UnhandledExceptionFilter IsValidCodePage GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW RaiseException HeapSize RtlPcToFileHeader GetSystemTime EncodePointer |
| USER32.dll |
EndDialog
SetWindowTextW GetWindowPlacement ShowWindow GetDlgCtrlID SetWindowPlacement SetWindowTextA IsDlgButtonChecked GetDlgItem CheckDlgButton DialogBoxParamW EnableWindow MessageBeep ExitWindowsEx GetUserObjectInformationA EnumDisplayMonitors GetSystemMetrics SetThreadDesktop GetThreadDesktop CloseDesktop BlockInput GetMonitorInfoA OpenInputDesktop GetKeyState GetMessageA GetMessageExtraInfo DispatchMessageA SendMessageW DestroyWindow GetDC PostMessageA GetIconInfo CallNextHookEx GetCursorInfo SetWindowsHookExA MapVirtualKeyA GetForegroundWindow UnhookWindowsHookEx DefWindowProcA CreateWindowExA TranslateMessage UnregisterClassA DrawIconEx SetWinEventHook RegisterClassExA UnhookWinEvent SetForegroundWindow ReleaseDC SendInput SetProcessDPIAware MessageBoxW GetUserObjectInformationW GetProcessWindowStation GetWindowRect LoadCursorA CreateWindowExW |
| GDI32.dll |
SetTextColor
SetBkMode SetBkColor CreateSolidBrush BitBlt StretchBlt DeleteDC SetStretchBltMode GetObjectA CreateCompatibleBitmap SelectObject CreateCompatibleDC GetDIBits DeleteObject GetStockObject |
| ADVAPI32.dll |
CloseServiceHandle
AllocateAndInitializeSid CryptEnumProvidersW CryptSignHashW CryptDestroyHash CryptCreateHash CryptDecrypt CryptExportKey CryptGetUserKey CryptGetProvParam CryptSetHashParam CryptAcquireContextW ReportEventW RegisterEventSourceW DeregisterEventSource StartServiceCtrlDispatcherA RegCreateKeyW RegSetValueExA RegDeleteKeyA RegCloseKey RegOpenKeyExA OpenProcessToken InitiateSystemShutdownA LookupPrivilegeValueA AdjustTokenPrivileges CryptReleaseContext RegSetValueExW CryptDestroyKey InitializeSecurityDescriptor SetEntriesInAclA SetSecurityDescriptorDacl DuplicateTokenEx CreateProcessAsUserW SetTokenInformation OpenServiceA CheckTokenMembership FreeSid RegisterServiceCtrlHandlerExA OpenSCManagerA SetServiceStatus QueryServiceStatus |
| SHELL32.dll |
ShellExecuteExW
|
| ole32.dll |
CoUninitialize
CoInitializeEx CreateStreamOnHGlobal |
| Type |
AFX_DIALOG_LAYOUT
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x2 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 0 |
| MD5 | c4103f122d27677c9db144cae1394a66 🔍 |
| SHA1 | 1489f923c4dca729178b3e3233458550d8dddf29 🔍 |
| SHA256 | 96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 🔍 |
| SHA3 | 762ba6a3d9312bf3e6dc71e74f34208e889fc44e6ff400724deecfeda7d5b3ce 🔍 |
| Type |
AFX_DIALOG_LAYOUT
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x2 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 0 |
| MD5 | c4103f122d27677c9db144cae1394a66 🔍 |
| SHA1 | 1489f923c4dca729178b3e3233458550d8dddf29 🔍 |
| SHA256 | 96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7 🔍 |
| SHA3 | 762ba6a3d9312bf3e6dc71e74f34208e889fc44e6ff400724deecfeda7d5b3ce 🔍 |
| Type |
RT_BITMAP
|
|---|---|
| Language | UNKNOWN |
| Codepage | UNKNOWN |
| Size | 0x1d4e8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 6.02969 |
| MD5 | fbea7bd8f964843026170092c46166c5 🔍 |
| SHA1 | a7b4b4aff0fe2a2600ce351aabbf1f06a3ba6081 🔍 |
| SHA256 | 8186d5bfc6ffd913de46849fcd30af2450197f033b014081f0766a5af9d6fc00 🔍 |
| SHA3 | 90694d80f1feb093862b8e01f13b0fc09d22074db44936683ed7a322df28e3bf 🔍 |
| Preview |
|
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x25a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.00712 |
| MD5 | 5f0695c678bef5499bb5ec4f9db13776 🔍 |
| SHA1 | 5d1495cc292b8e100dbbed75f0a409f45f99ba3f 🔍 |
| SHA256 | 79910f03fd95b85e967ab66e19f32236e48de2bf575973836cc5e77522f3c80e 🔍 |
| SHA3 | e52fd9947ceb8f2606cf18d906940a3d035953d4165305ba77cac7729c8603dd 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x10a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.49455 |
| MD5 | a49ab999acb6dd89c03842de46e5d61f 🔍 |
| SHA1 | 1383a3c5af3366bd1882440c40fd56b514b15aee 🔍 |
| SHA256 | f4a66649f464900adb21c521cceeb12a1407ad9a98d6a43ca9b34e3a5951fd90 🔍 |
| SHA3 | e49e01760746de0f108799a9d2bdbf1b5f7d8552309089246b86f4cea005f4d6 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x468 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.33196 |
| MD5 | 4f1b463e8801a5bfcde7b809db0b27b8 🔍 |
| SHA1 | 8ab4fcefdd8c0ae5da28ffda5f84a900bf94982e 🔍 |
| SHA256 | 544ff916efbd39d8fc9df1012940eeb4bf9dd60130da3b722c6c6da85e37a196 🔍 |
| SHA3 | 3ad97dcf0e520169d9edf8d839852606e2bf029eedeb8872d02e7c51a8105d51 🔍 |
| Type |
RT_DIALOG
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x394 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.28483 |
| MD5 | 395d5a5c457b4367c39e281d87800bee 🔍 |
| SHA1 | 738a207649257df0d8c6dcfcd20805e402ae0236 🔍 |
| SHA256 | dcaf1ef1811a601fc745a78e16c2b4fa802b3f54d7e48492b9551262978ea87f 🔍 |
| SHA3 | e82bc24d40221ab9ead2f1f9b153e2291f3f5e5dfeb83076caf235b6ef0ee30e 🔍 |
| Type |
RT_DIALOG
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x3c6 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.20053 |
| MD5 | 935c43b4263fb617a80ce239c56bfed9 🔍 |
| SHA1 | 04fd7d62948f34e138b01748f0097b798b9c96d5 🔍 |
| SHA256 | 2e5a68cde00d70b8abc59754e3461baf30a8c6457cd7ed00be8c7a8bf2a1b684 🔍 |
| SHA3 | 4b32467aed17984b22f09c99339af115e6bb3e6b1a6e5e839d8243e1b5b301bd 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x30 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.45849 |
| Detected Filetype | Icon file |
| MD5 | 1ec6a7b3300970378c29695a6cc13d36 🔍 |
| SHA1 | 99ce74251d19d800608e30bed6e0d793931da56e 🔍 |
| SHA256 | 77a1efb6136f52dd2372987b13bf486aa75baeacb93bad009aa3e284c57b8694 🔍 |
| SHA3 | 7a94ba315b3ab461cec9dad3048599d32b0e597047f9655159bd6dfdc694e4a3 🔍 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x29c |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.4145 |
| MD5 | 76b3bf7499a69fb29d82577a886c3dc4 🔍 |
| SHA1 | 8fd1478c768ddbd86a68b337e7783bdc5ee7932b 🔍 |
| SHA256 | fc47c0ec938bd3d0fb7bfeacdb79be439dbc9dbab174df38989f25da330a0994 🔍 |
| SHA3 | 974a3cd33ca00a7a8bb52a7f4e0773f5b51d7ce11e3d042d672a7e237c3042e2 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x32a |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.13808 |
| MD5 | 49313f90a913af591a096a14f9b6076f 🔍 |
| SHA1 | e12e40e226f7be9600745b9c234af1b2f04297d2 🔍 |
| SHA256 | 953fed19953e6a62dc14313af29bc22a8ed10edca835f944b0fadd00e316802d 🔍 |
| SHA3 | 40438553c09909e0d51a024cf281d6d17fa8945c6e5a0ec9446bc6aea0addc6b 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.0.0.0 |
| ProductVersion | 0.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileDescription | MeshCentral Background Service Agent |
| FileVersion (#2) | 2026-Feb-15 16:43:44-0800 |
| LegalCopyright | Apache 2.0 License |
| ProductName | MeshCentral Agent |
| ProductVersion (#2) | Commit: 2026-Feb-15 16:43:44-0800 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-16 00:51:55 |
| Version | 0.0 |
| SizeofData | 111 |
| AddressOfRawData | 0x2e86ac |
| PointerToRawData | 0x2e70ac |
| Referenced File | C:\Users\Default.DESKTOP-9CGK2DI\Desktop\AmtWebApp\MeshAgent\Release\MeshService64.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-16 00:51:55 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x2e871c |
| PointerToRawData | 0x2e711c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-16 00:51:55 |
| Version | 0.0 |
| SizeofData | 776 |
| AddressOfRawData | 0x2e8730 |
| PointerToRawData | 0x2e7130 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Feb-16 00:51:55 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x94 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140304ed0 |
| XOR Key | 0xe077f6f |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 20 |
| 243 (40116) | 176 |
| 242 (40116) | 38 |
| 199 (41118) | 1 |
| ASM objects (VS2015 UPD3 build 24123) | 10 |
| C++ objects (VS2015 UPD3 build 24123) | 33 |
| C objects (VS2015 UPD3 build 24123) | 25 |
| C objects (VS2015 UPD3.1 build 24215) | 496 |
| 209 (65501) | 1 |
| 208 (65501) | 1 |
| Imports (65501) | 29 |
| Total imports | 399 |
| C objects (LTCG) (VS2015 UPD3.1 build 24215) | 53 |
| Resource objects (VS2015 UPD3 build 24210) | 1 |
| 151 | 1 |
| Linker (VS2015 UPD3.1 build 24215) | 1 |