dd.exe

IP Labs GmbH

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Device Detection’.
Publisher:
IP Labs GmbH  (signed and verified)

Version:
1.14.1.0

MD5:
48818fc1a4be411e5d6d7f164487a840

SHA-1:
acf2fdf476afc9aa3475b42d8b17f0ebcad6d441

SHA-256:
fc1e9a156ce72ca76b17d5ba7ac32794440df738e9a50241def68ac41f5d7535

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:45:50 PM UTC  (today)

File size:
922.8 KB (944,928 bytes)

Product version:
1.0

Copyright:
Copyright (C) 2013 by IP Labs GmbH

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ebook\dd.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
12/21/2015 2:00:00 AM

Valid to:
6/17/2016 2:59:59 AM

Subject:
CN=IP Labs GmbH, OU=APPLICATION DEVELOPMENT, O=IP Labs GmbH, L=Bonn, S=Nordrhein-Westfalen, C=DE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
65ECE2C83A1BF44C1DBACCD6CAAE4A6E

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:wF6oB+AGvoypGAMOerZX5Mzlct8NUXdRbBn:w3Gzg51qNUNR1n

Entry address:
0xA7FAC

Entry point:
55, 8B, EC, 83, C4, F0, B8, D4, 65, 4A, 00, E8, BC, F1, F5, FF, E8, 9B, DB, FF, FF, E8, FE, C9, F5, FF, 8B, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 32, 13, 8B, C0, 00, 8D, 40, 00, 00, 8D, 40, 00...
 
[+]

Entropy:
6.8494

Developed / compiled with:
Microsoft Visual C++

Code size:
667 KB (683,008 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Device Detection

Command:
C:\Program Files\ebook\dd.exe


Scan dd.exe - Powered by Reason Core Security