dd.exe

IP Labs GmbH

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Device Detection’.
Publisher:
IP Labs GmbH  (signed and verified)

Version:
1.14.1.0

MD5:
bf48a82f0bee1db09bc55de9c5ce9cf3

SHA-1:
e2347f9c819ac9459e6f94e09669a8eff23f7ecd

SHA-256:
f94d67213fca9ef776e76a28a00f5ded04b229126cf05518fbda86b8b43782e2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/29/2024 12:48:40 AM UTC  (today)

File size:
922.6 KB (944,712 bytes)

Product version:
1.0

Copyright:
Copyright (C) 2013 by IP Labs GmbH

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ebook\dd.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/18/2012 3:00:00 AM

Valid to:
6/18/2014 2:59:59 AM

Subject:
CN=IP Labs GmbH, OU=APPLICATION DEVELOPMENT, O=IP Labs GmbH, L=Bonn, S=Nordrhein-Westfalen, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
152763E58C65752FD336C94C3BABCF16

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA7FAC

Entry point:
55, 8B, EC, 83, C4, F0, B8, D4, 65, 4A, 00, E8, BC, F1, F5, FF, E8, 9B, DB, FF, FF, E8, FE, C9, F5, FF, 8B, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 32, 13, 8B, C0, 00, 8D, 40, 00, 00, 8D, 40, 00...
 
[+]

Entropy:
6.8490

Developed / compiled with:
Microsoft Visual C++

Code size:
667 KB (683,008 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Device Detection

Command:
C:\Program Files\ebook\dd.exe


Scan dd.exe - Powered by Reason Core Security