teamviewer_host_setup-idc6xgegpp.exe

TeamViewer Host Installer

TeamViewer

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is installed with TeamViewer 10 Host. The file has been seen being downloaded from message.fortismail.us and multiple other hosts.
Publisher:
TeamViewer  (signed and verified)

Product:
TeamViewer Host Installer

Description:
TeamViewer Remote Control Application Installer

Version:
10.0.45862.0

MD5:
f93e7ba2896cf78e6435a1979cc88cd9

SHA-1:
f2ff064f47da6a9a688a0f5e597f259b03f38300

SHA-256:
6685ea2a7e841d93509951136ff760ac8ee8c98b2eb608837f6fce24c8966d48

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 8:01:40 AM UTC  (today)

File size:
7.8 MB (8,219,328 bytes)

Product version:
10.0.45862.0

Copyright:
TeamViewer

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\teamviewer_host_setup-idc6xgegpp.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/29/2014 8:00:00 PM

Valid to:
9/5/2017 7:59:59 PM

Subject:
CN=TeamViewer, O=TeamViewer, L=Goeppingen, S=Baden Wuerttemberg, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
56729300C78306C4267CA44A10ADCD03

File PE Metadata
Compilation timestamp:
2/24/2012 2:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:CI7IDO7Q/Lbp8L09B7708AyO+fuC0cfxS2TsxBmW0wwKyCPa:CEEZ/Lbqsp7XO+GCVsmywYPa

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Entropy:
7.9982

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file teamviewer_host_setup-idc6xgegpp.exe has been discovered within the following programs.

TeamViewer 10 Host  by TeamViewer GmbH
3% remove it
 
Powered by Should I Remove It?

The file teamviewer_host_setup-idc6xgegpp.exe has been seen being distributed by the following 20 URLs.

https://message.fortismail.us/public/downloadfile.aspx?f=lTpSgOeMJQMhlPeAnKVNkzaS/6bXqnpm/.../n44Td51URJzkaFDlSMSutT3bu9nJK9w=

https://downloadus1.teamviewer.com/download/.../TeamViewer_Host_Setup-idc5hxbzry.exe

https://download.teamviewer.com/download/.../TeamViewer_Host_Setup-idcw45mb8t.exe

http://downloadeu1.teamviewer.com/.../TeamViewer_Host_Setup.exe