Gridinsoft Logo

The AteraAgent.exe (Atera.Agent.Windows) File Analysis

Technical Analysis

File Name AteraAgent.exe
File Type
PE32+ executable (console) x86-64, for MS Windows
Scanner Version 1.0.228.174
Database Version 2025-11-01 14:00:28 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
21,980,368
File Size (bytes)
2025-11-01
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
77799ed7a2ec052e6fa4a550165453a9
SHA1
dd15e59a662fb09f3e858630ec43a19b7f3deb61
SHA256
f7c3a25fd903b99b1b0e1e52509bff02e66311cc335875a2ace895e457a92e46
SHA512
49c0a40698bf7038fb6f87c2982213bdf094c78ef7347d85c9397dcc5ba2a86932de1e28dbe9f074f8636a6cbbe63af0680ffcdae382617eae31da1f1fffe77b
ImpHash
70d2e884fa127843c5bcbb53da86b6c8

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x1405c27b0
Compilation Time 2025-08-19 22:11:35
Checksum 0x01500108 (Actual: 0x01500108)
OS Version 6.0
PEiD Signatures PE32+ executable (console) x86-64, for MS Windows
PDB Path D:\a\_work\1\s\artifacts\obj\coreclr\windows.x64.Release\Corehost.Static\singlefilehost.pdb
Digital Signature OK
Imports 17 libraries
Exports 5 functions
Resources 5 Resources
Sections 10 Sections

Version Information

Translation 0x0000 0x04b0
CompanyName Atera.Agent.Windows
FileDescription Atera.Agent.Windows
FileVersion 2.4.7.0
InternalName Atera.Agent.Windows.dll
LegalCopyright
OriginalFilename Atera.Agent.Windows.dll
ProductName Atera.Agent.Windows
ProductVersion 2.4.7+d206c69a15b24f3d6c543273f20b64debcc196ef
Assembly Version 2.4.7.0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 6,345,436 bytes 6,345,728 bytes 6.45 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ C1BB8C0A5AD9D9FAEC90519904E56EC3
.CLR_UEF 0x0060f000 221 bytes 512 bytes 3.10 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ FCF41F3D886AC9E8307A56DFE6E6751B
.rdata 0x00610000 1,567,332 bytes 1,567,744 bytes 5.67 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 0D752D3B728D4C93E3BC013108CD73A6
.data 0x0078f000 130,900 bytes 38,912 bytes 3.33 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E24DE0F013EE82A5C451E08420AA48A6
.pdata 0x007af000 221,376 bytes 221,696 bytes 6.48 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 66C33A6B3BB03D39301937192217DE49
.didat 0x007e6000 56 bytes 512 bytes 0.43 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 68722C189FD21A72FCD6606C7BD31139
Section 0x007e7000 8 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
_RDATA 0x007e8000 78,344 bytes 78,848 bytes 5.48 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 617430A8CD708DDA1865FEE2910D8A1A
.rsrc 0x007fc000 1,348,844 bytes 1,349,120 bytes 6.36 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ CEA3398A1491B90B6DE0C1610FC1B317
.reloc 0x00946000 32,316 bytes 32,768 bytes 5.45 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ D191285E77877A5B7AA026D7F26C78D4

Resource Analysis

Total Resources: 5 (1,348,362 bytes)
Resource Type Count Total Size Percentage
RT_RCDATA 3 1,346,984 bytes
99.9%
RT_VERSION 1 888 bytes
0.1%
RT_MANIFEST 1 490 bytes
0%

Certificate Chain Analysis

Certificate Information
Product Atera.Agent.Windows
Description Atera.Agent.Windows
File Version 2.4.7.0
Original Name Atera.Agent.Windows.dll
Signing Date 11:55 AM 09/30/2025 (101 days ago)
Verification Status Signed
Signers Atera Networks Ltd; DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1; DigiCert Trusted Root G4; DigiCert
Counter Signers DigiCert SHA256 RSA4096 Timestamp Responder 2025 1; DigiCert Trusted G4 TimeStamping RSA4096 SHA256 2025 CA1; DigiCert Trusted Root G4; DigiCert
Internal Name Atera.Agent.Windows.dll
Certificate Chain Summary
Microsoft Windows Code Signing PCA 2024 #1 Primary
Validity Period: 2024-08-08 21:36:23 → 2035-06-23 22:04:01
Signature Algorithm: sha384RSA
Serial Number: 33 00 00 00 1C 48 9F 81 DF A1 B0 B7 77 00 00 00 00 00 1C
.NET DAC #2 Chain
Validity Period: 2025-05-08 18:23:59 → 2026-05-06 18:23:59
Signature Algorithm: sha384RSA
Serial Number: 33 00 00 00 5D 70 ED 48 40 45 BA 82 3F 00 00 00 00 00 5D
Microsoft Time-Stamp Service #3 Chain
Validity Period: 2025-01-30 19:42:58 → 2026-04-22 19:42:58
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 02 0B 11 9D 56 29 92 F9 BF 85 00 01 00 00 02 0B
Microsoft Time-Stamp PCA 2010 #4 Chain
Validity Period: 2021-09-30 18:22:25 → 2030-09-30 18:32:25
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15
DigiCert Trusted Root G4 #5 Chain
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 #6 Chain
Validity Period: 2021-04-29 00:00:00 → 2036-04-28 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 08 AD 40 B2 60 D2 9C 4C 9F 5E CD A9 BD 93 AE D9
DigiCert Trusted G4 TimeStamping RSA4096 SHA256 2025 CA1 #7 Chain
Validity Period: 2025-05-07 00:00:00 → 2038-01-14 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0D C7 AC 57 05 FF 21 99 2E 40 43 22 0C 3A 49 86
DigiCert SHA256 RSA4096 Timestamp Responder 2025 1 #8 Chain
Validity Period: 2025-06-04 00:00:00 → 2036-09-03 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0A 80 EF 18 4B 8D F1 05 82 D1 C4 76 A7 95 74 68
Atera Networks Ltd #9 Chain
Validity Period: 2025-08-13 00:00:00 → 2028-08-15 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0E 54 39 CC 89 87 1E E6 D4 82 24 06 E2 BC 9D 57

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware