amsmtp.exe

AnoMail SMTP Server

www.SOFCIK.xx.pl

The executable amsmtp.exe, “Free & Simple SMTP Server for Win32” has been detected as malware by 8 anti-virus scanners.
Publisher:
www.AnoMail.pl  (signed by www.SOFCIK.xx.pl)

Product:
AnoMail SMTP Server

Description:
Free & Simple SMTP Server for Win32

Version:
1.0.0.0

MD5:
3cb49bf4f0975ebfbf9852c9781e4c08

SHA-1:
f40fa7983d8f44c54383afccb79b3035a5d00ba3

SHA-256:
a772619d4b419d580a2aa8d5cf65f0d6a7780bed89cf9d228fbf1d28d2530224

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
11/26/2024 9:31:57 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.3630462
395

Bitdefender
Trojan.Generic.3630462
1.0.20.30

Bkav FE
HW32.CDB
1.3.0.4613

F-Secure
Trojan.Generic.3630462
11.2016-06-01_4

G Data
Trojan.Generic.3630462
16.1.22

MicroWorld eScan
Trojan.Generic.3630462
17.0.0.18

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
23.00.65.16104

VIPRE Antivirus
Backdoor.Win32.Hupigon
24418

File size:
526.2 KB (538,848 bytes)

Product version:
1.0.0.0

Copyright:
AnoMail 2007 Freeware

Original file name:
amsmtp.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\anomail\amsmtp.exe

Digital Signature
Authority:
www.SOFCIK.xx.pl

Valid from:
8/1/2004 12:00:00 AM

Valid to:
8/1/2010 12:00:00 AM

Subject:
OU=Freeware, O=www.SOFCIK.xx.pl, CN=Przemek Rusiecki, C=PL

Issuer:
OU=Freeware, O=www.SOFCIK.xx.pl, CN=Przemek Rusiecki, C=PL

Serial number:
2F4E7D6412E9D5B14F26B527DBE6E6EE

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:4a+b0uAJb2XAv0EivCrcCHuaB8ouJHRH0axSwNxr89:4fb0DbVvF7rjuKl00axNNw

Entry address:
0xF4EC5

Entry point:
68, F4, 70, F1, AA, E8, DE, FD, 05, 00, 68, 74, 30, A6, 8C, E8, 55, 07, 06, 00, BE, D1, 54, F5, 47, 68, F4, B0, F3, 7D, E8, B6, FB, 05, 00, A2, D9, F5, 97, DD, 7D, 39, E4, 0D, 90, 47, 32, CF, 8B, E6, 7C, 7F, 3A, 07, B9, 88, 5E, F8, 46, 4E, B2, FB, 94, 7C, 05, F8, 8F, D8, 65, E3, B1, B0, 22, B8, 3F, E6, 8E, D6, 47, 7F, FC, 2E, 38, DD, 59, 44, AF, 84, 02, 33, 6B, A0, D8, 24, CC, F1, 18, 5A, 88, 84, 6B, 01, 51, F3, 14, AB, 6D, 4E, 4D, D2, E8, AD, 95, EC, B0, 33, 79, CE, 42, 1B, 80, E4, D1, 75, 5A, 83, B0, 81...
 
[+]

Code size:
1.3 MB (1,398,784 bytes)

Remove amsmtp.exe - Powered by Reason Core Security