gbmgr64.exe

Guardbox

IncrediMail, Inc.

The executable gbmgr64.exe has been detected as malware by 1 anti-virus scanner.
Publisher:
IncrediMail, Inc.  (signed and verified)

Product:
Guardbox

Version:
1.5.2.1

MD5:
dcd1e514d6932037181ff8b6993c32ec

SHA-1:
a211599d7cab2300534106050eaaae520bd9e8f2

SHA-256:
f5b90c46ba87071006a04be59862dab216aa1a79a63e3916e55af32b85bb01ba

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/24/2024 5:21:26 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.5.21.17

File size:
114 KB (116,688 bytes)

Product version:
1.5.2.1

Copyright:
© 2014 IncrediMail, Inc.

Original file name:
Guardbox

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\guardbox\1.5.2.1\app\api\native\gbmgr64.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
3/3/2015 6:00:00 PM

Valid to:
3/4/2017 5:59:59 PM

Subject:
CN="IncrediMail, Inc.", OU=GuardBox, O="IncrediMail, Inc.", L=Redmond, S=Washington, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0A94D8A33B5A91604406868292AF29E7

File PE Metadata
Compilation timestamp:
4/16/2015 3:25:10 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:HOjTLUYpzqpA+/mZWE5nA+5GesUok/Au3:H4TZpzsPCZ5nAheV/l

Entry address:
0x2EAC

Entry point:
48, 83, EC, 28, E8, B7, 26, 00, 00, 48, 83, C4, 28, E9, 36, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 8B, C1, 48, F7, D9, 48, A9, 07, 00, 00, 00, 74, 0F, 66, 90, 8A, 10, 48, FF, C0, 84, D2, 74, 5F, A8, 07, 75, F3, 49, B8, FF, FE, FE, FE, FE, FE, FE, 7E, 49, BB, 00, 01, 01, 01, 01, 01, 01, 81, 48, 8B, 10, 4D, 8B, C8, 48, 83, C0, 08, 4C, 03, CA, 48, F7, D2, 49, 33, D1, 49, 23, D3, 74, E8, 48, 8B, 50, F8, 84, D2, 74, 51, 84, F6, 74, 47, 48, C1, EA, 10, 84, D2, 74...
 
[+]

Entropy:
5.9277

Code size:
56.5 KB (57,856 bytes)

Remove gbmgr64.exe - Powered by Reason Core Security