GMX_MailCheck_Broker.exe

GMX MailCheck für Internet Explorer

1&1 Mail & Media GmbH

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘MailCheck IE Broker’.
Publisher:
1und1 Mail und Media GmbH  (signed by 1&1 Mail & Media GmbH)

Product:
GMX MailCheck für Internet Explorer

Description:
GMX MailCheck Dienst

Version:
2.4.1.0

MD5:
4c18fbd8dcd318b4f7c38bbcdb86f2b9

SHA-1:
352c2dd061942c88b4861c20f10fced052e02c06

SHA-256:
527f82b7f5f99f582288f746f316b30b27e8175226bcc4cf923d698182419373

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/8/2024 6:22:56 PM UTC  (today)

File size:
1.7 MB (1,731,136 bytes)

Product version:
2.4.1.0

Copyright:
© 1&1 Mail & Media GmbH. Alle Rechte vorbehalten.

Original file name:
GMX_MailCheck_Broker.exe

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\Program Files\gmx mailcheck\ie\gmx_mailcheck_broker.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
10/16/2013 2:00:00 AM

Valid to:
10/25/2016 1:59:59 AM

Subject:
CN=1&1 Mail & Media GmbH, OU=GMX, O=1&1 Mail & Media GmbH, L=Montabaur, S=Rheinland-Pfalz, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3557B83C19D293F1DDCD068D6B5AE1A5

File PE Metadata
Compilation timestamp:
12/10/2013 10:00:26 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:Ic5Dm2elfTQIIhn6uYqJ7ZpNkqG3X1a7tA7Dl127rzI/ynsP4XVu3wKq5Ipt:J5DmbfTTIp6U91kq4XBDoI6swXVuys

Entry address:
0xEC934

Entry point:
E8, AC, 93, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, D0, 66, 8B, 08, 83, C0, 02, 66, 85, C9, 75, F5, 66, 8B, 4D, 0C, 83, E8, 02, 3B, C2, 74, 05, 66, 39, 08, 75, F4, 66, 39, 08, 74, 02, 33, C0, 5D, C3, 8B, FF, 55, 8B, EC, 83, 7D, 10, 00, 75, 04, 33, C0, 5D, C3, 8B, 55, 0C, 8B, 4D, 08, FF, 4D, 10, 74, 15, 0F, B7, 01, 66, 85, C0, 74, 0D, 66, 3B, 02, 75, 08, 83, C1, 02, 83, C2, 02, EB, E6, 0F, B7, 01, 0F, B7, 0A, 2B, C1, 5D, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 57, 85, F6, 74, 07, 8B...
 
[+]

Code size:
1.2 MB (1,247,232 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MailCheck IE Broker

Command:
"C:\Program Files\gmx mailcheck\ie\gmx_mailcheck_broker.exe"


Scan GMX_MailCheck_Broker.exe - Powered by Reason Core Security