mail.com_MailCheck_Broker.exe

mail.com MailCheck for Internet Explorer

1&1 Mail & Media Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘MailCheck IE Broker’.
Publisher:
1and1 Mail and Media Inc.  (signed by 1&1 Mail & Media Inc.)

Product:
mail.com MailCheck for Internet Explorer

Description:
mail.com MailCheck Service

Version:
1.9.0.1

MD5:
a11c5b27822205862077fed248d70f14

SHA-1:
695770f83636345df2fb06f5b43e98ed45aedd98

SHA-256:
6d77d35ee1183ee5a6a9696dea49fc7ca5c2404a2106f3a305aab52eda8cdc45

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 6:02:04 AM UTC  (today)

File size:
1.4 MB (1,422,472 bytes)

Product version:
1.9.0.1

Copyright:
© 1&1 Mail & Media Inc. All rights reserved.

Original file name:
mail.com_MailCheck_Broker.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mail.com mailcheck\ie\mail.com_mailcheck_broker.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/28/2011 5:00:00 PM

Valid to:
6/28/2014 4:59:59 PM

Subject:
CN=1&1 Mail & Media Inc., OU=MAIL.com, O=1&1 Mail & Media Inc., L=Chesterbrook, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4537291B5E95E3DDBC002BFCB5EFEE18

File PE Metadata
Compilation timestamp:
11/21/2012 1:16:42 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:VV+JmQoHo9lbPleE7Ueauj9nD8HW+vKiW5HuSvRVbeNynZUWF5:D+zJPleE7Uea0xP+KTfbkynZT

Entry address:
0xCEE77

Entry point:
E8, BA, 96, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 57, 85, F6, 74, 07, 8B, 7D, 0C, 85, FF, 75, 15, E8, 6E, 08, 00, 00, 6A, 16, 5E, 89, 30, E8, AD, 30, 00, 00, 8B, C6, 5F, 5E, 5D, C3, 8B, 45, 10, 85, C0, 75, 05, 66, 89, 06, EB, DF, 8B, D6, 2B, D0, 0F, B7, 08, 66, 89, 0C, 02, 83, C0, 02, 66, 85, C9, 74, 03, 4F, 75, EE, 33, C0, 85, FF, 75, D4, 66, 89, 06, E8, 2E, 08, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, BC, 8B, FF, 55, 8B, EC, 83, EC, 10, 83, 65, FC, 00, 56, 8B, 75, 08, 85, F6, 75...
 
[+]

Entropy:
6.5482

Code size:
1006.5 KB (1,030,656 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MailCheck IE Broker

Command:
"C:\Program Files\mail.com mailcheck\ie\mail.com_mailcheck_broker.exe"


Scan mail.com_MailCheck_Broker.exe - Powered by Reason Core Security