maxprog email extractor 3.6.1.exe

New IT Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application maxprog email extractor 3.6.1.exe by New IT Limited has been detected as adware by 13 anti-malware scanners. The file has been seen being downloaded from 4su.getafilefast.net.
Publisher:
New IT Limited  (signed and verified)

Version:
3, 3, 55, 0

MD5:
4a25b036878e2f1b3e2924a74f1e8f56

SHA-1:
7fb9458be117670e33ba0621a27fc5f8ed9cd9a8

SHA-256:
0aa229ece4bebe734f1cf3da55a7f52970660ba3b3e69441c2924ee19c1ce3a3

Scanner detections:
13 / 68

Status:
Adware

Analysis date:
12/27/2024 7:28:21 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Downware
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.169.164

AVG
Generic
2015.0.3369

Dr.Web
Adware.Downware.2538
9.0.1.05190

ESET NOD32
Win32/4Shared.U potentially unwanted application
7.0.302.0

G Data
Win32.Application.4shared
14.8.24

IKARUS anti.virus
PUA.4Shared
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.183.13166

McAfee
PUP-FNX
5600.7025

NANO AntiVirus
Riskware.Win32.Downware.ddwsfi
0.28.2.61861

Panda Antivirus
Trj/Genetic.gen
14.08.28.04

Reason Heuristics
PUP.NewITLimited.BB
14.8.28.3

VIPRE Antivirus
Threat.4150696
32210

File size:
355.9 KB (364,392 bytes)

Product version:
3, 3, 55, 0

Copyright:
2014

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\maxprog email extractor 3.6.1.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
5/14/2014 1:00:04 PM

Valid to:
12/30/2016 8:33:53 AM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
049768F7F19C91

File PE Metadata
Compilation timestamp:
8/8/2014 4:05:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:QImvlo72lAgdH5V8ynsMoGlA1Y/wxABUXE5uBBu3eI:jklnGysMoGllIxyIY6Bu3

Entry address:
0x284C8

Entry point:
E8, A9, 91, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 14, A1, E8, 8B, 44, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 57, 8B, F1, 39, 1D, 5C, A2, 44, 00, 75, 38, 53, 53, 33, FF, 47, 57, 68, 58, E4, 43, 00, 68, 00, 01, 00, 00, 53, FF, 15, 6C, C1, 43, 00, 85, C0, 74, 08, 89, 3D, 5C, A2, 44, 00, EB, 15, FF, 15, C4, C0, 43, 00, 83, F8, 78, 75, 0A, C7, 05, 5C, A2, 44, 00, 02, 00, 00, 00, 39, 5D, 14, 7E, 22, 8B, 4D, 14, 8B, 45, 10, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, 45, 14, 2B, C1...
 
[+]

Entropy:
6.6216

Code size:
235 KB (240,640 bytes)

The file maxprog email extractor 3.6.1.exe has been seen being distributed by the following URL.

Remove maxprog email extractor 3.6.1.exe - Powered by Reason Core Security