mbae.exe

Malwarebytes Anti-Exploit

ZeroVulnerabilityLabs, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Malwarebytes Anti-Exploit’.
Publisher:
Malwarebytes Corporation  (signed by ZeroVulnerabilityLabs, Inc.)

Product:
Malwarebytes Anti-Exploit

Version:
1.7.2.1004

MD5:
7e40a342289d1bb172fa608c7e48d76d

SHA-1:
ec529e3070490f6e1a71ed5281b57affb00c6178

SHA-256:
9c7e4cbc815e63ea574f2e38c9d9f476cf6e80444ee2a41629a1e2b2a015c9b4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 2:48:04 AM UTC  (today)

File size:
2.5 MB (2,619,728 bytes)

Product version:
1.07.2.1004

Copyright:
© Malwarebytes Corporation. All rights reserved.

Original file name:
mbae.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\malwarebytes anti-exploit\mbae.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
6/5/2014 8:00:00 PM

Valid to:
6/22/2015 8:00:00 AM

Subject:
CN="ZeroVulnerabilityLabs, Inc.", O="ZeroVulnerabilityLabs, Inc.", L=San Jose, S=California, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0BDE0449DB7704A6F6620D0302BBEE4A

File PE Metadata
Compilation timestamp:
5/13/2015 11:00:16 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:U7LH+kWT81mDvvvvevvv8vvvvKvvvKvvvvtvvvmvvvvvhvvvvPvvvvv2vvvvPvvl:U7LHQTgC8xhBK4QEe

Entry address:
0x15733

Entry point:
E8, 72, 53, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, F8, 7F, 42, 00, 89, 0D, F4, 7F, 42, 00, 89, 15, F0, 7F, 42, 00, 89, 1D, EC, 7F, 42, 00, 89, 35, E8, 7F, 42, 00, 89, 3D, E4, 7F, 42, 00, 66, 8C, 15, 10, 80, 42, 00, 66, 8C, 0D, 04, 80, 42, 00, 66, 8C, 1D, E0, 7F, 42, 00, 66, 8C, 05, DC, 7F, 42, 00, 66, 8C, 25, D8, 7F, 42, 00, 66, 8C, 2D, D4, 7F, 42, 00, 9C, 8F, 05, 08, 80, 42, 00, 8B, 45, 00, A3, FC, 7F, 42, 00, 8B, 45, 04, A3, 00, 80, 42, 00, 8D, 45, 08, A3, 0C, 80, 42...
 
[+]

Entropy:
5.2608

Code size:
121 KB (123,904 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Malwarebytes Anti-Exploit

Command:
C:\Program Files\malwarebytes anti-exploit\mbae.exe


Scan mbae.exe - Powered by Reason Core Security