sysmsgr.exe

Office Cyber Alert

InfoWorks Technology Company

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘OfficeCyberAlert’.
Publisher:
InfoWorks Technology Company  (signed and verified)

Product:
Office Cyber Alert

Version:
5.00.0004

MD5:
9f2eca4203f1b8c10b9829ac4e4b9807

SHA-1:
ad3a3091bed788bccf9e5087048cdb874f15c481

SHA-256:
d2d03d4772cb7ade32fedce9394533d2b9f1ac9bcd0bc587325ad21fd259c82a

Scanner detections:
5 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/27/2024 1:08:56 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
UnclassifiedMalware
20257

Fortinet FortiGate
W32/VBThief.A
1/14/2016

McAfee
Keylog-FCA
5600.6521

Sophos
Mal/VBThief-A
4.98

Trend Micro House Call
Suspicious_GEN.F47V1125
7.2.14

File size:
1.6 MB (1,687,040 bytes)

Product version:
5.00.0004

Copyright:
InfoWorks Technology 2007-

Original file name:
sysmsgr.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\common files\winofficeca\sysmsgr.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/25/2013 5:30:00 AM

Valid to:
3/28/2015 5:29:59 AM

Subject:
CN=InfoWorks Technology Company, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=InfoWorks Technology Company, L=Cranberry Township, S=Pennsylvania, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1F9CCF430EAA6BB3D0E1842B0B89D041

File PE Metadata
Compilation timestamp:
5/15/2013 2:02:18 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:z+Rh+ONXGw8IE2LHkHEexoxEVlpaGsqR6ZRPI4FQnX+AMLv/bfBp13CMl+HqUymP:ij+ONXNYbsqsRBp13CMlOLju8kTs

Entry address:
0x8478

Entry point:
68, 84, 8D, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, 54, 3D, C0, 70, 4C, 06, 43, 4B, 9E, B0, 23, 7D, BF, 8F, 9D, BC, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 6F, 64, 75, 6C, 65, 5C, 4F, 66, 66, 69, 63, 65, 43, 79, 62, 65, 72, 41, 6C, 65, 72, 74, 00, 0A, 46, 6F, 72, 6D, 3D, 46, 00, 00, 00, 00, 01, 00, 2D, 00, A8, 25, 42, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, 6C, 2E, 42, 00, F4, 83, 59, 00, 00, 00, 00, 00, C8, 44, 35, 07...
 
[+]

Entropy:
6.4304

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
1.6 MB (1,667,072 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
OfficeCyberAlert

Command:
C:\Program Files\common files\winofficeca\sysmsgr.exe


Scan sysmsgr.exe - Powered by Reason Core Security