extractattachmentmsg.exe

Extract Attachments From MSG Files Software

Sobolsoft

The application extractattachmentmsg.exe, “Extract Attachments From MSG Files Software Setup ” by Sobolsoft has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.tucows.com.
Publisher:
Sobolsoft   (signed by Sobolsoft)

Product:
Extract Attachments From MSG Files Software

Description:
Extract Attachments From MSG Files Software Setup

MD5:
1f1a708d5c7428f3a01c816ef11de2b5

SHA-1:
d9124b998c1fa642af31e220d6d6f2c7c54126e3

SHA-256:
cbe3b377fe0772e5bec7f62af996b3049e9fcefe5de39446998d88dcf73f669b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/20/2024 2:44:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.IM (L)
17.2.18.19

File size:
5.6 MB (5,849,800 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
9/21/2013 5:19:02 PM

Valid to:
9/17/2014 7:11:20 PM

Subject:
CN=Sobolsoft, O=Sobolsoft, L=Haverhill, S=Massachusetts, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B550D8AFF459D

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file extractattachmentmsg.exe has been seen being distributed by the following URL.

http://www.tucows.com/download/windows/.../extractattachmentmsg.exe

Remove extractattachmentmsg.exe - Powered by Reason Core Security