Level3OutlookXpressMeet.exe

Level 3 XpressMeet Outlook Add-In

Level 3 Communications, Inc

It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in.
Publisher:
Level 3  (signed by Level 3 Communications, Inc)

Product:
Level 3 XpressMeet Outlook Add-In

Version:
2.0.75

MD5:
4f413674c5bafe2d58b4518a1ce75eb3

SHA-1:
328218386bd3ef6b3132c19b108656a77e9cc95d

SHA-256:
bea8d282c853c9e1fc640ff32c60c1f42a52cbc32255159c90b9d8c7126800a1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/12/2025 8:41:00 PM UTC  (today)

File size:
3.6 MB (3,774,080 bytes)

Product version:
2.0.75

Copyright:
Copyright (C) 2015 Level 3

Original file name:
Level3OutlookXpressMeet.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\level3outlookxpressmeet.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
7/22/2015 1:00:00 AM

Valid to:
8/20/2016 12:59:59 AM

Subject:
CN="Level 3 Communications, Inc", OU=collaboration product team, O="Level 3 Communications, Inc", L=Denver, S=Colorado, C=US

Issuer:
CN=thawte SHA256 Code Signing CA - G2, O="thawte, Inc.", C=US

Serial number:
53CE6D6238336CBBC71641E07DED49D4

File PE Metadata
Compilation timestamp:
11/19/2015 12:20:35 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:VTSwr46nW/XEiTAsBj7iYUOsB4lp6VO9NBruGnqK:5OsBLVaNBKGX

Entry address:
0x30933

Entry point:
E8, 38, 88, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, 8B, 54, 24, 04, 8B, 4C, 24, 08, F7, C2, 03, 00, 00, 00, 75, 3C, 8B, 02, 3A, 01, 75, 2E, 0A, C0, 74, 26, 3A, 61, 01, 75, 25, 0A, E4, 74, 1D, C1, E8, 10, 3A, 41, 02, 75, 19, 0A, C0, 74, 11, 3A, 61, 03, 75, 10, 83, C1, 04, 83, C2, 04, 0A, E4, 75, D2, 8B, FF, 33, C0, C3, 90, 1B, C0, D1, E0, 83, C0, 01, C3, F7, C2, 01, 00, 00, 00, 74, 18, 8A, 02, 83, C2, 01, 3A, 01, 75, E7, 83, C1, 01, 0A, C0, 74, DC, F7, C2, 02, 00, 00, 00, 74, A4, 66, 8B, 02, 83, C2, 02, 3A...
 
[+]

Entropy:
7.4653

Code size:
260 KB (266,240 bytes)

Scheduled Task
Task name:
C__Users_rdesai_Downloads_Level3OutlookXpressMeet.exe

Trigger:
Logon (Runs on logon)


Scan Level3OutlookXpressMeet.exe - Powered by Reason Core Security