MailSwitch.OCX

MailSwitch ActiveX Control Module

Esaya.com Inc.

The file MailSwitch.OCX has been detected as malware by 9 anti-virus scanners.
Publisher:
Esaya  (signed by Esaya.com Inc.)

Product:
MailSwitch ActiveX Control Module

Version:
2, 1, 3, 8

MD5:
c590956e0e80ab92dc2583369af02b20

SHA-1:
d68a98299ca0cb992ddb1d3af2778ba4339c7629

SHA-256:
d79f004086ad5a92a1615e674c7093f016316bae949114c5828d823960c83731

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
5/8/2024 5:49:05 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.PWS.Agent
7.1.1

Avira AntiVirus
TR/PSW.Agent.ani
7.11.174.250

Clam AntiVirus
Trojan.Spy-42367
0.98/21411

F-Prot
W32/Pws.BFDN
v6.4.7.1.166

IKARUS anti.virus
Trojan-PWS.Win32.Agent
t3scan.1.7.8.0

Norman
Suspicious_Gen2.OLDPG
11.20141103

Qihoo 360 Security
Win32/Trojan.PSW.002
1.0.0.1015

Rising Antivirus
PE:Trojan.Win32.Generic.136B7E28!325811752
23.00.65.141101

Zillya! Antivirus
Trojan.Win32.31706C5D
2.0.0.1935

File size:
1.2 MB (1,297,760 bytes)

Product version:
2, 1, 3, 8

Copyright:
Copyright (C) 2002 by Esaya

Original file name:
MailSwitch.OCX

File type:
OLE control extension (Win32 OCX)

Language:
English (United States)

Common path:
C:\windows\mailswitch.ocx

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/17/2006 7:00:00 PM

Valid to:
5/17/2009 6:59:59 PM

Subject:
CN=Esaya.com Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Esaya.com Inc., L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
244A552C72B65C01E472D28722707D5A

File PE Metadata
Compilation timestamp:
5/16/2008 4:07:22 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:NUyrWJdD6OsB3M17IUXoHpzLzZ7xbKfItlrq25kCWWrIDX5fHbMfbECN:GJdD6OspMcfJLZ7EAtlrq2dWVX5fHbMb

Entry address:
0xAA587

Entry point:
83, 7C, 24, 08, 01, 75, 05, E8, D4, D0, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, ED, FE, FF, FF, 59, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF...
 
[+]

Entropy:
6.4885

Code size:
829 KB (848,896 bytes)

Remove MailSwitch.OCX - Powered by Reason Core Security