wben.exe

Webmail

Starfield Technologies, LLC

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘wben’.
Publisher:
Starfield Technologies, LLC  (signed and verified)

Product:
Webmail

Description:
Workspace Webmail Notifier

Version:
2.0.25.78

MD5:
7dd8b566edfdb8864d4b7bced62dc70b

SHA-1:
f43b26788119e11536493fda928525f678e79a71

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 12:37:35 AM UTC  (today)

File size:
1.5 MB (1,570,416 bytes)

Product version:
5.6.22

Copyright:
Copyright 2007-2013. All rights reserved.

Original file name:
wben.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\workspace\wben.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
10/15/2014 5:58:31 PM

Valid to:
10/15/2017 5:58:31 PM

Subject:
CN="Starfield Technologies, LLC", O="Starfield Technologies, LLC", L=Scottsdale, S=Arizona, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B8980545ADB1E

File PE Metadata
Compilation timestamp:
10/15/2014 6:23:32 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:fjqHHbnyPFKyp/JFS6dGyvWKxozb97DqVFp3+3++O:6yL/fPzvW+apGbpuu+O

Entry address:
0x1A6F3

Entry point:
E8, 7F, A2, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, E8, C6, 29, 00, 00, 8B, 4D, 08, 89, 48, 14, 5D, C3, E8, B9, 29, 00, 00, 8B, C8, 8B, 41, 14, 69, C0, FD, 43, 03, 00, 05, C3, 9E, 26, 00, 89, 41, 14, C1, E8, 10, 25, FF, 7F, 00, 00, C3, 8B, FF, 55, 8B, EC, 83, EC, 0C, 53, 56, 57, 8B, 7D, 0C, 85, FF, 74, 1D, 83, 7D, 10, 00, 74, 17, 8B, 75, 14, 85, F6, 75, 17, E8, E5, 07, 00, 00, C7, 00, 16, 00, 00, 00, E8, 88, 07, 00, 00, 33, C0, 5F, 5E, 5B, C9, C3, 8B, 4D, 08, 85, C9, 74, E2, 83, C8, FF, 33, D2, F7...
 
[+]

Entropy:
6.3848

Code size:
757 KB (775,168 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
wben

Command:
"C:\Program Files\workspace\wben.exe"


Scan wben.exe - Powered by Reason Core Security