ioffsvc.exe

Crystal Rich Ltd

It runs as a separate (within the context of its own process) windows Service named “Internet Off Service”.
Publisher:
Crystal Rich Ltd  (signed and verified)

MD5:
3f3704d968903d194e88862729ce1eac

SHA-1:
b251c0b91d2995883047951dc00236aff175d31a

SHA-256:
419a2ad91f4a768afecef4b89f079a42d7a095e3215bef325162616e84b33a7d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 11:22:12 AM UTC  (today)

File size:
1.5 MB (1,602,872 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\tools\internetoff\ioffsvc.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/16/2012 12:00:00 AM

Valid to:
1/15/2014 11:59:59 PM

Subject:
CN=Crystal Rich Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Crystal Rich Ltd, L=Saint Petersburg, S=Saint Petersburg, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1A3971F7D5A04EBA878183D0A57E1EC1

File PE Metadata
Compilation timestamp:
8/9/2013 6:59:19 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
12288:85Z+f9rjURXlo8KHrQQ1jMXa88Jf/y/wcrAEub6Sgo1ti+Pc8doJ8:85XXE+dUHWFAEub6S7W+fe8

Entry address:
0x149BC0

Entry point:
55, 53, 48, 83, EC, 28, 48, 8B, EC, 48, 8B, 05, 40, 0F, 02, 00, C6, 00, 01, 90, 48, 8D, 0D, 0D, 45, FF, FF, E8, 60, 84, EC, FF, E8, 2B, D0, FD, FF, 48, 89, C3, 48, 8B, 0D, C9, BF, FD, FF, B2, 01, 4C, 8D, 05, 84, 00, 00, 00, 49, C7, C1, 01, 00, 00, 80, E8, AC, F3, FD, FF, 48, 89, D9, 48, 89, C2, E8, 41, EB, FD, FF, 48, 8B, 0D, 9A, 0B, 02, 00, 48, 8D, 15, 87, 00, 00, 00, E8, BE, 2A, EC, FF, 48, 8D, 0D, 97, 00, 00, 00, 48, 8D, 15, C4, 00, 00, 00, 4C, 8D, 05, F5, 00, 00, 00, 4C, 8D, 0D, 56, 01, 00, 00, E8, 1D...
 
[+]

Entropy:
5.7181

Code size:
1.3 MB (1,347,072 bytes)

Service
Display name:
Internet Off Service

Service name:
InternetOffService

Description:
Auxiliary service for InternetOff application

Type:
Win32OwnProcess

Group:
Base


Scan ioffsvc.exe - Powered by Reason Core Security