ofisvc.exe

NetSib OOO

It runs as a separate (within the context of its own process) windows Service named “ofiservice”.
Publisher:
NetSib OOO  (signed and verified)

MD5:
9810dcb52a7e51b1b398fd8f1a5eaf73

SHA-1:
bc7ee518832839923e86923af5fa078032d42d5c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 11:36:47 AM UTC  (today)

File size:
27.8 MB (29,133,536 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\ofisvc.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/23/2013 4:00:00 AM

Valid to:
8/23/2014 3:59:59 AM

Subject:
CN=NetSib OOO, OU=NETSIB OOO, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NetSib OOO, L=Novosibirsk, S=Novosibirskaya obl., C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
597CF451CBA583E83806A06A997A24B5

File PE Metadata
Compilation timestamp:
4/16/2014 10:39:28 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
393216:dT1Od1mhToYSwjfhDLYVeauazOKF+kEgCEwL4Kpr/cnIgPnzFETJDG+dpL12YtzO:dId86YFqYFXr/cn/FGDG+nL1Z

Entry address:
0x20D330

Entry point:
68, 3A, 14, 6F, FD, C7, 04, 24, 44, F3, 8E, 7E, 60, E8, B0, EA, FF, FF, 00, 00, 52, 61, 69, 73, 65, 45, 78, 63, 65, 70, 74, 69, 6F, 6E, 00, 8D, 64, 24, 04, 0F, 84, BB, 46, FF, FF, C0, E6, 03, 80, EE, 21, 8B, 70, 3C, 38, C4, 80, EA, 47, 01, C6, D2, D2, 0F, B6, D2, C0, C6, 03, 66, 0F, A3, EB, 8B, 56, 78, 66, 0F, A3, C6, 68, 5D, 2A, 3A, F1, 60, F5, 85, D2, 56, C7, 44, 24, 04, FE, 24, AC, 91, 51, E9, A6, 11, 00, 00, C6, 04, 24, 92, E9, 3B, FE, FF, FF, BF, C6, 9B, 60, 7A, 07, 29, 42, DD, 60, C9, 8C, 51, 8A, E7...
 
[+]

Code size:
1.5 MB (1,531,904 bytes)

Service
Display name:
ofiservice

Type:
Win32OwnProcess


Scan ofisvc.exe - Powered by Reason Core Security