tlistenersvcx64.exe

NetSib OOO

It runs as a separate (within the context of its own process) windows Service named “TListener Service”.
Publisher:
NetSib OOO  (signed and verified)

MD5:
959b8889457ae4c67622176b14b401fb

SHA-1:
534da583efef689cc30705c231fe5a300383e7c9

SHA-256:
6f9effe068830173aad147a00c4d227f70e61743f1e6bcdb751a406ab8f37bd5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/5/2024 12:30:20 PM UTC  (today)

File size:
7 MB (7,309,000 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\lanagent network filter\tlistenersvcx64.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/10/2012 5:00:00 AM

Valid to:
7/15/2013 4:59:59 AM

Subject:
CN=NetSib OOO, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NetSib OOO, L=Novosibirsk, S=Novosibirskaya obl., C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
11865D4EF6E94822C8CF9CF53960D60D

File PE Metadata
Compilation timestamp:
2/21/2013 3:47:36 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
98304:n+AzIyN6G/ZzWJEJw6PuUG7O+/uxA6s7f1SG3g:+Ty8G/ZsE8ONm7f1C

Entry address:
0x72C579

Entry point:
0F, 89, 97, A5, FF, FF, 68, 0E, 28, FE, 45, E9, FF, 06, 00, 00, E9, F2, 46, FF, FF, 48, 8D, 05, 03, 77, FF, FF, E9, 13, 88, FF, FF, 5F, 1F, DA, 7C, 3D, 60, 46, E7, 84, 32, DD, DE, 3D, 6F, 42, A9, CD, 97, D5, 9F, 0D, 5F, BA, 12, FD, 06, 32, 8C, 15, AD, 12, 03, A5, ED, D4, 33, BA, A7, 1D, AD, 4C, A1, AB, EB, 24, 7E, 2A, 8A, 25, 7D, 1B, A0, 03, D7, 6A, 07, F5, F2, ED, 1F, FA, 5A, E0, AC, 6A, 31, 2D, 0E, FF, FF, FF, F2, 8D, 5C, D4, 60, 95, 02, 77, 94, B6, 61, 06, CA, D4, 86, D7, 61, D0, 60, E0, D1, 13, 42, 7C...
 
[+]

Entropy:
6.4159

Code size:
3.7 MB (3,900,416 bytes)

Service
Display name:
TListener Service

Service name:
TListenerSvc

Type:
Win32OwnProcess


Scan tlistenersvcx64.exe - Powered by Reason Core Security