outlose.exe

Sivi Technology Limited

The application outlose.exe by Sivi Technology Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Protect Service(OutloseP)”. While running, it connects to the Internet address ip-172-26-136-17.ec2.internal on port 80 using the HTTP protocol.
Publisher:
Sivi Technology Limited  (signed and verified)

MD5:
45bf3efbde94b94e5df4f96a1d1c767c

SHA-1:
9440efce7b03dc43d0ab0c4659272fa209bc9001

SHA-256:
d49007d4ac819ff2106734f83b0122e6dfcb27a7d9494263557e15088c8628ee

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 10:11:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Elex (M)
16.7.14.9

File size:
419.9 KB (429,968 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\outlose\outlose.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/14/2016 12:57:45 PM

Valid to:
3/1/2017 3:56:03 PM

Subject:
CN=Sivi Technology Limited, O=Sivi Technology Limited, L=Hong Kong, S=Hong Kong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
08CE1D7B4F87FAE4994A1584

File PE Metadata
Compilation timestamp:
7/14/2016 1:21:29 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
6144:+lh2uJVPXzHiD6cAV7jrIugHd0J6u19Q3rwOz4r56y1RegL45I0ueaEozV:0h2BwvVX19Q3hzW56UE5IzYoB

Entry address:
0x2E6C4

Entry point:
DA, AD, 35, 00, 00, DB, B2, CC, CD, CD, CD, 17, 6E, C1, 76, 00, B9, 7F, C6, 56, BB, 3F, 00, 00, 00, 00, 6B, 6D, 6D, 6C, 69, B9, D7, 6F, 63, C0, F1, 62, 56, CD, 07, 00, 00, 00, 00, BF, 76, 16, 3E, 19, 56, 16, 3E, 61, 64, 65, BB, 1A, B9, DA, 93, 8E, 03, 74, 00, 01, F7, 62, CD, 47, CE, F5, 77, CE, CD, CD, CD, CD, BF, 77, C6, 56, 91, 00, 00, 00, 00, C0, F1, 62, 56, CD, 07, 00, 00, 00, 00, BF, 76, 16, 3E, 19, 56, 16, 3E, 61, 64, 65, BB, 1A, B9, DA, 93, 8E, 03, 74, 00, 01, F7, 62, BB, 57, C2, CD, 47, CE, F5, 77...
 
[+]

Entropy:
6.4212

Code size:
309.5 KB (316,928 bytes)

Service
Display name:
Protect Service(OutloseP)

Service name:
OutloseP

Description:
To ensure your Outlose software integrity. If this service is disabled or stopped, your Outlose software will not be kept integrity check. This service uninstalls itself when there is no Outlose softw

Type:
Win32OwnProcess

Depends on:
RpcSs


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ip-172-26-136-17.ec2.internal  (172.26.136.17:80)

Remove outlose.exe - Powered by Reason Core Security