zooface.exe

Sivi Technology Limited

The application zooface.exe by Sivi Technology Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Protect Service(ZoofaceP)”.
Publisher:
Sivi Technology Limited  (signed and verified)

MD5:
6ea7c87c73a880794aadcbeb7d4f1e54

SHA-1:
3f09c15a7a285ed9ba47419c46985d6fa1751efa

SHA-256:
a294d1248fb6d536af3a7f9c73edbbad421c07fed031e2f51b104020517ba599

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 10:16:05 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex (M)
16.8.4.7

File size:
493.3 KB (505,175 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\zooface\zooface.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/4/2016 7:53:15 AM

Valid to:
3/1/2017 1:56:03 PM

Subject:
CN=Sivi Technology Limited, O=Sivi Technology Limited, L=Hong Kong, S=Hong Kong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
0C64B008825954802956B674

File PE Metadata
Compilation timestamp:
7/4/2016 1:46:20 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
12288:phtHQxITgQYKsKGUmxJ0uHxV23GBjvrEH7pB:qWHKxJRxVIQrEH7pB

Entry address:
0x2DD71

Entry point:
E9, 66, D9, FF, FF, D4, BD, C3, C2, C2, C2, 18, 79, DE, 79, 00, B6, 70, C9, 59, B4, 30, 00, 00, 00, 00, 64, 62, 62, 63, 66, B6, D8, 60, 6C, CF, FE, 6D, 59, C2, 08, 00, 00, 00, 00, B0, 79, 19, 31, 16, 59, 19, 31, 6E, 6B, 6A, B4, 15, B6, D5, 9C, 81, 1C, 7B, 00, 0E, F8, 6D, C2, 48, C1, FA, 78, C1, C2, C2, C2, C2, B0, 78, C9, 59, 9E, 00, 00, 00, 00, CF, FE, 6D, 59, C2, 08, 00, 00, 00, 00, B0, 79, 19, 31, 16, 59, 19, 31, 6E, 6B, 6A, B4, 15, B6, D5, 9C, 81, 1C, 7B, 00, 0E, F8, 6D, B4, 58, CD, C2, 48, C1, FA, 78...
 
[+]

Entropy:
6.7929

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
307 KB (314,368 bytes)

Service
Display name:
Protect Service(ZoofaceP)

Service name:
ZoofaceP

Description:
To ensure your Zooface software integrity. If this service is disabled or stopped, your Zooface software will not be kept integrity check. This service uninstalls itself when there is no Zooface softw

Type:
Win32OwnProcess

Depends on:
RpcSs


Remove zooface.exe - Powered by Reason Core Security