ABC_FTKBD.sys

ABC_KBD

Agricultural Bank of China

It runs as a Windows kernel mode device driver named “ABC_FTKBD”.
Publisher:
ABChina  (signed by Agricultural Bank of China)

Product:
ABC_KBD

Description:
ABC KeyBoard Safe Driver

Version:
1.0.15.0125

MD5:
b692d884b7cf5acf1a59453a5a728103

SHA-1:
fbd6fb7479cce9aeb12653e231161dc48c7ab669

SHA-256:
59d2dc3313f6c6512faa1e6ea4c2f6ac268c9dbd007ed73e6cfe32b1ea8b49fa

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 4:37:15 PM UTC  (today)

File size:
105.3 KB (107,776 bytes)

Product version:
1.0.15.0125

Copyright:
Copyright (C) 2015 ABChina

Original file name:
ABC_FTKBD.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\abc_ftkbd.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/4/2013 8:00:00 AM

Valid to:
5/4/2016 7:59:59 AM

Subject:
CN=Agricultural Bank of China, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Agricultural Bank of China, L=beijing, S=beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
395410384D767D7CDC6635C57A4EB5E0

File PE Metadata
Compilation timestamp:
1/25/2015 7:02:05 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
3072:47+2VKgaAcVsauXs7LPuTIisL9z3pIsF:CrVK9Acpb7LP/iK9z+s

Entry address:
0x32C8C

Entry point:
E8, 29, 70, FF, FF, 8D, 64, 24, 40, 0F, 87, 9E, C9, FE, FF, E8, 69, 0A, 00, 00, F5, 8B, 7A, 1C, E8, C3, DE, FE, FF, FF, 30, 8F, 44, 24, 44, 66, 89, 64, 24, 04, 9C, 68, 0A, 6C, 02, 7A, FF, 74, 24, 4C, C2, 50, 00, E9, A0, 5E, FF, FF, F4, CE, F4, 7E, F4, 8A, F5, 9E, F4, 62, F4, 56, F4, 8E, F4, 7A, F4, 66, F4, 9A, F4, 6E, F5, 9E, F5, 8A, F4, 4A, F5, 9E, F4, 92, F4, 62, F4, 4A, F4, 6E, F4, 8E, F5, 9E, F4, 66, F4, 62, F4, 4E, F5, 9E, F4, 96, F4, 8A, F5, 9E, F4, 6E, F4, 62, F4, 92, F4, 9A, F4, 4E, F4, 8A, F4, 8E...
 
[+]

Entropy:
7.8171  (probably packed)

Code size:
26 KB (26,624 bytes)

Driver
Display name:
ABC_FTKBD

Type:
Kernel device driver (KernelDriver)


Scan ABC_FTKBD.sys - Powered by Reason Core Security