apf005.sys

Beijing Apex Weifeng Technology Co.,Ltd.

It runs as a Windows kernel mode device driver named “apf005”.
Publisher:

MD5:
36ba6491108b000489dd5c188c2de26b

SHA-1:
6579e24b659d1c743f830a99a0004b8b683ee0f0

SHA-256:
df5ea84245693dc6478621c9aaa99d354de0e14a0d095fca980aa85ecfad09d0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/2/2024 9:05:27 AM UTC  (today)

File size:
15.1 KB (15,512 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\apf005.sys

Digital Signature
Authority:
WoSign CA Limited

Valid from:
11/1/2016 12:34:23 AM

Valid to:
12/31/2017 11:34:23 PM

Subject:
CN="Beijing Apex Weifeng Technology Co.,Ltd.", O="Beijing Apex Weifeng Technology Co.,Ltd.", STREET="NO.A-0116, 2F, NO.3 BLGD, NO.30 YARD, SHIXING STREET, SHIJINGSHAN DISTRICT", PostalCode=100041, L=Beijing, S=Beijing, C=CN, SERIALNUMBER=110105008981874, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.1=Beijing, OID.1.3.6.1.4.1.311.60.2.1.2=Beijing, OID.1.3.6.1.4.1.311.60.2.1.3=CN

Issuer:
CN=WoSign EV Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
255997E1750A395E8B8BF01021640E0B

File PE Metadata
Compilation timestamp:
10/16/2013 8:40:29 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
192:R+xQNm7mgK3EgRjQKQxThQiW0C0BzailXGJp/o6YEM2o6YEMs1KMWA:R+3jZg+KaT270C0BzailXGkzJ5zJOWA

Entry address:
0x4005

Entry point:
8B, FF, 55, 8B, EC, A1, 40, 30, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1E, 8B, 15, 24, 20, 01, 00, B8, 40, 30, 01, 00, C1, E8, 08, 33, 02, A3, 40, 30, 01, 00, 75, 07, 8B, C1, A3, 40, 30, 01, 00, F7, D0, A3, 44, 30, 01, 00, 5D, E9, 6D, D0, FF, FF, CC, 8C, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 58, 41, 00, 00, 08, 20, 00, 00, 84, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 74, 41, 00, 00, 00, 20, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 66...
 
[+]

Entropy:
6.8692

Code size:
1.5 KB (1,536 bytes)

Driver
Display name:
apf005

Type:
Kernel device driver (KernelDriver)


Scan apf005.sys - Powered by Reason Core Security