bphfilterdrv.sys

NetFilter SDK

E-COMMERCE MEDIA GROUP INFORMACAO E TECNOLOGIA LTDA

It runs as a Windows 64-bit kernel mode device driver named “bphfilterdrv”.
Publisher:
NetFilterSDK.com  (signed by E-COMMERCE MEDIA GROUP INFORMACAO E TECNOLOGIA LTDA)

Product:
NetFilter SDK

Description:
NetFilter SDK WFP Driver (WPP)

Version:
1.4.1.6 built by: WinDDK

MD5:
ff73681260d8c78ad9a4f25bba280586

SHA-1:
d9ec00dfb635b23e1702dcf875b1053b9a1cb019

SHA-256:
e832294be3272954cfa8b1517a84e2834a22e146aae1e7466927b744b732cef2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 10:42:18 PM UTC  (today)

File size:
36.6 KB (37,480 bytes)

Product version:
1.4.1.6

Copyright:
Copyright © 2013 NetFilterSDK.com

Original file name:
netfilter2.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\bphfilterdrv.sys

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/15/2013 9:00:00 PM

Valid to:
8/15/2015 8:59:59 PM

Subject:
CN=E-COMMERCE MEDIA GROUP INFORMACAO E TECNOLOGIA LTDA, OU=Buscapé na Hora, O=E-COMMERCE MEDIA GROUP INFORMACAO E TECNOLOGIA LTDA, L=São Paulo, S=São Paulo, C=BR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
113F28B339D4835B842257F2AA9B2338

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
768:wrRoqjQIVJYVXZqvKGzUAfK5weJUTFpmZTkHx:wrRPj5UJsn4AfdeJ7mx

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 20, 80, FF, FF, CC, CC, 74, 91, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 74, 94, 00, 00, C0, 70, 00, 00, B4, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, CA, 94, 00, 00, 00, 70, 00, 00, EC, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 66, 98, 00, 00, 38, 70, 00, 00, C4, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 5E, 99, 00, 00, 10, 70, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A2, 94, 00, 00, B6, 94, 00, 00, 8E, 94...
 
[+]

Driver
Display name:
bphfilterdrv

Type:
Kernel device driver (KernelDriver)


Scan bphfilterdrv.sys - Powered by Reason Core Security