csim.sys

CrowdStrike Falcon Sensor

CrowdStrike, Inc.

It runs as a Windows kernel mode device driver named “IM”.
Publisher:
CrowdStrike, Inc.  (signed and verified)

Product:
CrowdStrike Falcon Sensor

Description:
CrowdStrike Falcon Sensor Support Module

Version:
2.0.0005.2503

MD5:
31e99cfa47393558ffa839111d6e6abc

SHA-1:
71edb5c44c207f301d4a581e01e20e9926a41fe6

SHA-256:
76911256b3a2de34b0461a742b1fa46440cae417089223b65fe331180ee6aec2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 9:57:02 PM UTC  (today)

File size:
7.5 KB (7,648 bytes)

Product version:
2.0.0005.2503

Copyright:
(c) CrowdStrike, Inc. All rights reserved.

Original file name:
csim.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\crowdstrike\csim.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/20/2012 10:00:00 AM

Valid to:
6/21/2015 9:59:59 AM

Subject:
CN="CrowdStrike, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="CrowdStrike, Inc.", L=Laguna Niguel, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3A7BEF620A0D4D7FD7ECD5CCB6846663

File PE Metadata
Compilation timestamp:
2/21/2015 12:14:03 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
192:L9fvCVrFd+vzmbjtlAur9ZCspE+TMDQrLm:JfvgyeUHeMDcm

Entry address:
0x49E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, E2, FE, FF, FF, CC, CC, 3C, 05, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 52, 05, 00, 00, A8, 02, 00, 00, 30, 05, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 60, 05, 00, 00, 9C, 02, 00, 00, 20, 05, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 6A, 05, 00, 00, 8C, 02, 00, 00, 14, 05, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 74, 05, 00, 00, 80, 02, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 20, 03, 00, 80, 21, 03, 00, 80, 00, 00...
 
[+]

Entropy:
6.7032

Code size:
768 Bytes (768 bytes)

Driver
Display name:
IM

Type:
Kernel device driver (KernelDriver)

Group:
System Reserved


Scan csim.sys - Powered by Reason Core Security