dumpata.sys

ATAPI Dump Driver

Microsoft Corporation

Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft® Windows® Operating System

Description:
ATAPI Dump Driver

Version:
6.2.9200.16384 (win8_rtm.120725-1247)

MD5:
15afd3118600205b013550c8e81a0d92

SHA-1:
0d686d80c5935692f6ab71afd41a7d6d4a28eb0e

SHA-256:
9611fa36b84b8d396f90e50bae5ad0821182a2290ba85921328dc184c3573df3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/25/2024 9:08:27 AM UTC  (today)

File size:
33.2 KB (34,032 bytes)

Product version:
6.2.9200.16384

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
dumpata.sys

File type:
Driver (Win64 SYS)

Language:
Language Neutral

Digital Signature
Authority:
Microsoft Corporation

Valid from:
4/9/2012 10:55:50 PM

Valid to:
7/9/2013 10:55:50 PM

Subject:
CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
610BBBD8000000000005

File PE Metadata
Compilation timestamp:
7/26/2012 4:29:16 AM

OS version:
6.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
10.10

CTPH (ssdeep):
768:+TJUBimiNkvDHZY2qNbeFeOz7R9zTsmVNh/GBs1Ptj:KmdiNuC6F9zwmJqMPtj

Entry address:
0x449C

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8B, DA, 48, 8B, F9, E8, 57, 5B, 00, 00, 48, 8B, D3, 48, 8B, CF, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, E9, DA, F8, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 3B, 0D, 19, 1C, 00, 00, 75, 12, 48, C1, C1, 10, 66, F7, C1, FF, FF, 75, 03, C2, 00, 00, 48, C1, C9, 10, E9, 08, 00, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, B9, 02, 00, 00, 00, CD, 29, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00...
 
[+]

Entropy:
6.3334

Code size:
17 KB (17,408 bytes)