imnpf.sys

IMPcap

NanJing BengLv Information Technology Ltd.

It runs as a Windows 64-bit kernel mode device driver named “WinPcap Packet Driver (IMNPF)”.
Publisher:
IMFirewall Software  (signed by NanJing BengLv Information Technology Ltd.)

Product:
IMPcap

Description:
imnpf.sys (NT5/6 x86) Kernel Driver

Version:
4.0.0.1040

MD5:
d9c09031b1da9bc726248905f856ebc0

SHA-1:
e411d933bd918f21e60f8e8d3c2c6241864382eb

SHA-256:
b50f3e7eada36a25512b9cb2dcf9a4fdfe809a81a9bbb7e8d388d694b55a329b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/13/2025 1:44:46 PM UTC  (today)

File size:
32 KB (32,752 bytes)

Product version:
4.0.0.1040

Copyright:
Copyright ?2005-2010 IMFirewall Software.

Original file name:
imnpf.sys

File type:
Driver (Win64 SYS)

Language:
Language Neutral

Common path:
C:\Windows\System32\drivers\imnpf.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/26/2010 2:00:00 AM

Valid to:
3/27/2011 1:59:59 AM

Subject:
CN=NanJing BengLv Information Technology Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NanJing BengLv Information Technology Ltd., L=NanJing, S=JiangSu, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1775230C86D60BB8314E8B7BC452290C

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
768:lDmOeytDIljhTTEUwzMXTFIMjjIVzDLWJDbCqi:lDdeyOVTlwzwIVzDaJCqi

Entry point:
A1, 28, 59, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 19, A1, C4, 50, 01, 00, 8B, 00, 35, 28, 59, 01, 00, A3, 28, 59, 01, 00, 75, 06, 89, 0D, 28, 59, 01, 00, E9, AD, BA, FF, FF, CC, CC, CC, 5C, 5B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 5A, 60, 00, 00, 54, 50, 00, 00, 08, 5B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, C8, 60, 00, 00, 00, 50, 00, 00, 20, 5B, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 62, 00, 00, 18, 50, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3635

Driver
Display name:
WinPcap Packet Driver (IMNPF)

Service name:
IMNPF

Type:
Kernel device driver (KernelDriver)


Scan imnpf.sys - Powered by Reason Core Security