ipbusenum.exe

CounterTack, Inc.

It runs as a separate (within the context of its own process) windows Service named “PnP-X IP Bus Enumerator Service”.
Publisher:
CounterTack, Inc.  (signed and verified)

MD5:
34b10beabf9571e37452563efc34416a

SHA-1:
1c4c39797789098393e9faaac0ea6e9b6581186e

SHA-256:
ba9e5155db5d6898e25c5b427425b965c91abff50dcacb585b819359fd7c60b8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/5/2024 6:06:22 PM UTC  (today)

File size:
171.7 KB (175,792 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Windows\System32\ipbusenum.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/28/2014 10:00:00 AM

Valid to:
3/24/2017 9:59:59 AM

Subject:
CN="CounterTack, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="CounterTack, Inc.", L=Waltham, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3E1DC2FA6057A482E3B538AE0C5064D0

File PE Metadata
Compilation timestamp:
8/26/2016 8:38:38 AM

OS version:
6.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
11.0

Entry address:
0x5924

Entry point:
48, 83, EC, 28, E8, DF, 4F, 00, 00, 48, 83, C4, 28, E9, E2, FD, FF, FF, CC, CC, CC, CC, CC, CC, 48, 83, EC, 38, 4C, 89, 4C, 24, 20, 45, 33, C9, E8, 0B, 00, 00, 00, 48, 83, C4, 38, C3, CC, CC, CC, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 08, 48, 89, 68, 10, 48, 89, 70, 18, 57, 48, 83, EC, 50, 48, 83, 60, C8, 00, 48, 8B, DA, 33, D2, 49, 8B, F0, 48, 8B, F9, 44, 8D, 42, 28, 48, 8D, 48, D0, 49, 8B, E9, E8, 14, F0, FF, FF, 48, 85, F6, 75, 15, E8, 3E, 32, 00, 00, C7, 00, 16, 00, 00, 00, E8, CB, 20, 00, 00, 83, C8, FF...
 
[+]

Entropy:
6.1139

Code size:
107.5 KB (110,080 bytes)

Service
Display name:
PnP-X IP Bus Enumerator Service

Service name:
IPBusEnumsvc

Description:
The PnP-X bus enumerator service manages the virtual network bus. It discovers network connected devices using the SSDP/WS discovery protocols and gives them presence in PnP. If this service is stoppe

Type:
Win32OwnProcess

Group:
NetworkBase


Scan ipbusenum.exe - Powered by Reason Core Security