msahci.sys

Windows Main Build Lab Account

It runs as a Windows kernel mode device driver named “msahci”.
Publisher:
Windows Main Build Lab Account  (signed and verified)

MD5:
bfd5a3869ceb91d3908eba8496f264d3

SHA-1:
55c8ffa6bbc6ceaee5aa0dfece97f8853f5d1d4a

SHA-256:
89f56dd3c16a66bce3bc31da6e9b12291d0f0abd769f65dde944265dd7d7ad37

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
6/25/2025 10:17:30 PM UTC  (today)

File size:
24.2 KB (24,800 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\msahci.sys

Digital Signature
Authority:
MSIT Test CodeSign CA 2

Valid from:
3/13/2009 1:39:14 AM

Valid to:
3/13/2010 12:39:14 AM

Subject:
CN=Windows Main Build Lab Account

Issuer:
CN=MSIT Test CodeSign CA 2, DC=redmond, DC=corp, DC=microsoft, DC=com

Serial number:
29C9F976000100003536

File PE Metadata
Compilation timestamp:
4/8/2009 8:06:35 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:36oiitN5/N4mmqqSAOcOk9hbCdu4uT3gaWQA:36litjKwqxF9hbCduRT3ga6

Entry address:
0x703E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 4A, AE, FF, FF, CC, CC, 98, 70, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 34, 73, 00, 00, 0C, 50, 00, 00, 8C, 70, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 40, 73, 00, 00, 00, 50, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 16, 73, 00, 00, 24, 73, 00, 00, 00, 00, 00, 00, 42, 71, 00, 00, 5E, 71, 00, 00, 74, 71, 00, 00, 88, 71, 00, 00, A4, 71, 00, 00, BA, 71, 00, 00, D0, 71, 00, 00, E4, 71, 00, 00, 26, 71, 00, 00, 20, 72...
 
[+]

Entropy:
6.2525

Code size:
16.5 KB (16,896 bytes)

Driver
Display name:
msahci

Type:
Kernel device driver (KernelDriver)

Group:
SCSI Miniport


Scan msahci.sys - Powered by Reason Core Security