mutenx.sys

IBIK, LLC

It runs as a Windows kernel mode device driver named “MUTENX_SERVICE”.
Publisher:
IBIK, LLC  (signed and verified)

Description:
kernel module

Version:
0, 0, 0, 10

MD5:
e08e047216cda1a4493aa79bdc9af3ba

SHA-1:
6a426cd6c3718f5338be60a65aae4d66bdd60db5

SHA-256:
25d72f3389f8d36acc80f7150dd66ee95b71cea7510381b71e32f9a242627ad8

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/14/2017 1:23:20 PM UTC  (today)

Scan engine
Detection
Engine version

ByteHero BDV
Trojan.Win32.Native.Heur.Gen
7.22.2016.10

File size:
57 KB (58,400 bytes)

Product version:
0, 1, 0, 0

File type:
Driver (Win32 SYS)

Language:
Language Neutral

Common path:
C:\Windows\System32\drivers\mutenx.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/22/2013 4:51:37 AM

Valid to:
11/23/2014 4:51:37 AM

Subject:
CN="IBIK, LLC", O="IBIK, LLC", L=Moscow, S=Moscow, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121EC63DE53EC2C8DE7D552E8CF8DA03676

File PE Metadata
Compilation timestamp:
1/17/2014 10:23:19 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
1536:+ZA8aJdKu2V7XDw60CKeSURGo78lJhk7p8Xlh:r8cT1BCKeSDSWX

Entry address:
0x1C27

Entry point:
8B, 0D, 38, 12, 01, 00, 33, C0, 39, 01, 56, 75, 4F, 8B, 74, 24, 08, 68, 88, B8, 01, 00, 50, 68, 00, 01, 00, 00, 6A, 22, 68, 0C, B0, 01, 00, 50, 56, 89, 35, 8C, B8, 01, 00, FF, 15, 3C, 12, 01, 00, 85, C0, 75, 27, A1, 88, B8, 01, 00, 83, 48, 1C, 04, C7, 46, 38, C9, 1B, 01, 00, C7, 46, 40, FA, 1B, 01, 00, C7, 46, 70, 78, 1B, 01, 00, E8, A8, 3C, 00, 00, 33, C0, EB, 05, B8, 01, 00, 00, C0, 5E, C2, 08, 00, 8B, 54, 24, 08, 33, C0, 85, D2, 74, 49, 8B, 4C, 24, 04, 56, 8D, 34, 11, 0F, B7, 11, 85, D2, 74, 39, 03, C2...
 
[+]

Entropy:
6.6544

Code size:
43 KB (44,032 bytes)

Driver
Display name:
MUTENX_SERVICE

Type:
Kernel device driver (KernelDriver)


Scan mutenx.sys - Powered by Reason Core Security