NETFILTER.SYS

Windows Win 7 DDK driver

China Telecom

It runs as a Windows 64-bit kernel mode device driver named “Driver for netfilter Device”.
Publisher:
Windows (R) Win 7 DDK provider  (signed by China Telecom)

Product:
Windows (R) Win 7 DDK driver

Description:
Sample NDIS 4.0 Intermediate Miniport Driver

Version:
6.1.7600.16385 built by: WinDDK

MD5:
208e97c869140178676eac35f6331227

SHA-1:
6430e0a822d2e9339308e9f9653c50af678f3a55

SHA-256:
0d1b2b4d44233f0504a41b39dabbcdbd5fa4ab96a9f508b3f4ad2f8d5504ff3c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
7/13/2025 1:57:53 PM UTC  (today)

File size:
31.2 KB (31,968 bytes)

Product version:
6.1.7600.16385

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
NETFILTER.SYS

File type:
Driver (Win64 SYS)

Common path:
C:\Windows\System32\drivers\netfilter.sys

Digital Signature
Signed by:

Authority:
China Telecom

Valid from:
9/26/2010 10:33:24 AM

Valid to:
9/25/2012 10:33:24 AM

Subject:
CN=China Telecommunications Corporation, OU=China Telecom Trust Network, O=China Telecom, C=CN

Issuer:
CN=China Telecom Root CA, OU=China Telecom Trust Network, O=China Telecom, C=CN

Serial number:
1E

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
768:Be1bbWtFgbtl4PS0vrRoCPFdyD5qfT1LFm0:sbbqo4R72qfT1g0

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, 26, FC, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 6E, 00, 65, 00, 74, 00, 66, 00, 69, 00, 6C, 00, 74, 00, 65, 00, 72, 00, 00, 00, C8, 95, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, E4, 96, 00, 00, 88, 61, 00, 00, 40, 94, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A2, 9B, 00, 00, 00, 60, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, C8, 98, 00, 00...
 
[+]

Entropy:
6.3235

Driver
Display name:
Driver for netfilter Device

Service name:
netfilter

Type:
Kernel device driver (KernelDriver)


Scan NETFILTER.SYS - Powered by Reason Core Security