netfilter2.sys

NetFilter SDK

MSecure Data Labs

It runs as a Windows kernel mode device driver named “netfilter2”.
Publisher:
NetFilterSDK.com  (signed by MSecure Data Labs)

Product:
NetFilter SDK

Description:
NetFilter SDK TDI Hook Driver (WPP)

Version:
1.4.0.7 built by: WinDDK

MD5:
612acb3a3c0aa64d6ca4e70df9eedc42

SHA-1:
87f697d4320fe1519e9bea76414543bb811a7c57

SHA-256:
85cbd2b26a5753bd76e7d34ec978b67e775ae29a65e975903ee6f6cac78ae495

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 3:28:10 PM UTC  (today)

File size:
49 KB (50,176 bytes)

Product version:
1.4.0.7

Copyright:
Copyright © 2012 NetFilterSDK.com

Original file name:
netfilter2.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\netfilter2.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/27/2011 8:01:45 PM

Valid to:
12/27/2012 8:01:45 PM

Subject:
CN=MSecure Data Labs, O=MSecure Data Labs, L=Hyderabad, S=Andhra Pradesh, C=IN

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121FCFDA3F1BA4B5A7186C7E2E6A2D56EC3

File PE Metadata
Compilation timestamp:
7/12/2012 2:31:03 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
1536:HHO6DVN3QJR6VsmT9cJ52IE1cN+2AZAzRTy091X92iX:nOoVNAJR6VsY91cNdVTx91X9tX

Entry address:
0xA005

Entry point:
8B, FF, 55, 8B, EC, A1, 80, 8B, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1E, 8B, 15, 88, 8A, 01, 00, B8, 80, 8B, 01, 00, C1, E8, 08, 33, 02, A3, 80, 8B, 01, 00, 75, 07, 8B, C1, A3, 80, 8B, 01, 00, F7, D0, A3, 84, 8B, 01, 00, 5D, E9, 71, E7, FF, FF, CC, AC, A0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 28, A4, 00, 00, 14, 8A, 00, 00, 98, A0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 5E, A4, 00, 00, 00, 8A, 00, 00, A4, A0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 7A, A4, 00, 00, 0C, 8A, 00, 00, 00...
 
[+]

Entropy:
6.1537

Code size:
34.6 KB (35,456 bytes)

Driver
Display name:
netfilter2

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Scan netfilter2.sys - Powered by Reason Core Security