njbank.sys

Chongqing Shahai Information Tech Co.,Ltd

It runs as a Windows kernel mode device driver named “njbank”.
Publisher:
沙海  (signed by Chongqing Shahai Information Tech Co.,Ltd)

Product:
沙海

Description:
SecurityPassDrv

Version:
3, 0, 0, 0

MD5:
54ace83f97154b245a5f713151820a15

SHA-1:
ef3effe497254e5d7071756d089f35e32bff3e73

SHA-256:
7e209fceaeb08c6415b369360b4de427b10e905362e7c063091f0cefc3a24636

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 1:20:10 PM UTC  (today)

File size:
79.8 KB (81,728 bytes)

Product version:
3, 0, 0, 0

Copyright:
沙海

Original file name:
SecurityPassDrv.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\njbank.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/27/2011 8:00:00 AM

Valid to:
5/11/2012 7:59:59 AM

Subject:
CN="Chongqing Shahai Information Tech Co.,Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Chongqing Shahai Information Tech Co.,Ltd", L=Chongqing, S=Chongqing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6144B2B7D044E8CE85A337E29A775AA9

File PE Metadata
Compilation timestamp:
7/31/2011 4:07:57 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
1536:AHlZeolfKfmn03daAMqqU+2bbbAV2/S2j2S+fyR+:YSeKfi03djMqqDL2/yS+fy

Entry address:
0x53005

Entry point:
8B, FF, 55, 8B, EC, A1, 08, 12, 02, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1E, 8B, 15, 90, B0, 01, 00, B8, 08, 12, 02, 00, C1, E8, 08, 33, 02, A3, 08, 12, 02, 00, 75, 07, 8B, C1, A3, 08, 12, 02, 00, F7, D0, A3, 0C, 12, 02, 00, 5D, E9, 4D, F3, FA, FF, CC, 70, 30, 05, 00, 00, 00, 00, 00, 00, 00, 00, 00, 6A, 34, 05, 00, 00, B0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 56, 31, 05, 00, 6C, 31, 05, 00, 84, 31, 05, 00, 96, 31, 05, 00, B4, 31, 05, 00, C6...
 
[+]

Entropy:
6.6882

Code size:
41 KB (41,984 bytes)

Driver
Display name:
njbank

Type:
Kernel device driver (KernelDriver)


Scan njbank.sys - Powered by Reason Core Security