nzfsd.sys

NZFS Driver

Brahim Bakayoko

It runs as a Windows 64-bit kernel mode device driver named “NZFS Ultra-X SCSI/SAS RAID Service”.
Publisher:
FlexRAID  (signed by Brahim Bakayoko)

Product:
NZFS Driver

Version:
1, 0, 0, 1

MD5:
a902ede923bd41acaa957d8a3bfcaaa5

SHA-1:
ae5068f999e8957fe6226ce317e2292f141d097b

SHA-256:
d83b5a96eaf6ff6e0f79db6746a36a828adf92f15900fe968c14ca889a000707

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 7:28:23 PM UTC  (today)

File size:
273.1 KB (279,624 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2013

Trademarks:
NZFS

Original file name:
NZFSD.exe

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\nzfsd.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
4/4/2013 11:34:17 AM

Valid to:
4/5/2014 11:34:17 AM

Subject:
CN=Brahim Bakayoko, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E18331E388A5FD1C27C6C36FA8E9908F

File PE Metadata
Compilation timestamp:
11/8/2013 1:48:10 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
6144:iBeR5hQpkF2cnMOKG10jZerKNCrrkdN1Mh1LRm/Hte7jf3Wq3Yt:iBeR5QkF2cnjK40jZe+sfkdN1MhbYt

Entry address:
0x25FE0

Entry point:
48, 89, 54, 24, 10, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, E8, 3A, 0B, 00, 00, 89, 44, 24, 20, 83, 7C, 24, 20, 00, 7D, 09, 8B, 44, 24, 20, E9, F5, 00, 00, 00, E8, 61, 98, FF, FF, 48, 89, 05, A2, 9B, 01, 00, 48, 83, 3D, 9A, 9B, 01, 00, 00, 75, 0A, B8, E5, 00, 00, C0, E9, D5, 00, 00, 00, 48, 8B, 05, 87, 9B, 01, 00, 48, 83, C0, 18, 48, 89, 44, 24, 68, 48, 8B, 84, 24, 98, 00, 00, 00, 0F, B7, 00, 33, D2, B9, 02, 00, 00, 00, 48, F7, F1, 4C, 8B, C0, 48, 8B, 94, 24, 98, 00, 00, 00, 48, 8B, 52, 08, 48, 8B...
 
[+]

Entropy:
6.2296

Code size:
193.5 KB (198,144 bytes)

Driver
Display name:
NZFS Ultra-X SCSI/SAS RAID Service

Service name:
NZFSD

Type:
Kernel device driver (KernelDriver)

Group:
Extended Base


Scan nzfsd.sys - Powered by Reason Core Security