ri1394up64.sys

RICOH Company Limited

Publisher:
RICOH Company Limited  (signed and verified)

MD5:
da36b613db40ecc9465ab638c7071f36

SHA-1:
aa746b2aa4919f3236a56f1a800c7a94f51a3d57

SHA-256:
c8a7393a821a5acb912563216b6d6a6049222971fb185827f11386ecb3125b72

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/6/2024 7:56:19 AM UTC  (today)

File size:
11.9 KB (12,152 bytes)

File type:
Driver (Win64 SYS)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ri1394up64.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/27/2009 7:00:00 AM

Valid to:
4/28/2010 6:59:59 AM

Subject:
CN=RICOH Company Limited, OU=Quality Management Division, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=RICOH Company Limited, L=1-3-6 Nakamagome Ohta-Ku, S=Tokyo, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
17CDC17E01E0D6A9D4C8EEB146F49089

File PE Metadata
Compilation timestamp:
12/9/2009 1:40:33 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
192:NYlVCeebx3zjoibwiJWF+Hj5ZSb+OGMjGwP7oZgjlkMcLJ+ebMThMj:SlVCeebxDjoibwiJWF2WCOyd6jU/b80

Entry address:
0x5064

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, 86, BF, FF, FF, CC, CC, E0, 50, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, EE, 51, 00, 00, 20, 20, 00, 00, C0, 50, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 3C, 52, 00, 00, 00, 20, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 14, 52, 00, 00, 00, 00, 00, 00, FC, 51, 00, 00, 00, 00, 00, 00, 2C, 52, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 8C, 51, 00, 00...
 
[+]

Entropy:
6.0550

Code size:
5 KB (5,120 bytes)

Scan ri1394up64.sys - Powered by Reason Core Security