SbieDrv.sys

Sandboxie

SANDBOXIE L.T.D

It runs as a Windows 64-bit kernel mode device driver named “SbieDrv”.
Publisher:
SANDBOXIE L.T.D  (signed and verified)

Product:
Sandboxie

Description:
Sandboxie Kernel Mode Driver

Version:
3.62

MD5:
6cd911b4df6f11a41c1935a4cf0d765f

SHA-1:
3e7644d3836c81a35af2c2c3024e690d62e996d7

SHA-256:
dfdf4b236a9c0bba32756e48968e1e1460007b488694ea3df8e2e76764544bdf

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 4:07:49 AM UTC  (today)

File size:
154.6 KB (158,336 bytes)

Product version:
3.62

Copyright:
Copyright © 2004-2011 by Ronen Tzur

Original file name:
SbieDrv.sys

File type:
Driver (Win64 SYS)

Common path:
C:\Program Files\sandboxie\sbiedrv.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
10/28/2010 1:34:15 PM

Valid to:
2/4/2013 6:10:10 PM

Subject:
CN=SANDBOXIE L.T.D, O=SANDBOXIE L.T.D, L=Holon, S=Israel, C=IL

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012BF299E10C

File PE Metadata
Compilation timestamp:
11/23/2011 3:02:45 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
3072:2jcDMDS7+6AiPlqs/NqFmXCATzk+Th5t+:8inAUlqKUmXxj+

Entry address:
0x24984

Entry point:
48, 53, 57, 48, 83, EC, 28, 48, 89, 0D, 3E, CA, FF, FF, 48, 8B, FA, 48, C7, 41, 68, 00, 00, 00, 00, 48, 8D, 0D, 1C, CA, FF, FF, 48, 8D, 15, F5, 18, 00, 00, FF, 15, A7, 86, FF, FF, E8, C6, F9, FF, FF, 84, C0, 8A, D8, 0F, 84, 10, 01, 00, 00, E8, D7, 83, FE, FF, 48, 85, C0, 48, 89, 05, 99, C4, FF, FF, 75, 11, 45, 33, C0, 33, D2, B9, 50, 04, 01, C1, E8, 4C, C6, FE, FF, 32, DB, 84, DB, 0F, 84, E6, 00, 00, 00, E8, 51, 04, FE, FF, 84, C0, 8A, D8, 0F, 84, D7, 00, 00, 00, 48, 8B, 57, 08, 48, 8B, 0D, 64, C4, FF, FF...
 
[+]

Code size:
125.5 KB (128,512 bytes)

Driver
Display name:
SbieDrv

Type:
Kernel device driver (KernelDriver)


Scan SbieDrv.sys - Powered by Reason Core Security