secburn.sys

Protect Software GmbH

It runs as a Windows 64-bit kernel mode device driver named “secburn”.
Publisher:
Protect Software GmbH  (signed and verified)

Description:
SecureBurnDriver

Version:
1.0.1.99

MD5:
7fa864b0fb693ad996b42478f69b41d0

SHA-1:
a36133ce64f7fdd12fb51bb58a1b55ced28fd0f2

SHA-256:
3b56c72cadaf3e1b5c15bad80229d8fd0d139d7fffa4513d74382b52fcf397cc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/25/2018 4:17:40 PM UTC  (today)

File size:
100.8 KB (103,184 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (C) 2006-2009

Original file name:
secburn.sys

File type:
Driver (Win64 SYS)

Language:
German (Germany)

Common path:
C:\Windows\System32\drivers\secburn.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/18/2011 4:00:33 PM

Valid to:
11/13/2013 2:33:30 PM

Subject:
E=cert@protect-software.com, CN=Protect Software GmbH, O=Protect Software GmbH, L=Dortmund, S=NRW, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D4C609DCCB89F9E370E24902B676D4B8

File PE Metadata
Compilation timestamp:
7/6/2012 2:05:53 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:wsNBzjk7S5GVNtR59YLY6mEGluBaho9S4AJKqBz8MZJFBUnPSEIILv+jqiTn:JAVzRALY6mJUN9S4A3+SEjir

Entry address:
0x17024

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, C6, FE, FF, FF, CC, CC, 70, 70, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 6C, 74, 01, 00, 80, 34, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 78, 71, 01, 00, 00, 00, 00, 00, 90, 71, 01, 00, 00, 00, 00, 00, A8, 71, 01, 00, 00, 00, 00, 00, C4, 71, 01, 00, 00, 00, 00, 00, E4, 71, 01, 00, 00, 00, 00, 00, FC, 71, 01, 00, 00, 00, 00, 00, 10, 72, 01, 00...
 
[+]

Entropy:
3.5757

Code size:
14.8 KB (15,104 bytes)

Driver
Display name:
secburn

Type:
Kernel device driver (KernelDriver)

Group:
Filter


Scan secburn.sys - Powered by Reason Core Security