shicqrcb.sys

Chongqing Shahai Information Tech Co.,Ltd

It runs as a Windows kernel mode device driver named “shicqrcb”.
Publisher:
沙海  (signed by Chongqing Shahai Information Tech Co.,Ltd)

Product:
沙海

Description:
SecurityPassDrv

Version:
3, 0, 0, 0

MD5:
fb601615a81900c335994a1ff70011bd

SHA-1:
90df1f86ee512d0f0b69dc276dad0eb95f701d01

SHA-256:
8c46f1870d5f8d89bc18afd75b8f88221377a69bef228640242a2bd931d8672a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 1:06:57 PM UTC  (today)

File size:
147.3 KB (150,800 bytes)

Product version:
3, 0, 0, 0

Copyright:
沙海

Original file name:
SecurityPassDrv.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\shicqrcb.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/26/2014 8:00:00 AM

Valid to:
8/26/2015 7:59:59 AM

Subject:
CN="Chongqing Shahai Information Tech Co.,Ltd", OU=IT, O="Chongqing Shahai Information Tech Co.,Ltd", L=Chongqing, S=Chongqing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7ABA7B20248A50ACD93F3A01195662E1

File PE Metadata
Compilation timestamp:
4/1/2015 10:11:46 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
3072:oIkzRaAHIgoLeAw+ZTF5mJSysALum/t1VgOZF80k7ynRlXmEgSQe9+0L:o8g1Aw+/mJIAL1/XV9F8H7ynRlXmny91

Entry address:
0x795F7

Entry point:
60, 57, FF, 34, 24, 9C, C7, 44, 24, 28, 7E, 34, 04, 05, E8, 07, A1, FF, FF, 04, 20, D2, E4, D2, E4, E8, 8C, FC, FF, FF, 7F, 66, FB, 0A, 13, E2, 5E, 56, FB, 9A, 43, 88, A1, B4, 7D, 74, 55, FF, 40, B7, BC, 4B, 6C, D6, F9, 54, C1, 30, 40, 6D, 4A, F4, CD, 77, EC, 1B, 4B, 50, 98, 0A, E2, C1, 3C, 8B, 80, 10, 9E, 07, 1C, 28, BD, A6, 5D, 95, 74, 18, DF, B6, FE, 36, 2A, 3E, CC, 27, 3F, 6C, 5F, AF, F8, 48, 04, A9, 75, 2F, 1B, C4, 80, 78, 4D, 09, 01, D4, 70, 68, 6C, C4, 67, 34, A1, D1, B0, F0, 02, 0F, E6, FB, 42, EA...
 
[+]

Entropy:
7.7616  (probably packed)

Code size:
43.5 KB (44,544 bytes)

Driver
Display name:
shicqrcb

Type:
Kernel device driver (KernelDriver)


Scan shicqrcb.sys - Powered by Reason Core Security