shihanabank.sys

Chongqing Shahai Information Tech Co.,Ltd

It runs as a Windows kernel mode device driver named “SHIHANABANK”.
Publisher:
沙海  (signed by Chongqing Shahai Information Tech Co.,Ltd)

Product:
沙海

Description:
SecurityPassDrv

Version:
3, 0, 0, 0

MD5:
9999f36c9ba9732c17c29fbabcab66cd

SHA-1:
0ebeb025152ce30196c5001d9935cf6d496641a1

SHA-256:
316fab9cdb6a5b026b9355313d4a95049f540bef6acc964ad54beaddb4100c3a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 1:36:17 PM UTC  (today)

File size:
146.3 KB (149,776 bytes)

Product version:
3, 0, 0, 0

Copyright:
沙海

Original file name:
SecurityPassDrv.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\shihanabank.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/26/2014 8:00:00 AM

Valid to:
8/26/2015 7:59:59 AM

Subject:
CN="Chongqing Shahai Information Tech Co.,Ltd", OU=IT, O="Chongqing Shahai Information Tech Co.,Ltd", L=Chongqing, S=Chongqing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7ABA7B20248A50ACD93F3A01195662E1

File PE Metadata
Compilation timestamp:
3/23/2015 10:47:38 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
3072:m2xNfawCfNhyVWCoax9MMthuTxxKExhhBdFyez9C/dD+t:m2xxyYzb9MMmv7HdFyexC/dD8

Entry address:
0x6FB4E

Entry point:
E9, 3C, 65, FF, FF, 2F, 60, F1, 00, A1, A3, B7, FA, C2, 0A, 23, 01, B1, AD, 0A, 34, 11, E0, 61, 90, 15, 3F, 14, E3, 70, 87, 2E, 21, 8A, B4, A9, 58, E5, 1C, BD, 87, 08, 4A, 45, EF, 23, 3D, 96, 05, 45, BF, 84, 29, 0E, 67, 7C, 4E, 19, 31, 74, CF, 7D, B9, 36, 51, 86, 82, 25, BE, 83, 72, C7, 3E, 6D, B7, 88, 7F, 52, DC, 38, 6A, 3C, 84, 90, A4, E7, 1D, 2D, 25, A1, 79, 58, 61, 74, 13, A8, 95, 3D, 38, 08, 44, AD, A9, EC, 1A, FE, CE, E1, 42, 84, A8, 68, 38, CA, EB, 55, 7E, C0, 4C, EF, C9, AC, EF, 33, 1B, 9A, 54, 71...
 
[+]

Entropy:
7.7746

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
43 KB (44,032 bytes)

Driver
Display name:
SHIHANABANK

Type:
Kernel device driver (KernelDriver)


Scan shihanabank.sys - Powered by Reason Core Security