shihanabank.sys

Chongqing Shahai Information Tech Co.,Ltd

It runs as a Windows kernel mode device driver named “SHIHANABANK”.
Publisher:
沙海  (signed by Chongqing Shahai Information Tech Co.,Ltd)

Product:
沙海

Description:
SecurityPassDrv

Version:
3, 0, 0, 0

MD5:
2297bd2850d167eb3fd66d8c348a42ed

SHA-1:
b70ae568c6db77ee8d8c20f495e3352d64afe599

SHA-256:
9a3d1164b40ff5a08d0d719944227825172d45e7b728fcdf4427f5cea81e4ea4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 2:47:25 PM UTC  (today)

File size:
145.8 KB (149,312 bytes)

Product version:
3, 0, 0, 0

Copyright:
沙海

Original file name:
SecurityPassDrv.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\shihanabank.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/13/2013 9:00:00 AM

Valid to:
7/13/2014 8:59:59 AM

Subject:
CN="Chongqing Shahai Information Tech Co.,Ltd", OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Chongqing Shahai Information Tech Co.,Ltd", L=Chongqing, S=Chongqing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
71825A61C6D3DB1C677B6F98174E44F8

File PE Metadata
Compilation timestamp:
3/21/2014 5:29:39 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x80D91

Entry point:
60, 68, 0E, E1, 9B, B4, 9C, C7, 44, 24, 24, 77, E3, 04, 04, E8, D2, 26, FE, FF, 19, 53, 4C, F6, 53, A2, FD, 98, 04, 65, 0B, D1, DA, 8D, 7E, 75, FA, 09, 1D, 82, BE, E3, 5C, AB, 3A, 15, 1D, 82, A3, 52, BF, 36, CD, 80, 3B, 16, 37, CE, C1, 63, E7, 08, 96, 54, 98, 0A, 1A, DB, 13, 8D, 91, 52, 55, DF, 47, 59, F1, 43, 9C, B0, 3E, EF, 61, 4F, BE, E2, FF, 04, 4E, A6, 49, D1, ED, 77, 93, 28, 33, EB, 41, 0D, E4, 5C, AC, F5, 37, 59, 30, F2, 4E, 97, BF, 20, 38, B9, B5, AD, 10, 9E, B0, 35, 63, FF, 2F, F8, 68, 26, A6, 21...
 
[+]

Entropy:
7.7625  (probably packed)

Code size:
43 KB (44,032 bytes)

Driver
Display name:
SHIHANABANK

Type:
Kernel device driver (KernelDriver)


Scan shihanabank.sys - Powered by Reason Core Security