shihanabank.sys

Chongqing Shahai Information Tech Co.,Ltd

It runs as a Windows kernel mode device driver named “SHIHANABANK”.
Publisher:
沙海  (signed by Chongqing Shahai Information Tech Co.,Ltd)

Product:
沙海

Description:
SecurityPassDrv

Version:
3, 0, 2, 0

MD5:
eb652dda0a2f860e9c915c39cd021ac6

SHA-1:
fbba9ea6c8501dec7c62501c99ca7ef052eeaa0e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 1:31:33 PM UTC  (today)

File size:
154.7 KB (158,440 bytes)

Product version:
3, 0, 2, 0

Copyright:
沙海

Original file name:
SecurityPassDrv.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\shihanabank.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/12/2015 8:00:00 AM

Valid to:
9/11/2016 7:59:59 AM

Subject:
CN="Chongqing Shahai Information Tech Co.,Ltd", OU=IT, O="Chongqing Shahai Information Tech Co.,Ltd", L=Chongqing, S=Chongqing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
48C3DC72FE59B29E68DD8B4C8E454AD9

File PE Metadata
Compilation timestamp:
10/9/2015 6:41:18 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x7A1F8

Entry point:
E8, E4, 32, FF, FF, 47, 58, 6D, D7, F8, 5A, D6, 19, FB, 92, 4C, E6, 59, 8E, AB, 5A, EF, 06, 03, F2, F1, 6C, 87, DA, E7, 69, C2, 31, 02, F1, 66, 9D, 92, 61, 98, CB, D8, 7A, D6, 1F, 96, D6, 28, 04, 1E, B7, A0, 10, 96, 08, 56, C5, 12, D2, 66, 1E, 38, 92, 46, 17, 4B, CB, E5, ED, E4, 6D, F6, 0D, 7F, 7D, EA, 19, 84, AE, AA, 4B, AB, D6, E1, 81, 79, 6C, F4, 92, A1, 61, 6C, 3F, 99, F8, 78, CA, 2D, C3, 8C, 29, 1A, C0, D9, EF, 69, F7, 75, A5, 3A, 1E, C7, 7B, 19, 19, 19, 6B, C5, 86, 12, EF, 87, 06, F8, 71, 80, 98, 05...
 
[+]

Entropy:
7.7661  (probably packed)

Code size:
46 KB (47,104 bytes)

Driver
Display name:
SHIHANABANK

Type:
Kernel device driver (KernelDriver)


Scan shihanabank.sys - Powered by Reason Core Security