shihbbank.sys

Chongqing Shahai Information Tech Co.,Ltd

It runs as a Windows kernel mode device driver named “shihbbank”.
Publisher:
沙海  (signed by Chongqing Shahai Information Tech Co.,Ltd)

Product:
沙海

Description:
SecurityPassDrv

Version:
3, 0, 2, 0

MD5:
8f45f0781644400e5e32f20f84ad0325

SHA-1:
ad6c9814e7fff321c1f87539d66298a356527631

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 11:51:20 AM UTC  (today)

File size:
154.7 KB (158,440 bytes)

Product version:
3, 0, 2, 0

Copyright:
沙海

Original file name:
SecurityPassDrv.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\shihbbank.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/12/2015 8:00:00 AM

Valid to:
9/11/2016 7:59:59 AM

Subject:
CN="Chongqing Shahai Information Tech Co.,Ltd", OU=IT, O="Chongqing Shahai Information Tech Co.,Ltd", L=Chongqing, S=Chongqing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
48C3DC72FE59B29E68DD8B4C8E454AD9

File PE Metadata
Compilation timestamp:
10/9/2015 6:41:14 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
3072:dwxJa9GOpmRlBnrGfG84zq3Yn/O84SSHz68+TiCvncvI7c/j:MJa9/pmNG+84zq3Y/4SK+8kUA7+j

Entry address:
0x7918C

Entry point:
E8, EA, 32, FF, FF, 5E, 37, 8C, B6, 17, 39, 35, 78, FB, 92, 6F, 87, 3A, AF, 8C, 7B, D0, 27, 24, D3, 12, 4D, 68, FB, C8, 8A, A3, 52, E3, 12, 07, FE, 73, 82, 39, 14, 91, B3, 8F, 50, 47, 87, 79, B5, CF, 00, 11, 10, 96, 2B, E1, 74, 61, C1, 55, 1E, 38, B1, 57, 26, 3A, DA, F4, FC, F3, 5C, C5, 3C, 8E, 6C, F9, 08, 73, BD, 99, 5A, 9A, C5, F0, 70, 68, 73, 03, A1, 90, 70, 7B, 30, A8, EF, 87, D9, 3C, D2, 73, 60, E3, F7, 10, EF, 69, D4, 3C, 39, 96, CA, 2B, 0F, AD, 75, ED, 3F, F4, B2, E6, 1B, 1B, 9A, 54, D5, 2C, 2C, 71...
 
[+]

Entropy:
7.7635  (probably packed)

Code size:
45.5 KB (46,592 bytes)

Driver
Display name:
shihbbank

Type:
Kernel device driver (KernelDriver)


Scan shihbbank.sys - Powered by Reason Core Security