shihbbank.sys

Chongqing Shahai Information Tech Co.,Ltd

It runs as a Windows kernel mode device driver named “shihbbank”.
Publisher:
沙海  (signed by Chongqing Shahai Information Tech Co.,Ltd)

Product:
沙海

Description:
SecurityPassDrv

Version:
3, 0, 0, 0

MD5:
80deebeb143a7beedd76040849dec30a

SHA-1:
c58b011fc7e6340e8bdc79ad40c9b0a6bfc2abb9

SHA-256:
c1230ffe64c11e488910714ab57c83218eecb0d9a24bc530d56b42558d35f2d0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 3:04:49 PM UTC  (today)

File size:
146.3 KB (149,776 bytes)

Product version:
3, 0, 0, 0

Copyright:
沙海

Original file name:
SecurityPassDrv.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\shihbbank.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/26/2014 8:00:00 AM

Valid to:
8/26/2015 7:59:59 AM

Subject:
CN="Chongqing Shahai Information Tech Co.,Ltd", OU=IT, O="Chongqing Shahai Information Tech Co.,Ltd", L=Chongqing, S=Chongqing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7ABA7B20248A50ACD93F3A01195662E1

File PE Metadata
Compilation timestamp:
3/10/2015 12:59:12 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
3072:CXlhJ6TlUdfz+sCR4czxwt2Ce8CTkthH4eqlxKEI31RwtxJGXQxuG+k:CXlLoadKpR4KhVhTiHsq1EGgxuGl

Entry address:
0x6FB48

Entry point:
E9, 42, 65, FF, FF, D3, CC, 55, AC, 35, 1F, 23, 66, C2, 0A, 23, 95, 1D, 31, 9E, A0, 7D, 74, ED, 04, 89, CB, 60, 97, 84, 73, A2, BD, 1E, 20, 35, CC, 79, 88, 31, 13, 9C, A6, 19, 1B, F7, 11, C2, B1, F1, 03, 38, 29, 0E, 67, C0, CA, 9D, AD, F0, CF, 7D, B9, BA, DD, 0A, 0E, B1, 22, 17, EE, 53, A2, 01, 23, 1C, EB, E6, 48, CC, C6, E0, 28, FC, 80, C3, 31, 19, 11, B5, 8D, 6C, 4D, 88, 0F, C4, 79, 59, 54, EC, 68, 89, C5, 08, FE, 1A, EA, E1, 26, A0, 8C, 8C, 5C, 96, 3F, 01, B2, 9C, 70, 13, C9, 88, 13, 1F, 2F, AE, 40, 7D...
 
[+]

Entropy:
7.7750

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
43 KB (44,032 bytes)

Driver
Display name:
shihbbank

Type:
Kernel device driver (KernelDriver)


Scan shihbbank.sys - Powered by Reason Core Security