shiibkbank64.sys

Chongqing Shahai Information Tech Co.,Ltd

It runs as a Windows 64-bit kernel mode device driver named “SHIIBKBANK”.
Publisher:
沙海  (signed by Chongqing Shahai Information Tech Co.,Ltd)

Product:
沙海

Description:
SecurityPassDrv

Version:
3, 0, 0, 0

MD5:
8cd1c832ac180de52d907432cd18d7b4

SHA-1:
e794f1aeef65d2c63dbfb63c9e6247bf95ca83b6

SHA-256:
2fda39237f88b54db183eba1f01262b80caafa9a76521d02b2ef37c92341a406

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 6:04:28 PM UTC  (today)

File size:
457.8 KB (468,800 bytes)

Product version:
3, 0, 0, 0

Copyright:
沙海

Original file name:
SecurityPassDrv.sys

File type:
Driver (Win64 SYS)

Common path:
C:\windows\syswow64\drivers\shiibkbank64.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/13/2013 9:00:00 AM

Valid to:
7/13/2014 8:59:59 AM

Subject:
CN="Chongqing Shahai Information Tech Co.,Ltd", OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Chongqing Shahai Information Tech Co.,Ltd", L=Chongqing, S=Chongqing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
71825A61C6D3DB1C677B6F98174E44F8

File PE Metadata
Compilation timestamp:
12/4/2013 12:13:36 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
6144:C+tQohnqqDL6GS1uBx0W9XLKFR1ZrhRtBRG8hpNEN:pzqqn6GS18x0WdK/NL7GIpi

Entry address:
0x684AF

Entry point:
E9, 0D, 47, 00, 00, E9, B4, 12, 00, 00, E9, CA, 00, 00, 00, 3C, 09, E9, 98, 9D, FF, FF, 48, 8D, 34, 8D, 71, C9, FD, CC, 48, 8D, B7, A9, D4, 06, 1F, 0F, B6, F1, 48, 8D, 35, F6, A2, FF, FF, E9, 84, 07, 00, 00, F8, 84, D9, F9, 3B, 4A, 14, E9, B2, ED, FF, FF, E9, 8F, AB, FF, FF, 0F, 85, 1C, D5, FF, FF, 48, 0F, BA, E3, 28, 38, C8, C6, 47, FF, 00, F6, C4, 94, 66, 0F, A3, E8, 80, FA, 68, 48, F7, C4, 08, 00, 00, 00, E9, 41, AB, FF, FF, 0F, 87, F5, D4, FF, FF, E9, 11, 3C, 00, 00, 0F, 85, 1B, AB, FF, FF, 66, 0F, B6...
 
[+]

Entropy:
3.8472

Packer / compiler:
Xtreme-Protector v1.05

Code size:
43.5 KB (44,544 bytes)

Driver
Display name:
SHIIBKBANK

Type:
Kernel device driver (KernelDriver)


Scan shiibkbank64.sys - Powered by Reason Core Security