shitcrcb.sys

Chongqing Shahai Information Tech Co.,Ltd

It runs as a Windows kernel mode device driver named “SHITCRCB”.
Publisher:
沙海  (signed by Chongqing Shahai Information Tech Co.,Ltd)

Product:
沙海

Description:
SecurityPassDrv

Version:
3, 0, 0, 0

MD5:
8c5a1a539f48a069f8105ed7234d80c1

SHA-1:
2617adffe7a0f8599edcbdd61a940c6d5f818901

SHA-256:
a4bdc97fc5ab6f6db017b78b250cb107b909b3df18586160740f1d834fc38e16

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 6:49:56 AM UTC  (today)

File size:
148.8 KB (152,384 bytes)

Product version:
3, 0, 0, 0

Copyright:
沙海

Original file name:
SecurityPassDrv.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\shitcrcb.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/13/2013 8:00:00 AM

Valid to:
7/13/2014 7:59:59 AM

Subject:
CN="Chongqing Shahai Information Tech Co.,Ltd", OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Chongqing Shahai Information Tech Co.,Ltd", L=Chongqing, S=Chongqing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
71825A61C6D3DB1C677B6F98174E44F8

File PE Metadata
Compilation timestamp:
12/4/2013 11:17:52 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x7EF5F

Entry point:
E9, 50, 09, FF, FF, 9C, 8D, 64, 24, 08, E8, 25, 46, FF, FF, 56, 88, 24, 24, E8, 60, 07, FF, FF, 66, 0F, B6, C3, 9F, 37, 8B, 45, F8, 0F, 8A, 25, 3F, FF, FF, F8, D1, E0, 9C, 9C, E8, 24, 54, FE, FF, 88, 0C, 24, 8D, 64, 24, 10, 0F, 82, 84, 0D, FF, FF, F9, 52, F9, 3B, 45, F0, C6, 04, 24, 80, E9, 96, 06, FF, FF, 8D, 64, 24, 2C, 0F, 86, 2C, 51, FF, FF, 66, C1, D7, 06, 80, FE, 08, 66, 0F, BC, D8, E9, 45, 09, FF, FF, 66, 0F, B6, F3, 5E, 8B, 35, 34, 60, 08, 00, 9C, 9C, C6, 04, 24, FB, 8D, 64, 24, 08, E9, 5E, B0, FF...
 
[+]

Entropy:
7.7589

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
42.5 KB (43,520 bytes)

Driver
Display name:
SHITCRCB

Type:
Kernel device driver (KernelDriver)


Scan shitcrcb.sys - Powered by Reason Core Security