shiucfpay64.sys

Chongqing Shahai Information Tech Co.,Ltd

It runs as a Windows 64-bit kernel mode device driver named “SHIUCFPAY”.
Publisher:
沙海  (signed by Chongqing Shahai Information Tech Co.,Ltd)

Product:
沙海

Description:
SecurityPassDrv

Version:
3, 0, 0, 0

MD5:
6fcc2eed4d37fa698b4c09e53e3ac56f

SHA-1:
afd17cbb35399997345b70a3d0f90f9fbd03566f

SHA-256:
aa0f75c931c06cb55564aa566b36d0939f2cd8b3e8b4e2c2e1ff5fed493e330b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 12:23:44 PM UTC  (today)

File size:
456.9 KB (467,864 bytes)

Product version:
3, 0, 0, 0

Copyright:
沙海

Original file name:
SecurityPassDrv.sys

File type:
Driver (Win64 SYS)

Common path:
C:\windows\syswow64\drivers\shiucfpay64.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/26/2014 8:00:00 AM

Valid to:
8/26/2015 7:59:59 AM

Subject:
CN="Chongqing Shahai Information Tech Co.,Ltd", OU=IT, O="Chongqing Shahai Information Tech Co.,Ltd", L=Chongqing, S=Chongqing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7ABA7B20248A50ACD93F3A01195662E1

File PE Metadata
Compilation timestamp:
6/24/2014 4:00:18 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
6144:S+S0c3sv8qqDL6jZIp0Eg5k7MWVf5mVHMEohKNhvb09ju:5rvZqn6+p0jkoWVzEWKNhgo

Entry address:
0x66B3C

Entry point:
E9, A3, 50, 00, 00, 0F, 82, 4B, BE, FF, FF, F8, F8, 0F, A3, E3, 80, 7F, FF, 00, E9, F5, 34, 00, 00, 3D, 3E, 7D, 2A, 47, F9, 08, E4, E9, FF, 32, 00, 00, D0, 6B, 4F, DF, D5, 76, B8, A7, 18, B7, 3F, D8, 96, 39, 12, D2, 2E, 9A, 74, CC, 99, CD, 69, 31, 48, C3, CA, 4C, 45, FE, 8B, C7, 04, 62, CC, 90, 0B, C2, C6, FA, 96, 7D, B1, 42, C8, 6A, B7, 57, F6, 9A, 95, 21, 34, DF, 3B, D7, 9A, 21, 61, FB, 90, 21, 17, A2, CE, 6B, F5, 84, CC, 61, B3, 43, D2, 78, 81, 0E, 58, EE, A7, 41, 6D, B5, 2B, 45, 5E, A3, 35, C9, 7B, 31...
 
[+]

Entropy:
3.7937

Packer / compiler:
Xtreme-Protector v1.05

Code size:
44.3 KB (45,312 bytes)

Driver
Display name:
SHIUCFPAY

Type:
Kernel device driver (KernelDriver)


Scan shiucfpay64.sys - Powered by Reason Core Security