shiylbank64.sys

Chongqing Shahai Information Tech Co.,Ltd

It runs as a Windows 64-bit kernel mode device driver named “SHIYLBANK”.
Publisher:
沙海  (signed by Chongqing Shahai Information Tech Co.,Ltd)

Product:
沙海

Description:
SecurityPassDrv

Version:
3, 0, 0, 0

MD5:
adbc2c2dc545e94c0a500a0e3c5feda2

SHA-1:
798eda04dadb821ccd623a45109b34b89d1d2705

SHA-256:
73a1832495b36a1aa718500f4c0a95bc6e29c0d28e1b1dfdf24ac4a043256f95

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 11:30:48 PM UTC  (a few moments ago)

File size:
457.8 KB (468,800 bytes)

Product version:
3, 0, 0, 0

Copyright:
沙海

Original file name:
SecurityPassDrv.sys

File type:
Driver (Win64 SYS)

Common path:
C:\windows\syswow64\drivers\shiylbank64.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/13/2013 9:00:00 AM

Valid to:
7/13/2014 8:59:59 AM

Subject:
CN="Chongqing Shahai Information Tech Co.,Ltd", OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Chongqing Shahai Information Tech Co.,Ltd", L=Chongqing, S=Chongqing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
71825A61C6D3DB1C677B6F98174E44F8

File PE Metadata
Compilation timestamp:
12/4/2013 12:19:07 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
6144:E+tQohiqqDL6vS1uBx0W9BLKFRwZrhRYBRG8hpNE5:LzXqn6vS18x0WnKkNC7GIpe

Entry address:
0x684AF

Entry point:
E9, 0D, 47, 00, 00, E9, B4, 12, 00, 00, E9, CA, 00, 00, 00, 3C, 09, E9, 98, 9D, FF, FF, 48, 8D, 34, 8D, 71, C9, FD, CC, 48, 8D, B7, A9, D4, 06, 1F, 0F, B6, F1, 48, 8D, 35, F6, A2, FF, FF, E9, 84, 07, 00, 00, F8, 84, D9, F9, 3B, 4A, 14, E9, B2, ED, FF, FF, E9, 8F, AB, FF, FF, 0F, 85, 1C, D5, FF, FF, 48, 0F, BA, E3, 28, 38, C8, C6, 47, FF, 00, F6, C4, 94, 66, 0F, A3, E8, 80, FA, 68, 48, F7, C4, 08, 00, 00, 00, E9, 41, AB, FF, FF, 0F, 87, F5, D4, FF, FF, E9, 11, 3C, 00, 00, 0F, 85, 1B, AB, FF, FF, 66, 0F, B6...
 
[+]

Entropy:
3.8471

Packer / compiler:
Xtreme-Protector v1.05

Code size:
43.5 KB (44,544 bytes)

Driver
Display name:
SHIYLBANK

Type:
Kernel device driver (KernelDriver)


Scan shiylbank64.sys - Powered by Reason Core Security