___temp.sys

JNESS Inc.

It runs as a Windows kernel mode device driver named “PMCore32”.
Publisher:
JNESS Inc.  (signed and verified)

MD5:
1b11a79e5917597d41196dfda8120a44

SHA-1:
f794a80c3b878d6fb4dbc398dcc21ac927efb224

SHA-256:
c465b0c21c33967df64e982cf2a6294081fb26c877232f6e32a0acd7a2d51fa2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 10:57:33 PM UTC  (today)

File size:
13.9 KB (14,192 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\windows\___temp.sys

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
10/10/2012 9:00:00 AM

Valid to:
10/11/2014 8:59:59 AM

Subject:
CN=JNESS Inc., O=JNESS Inc., L=Seongdong-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4D82802065B0D4FC5CBE3631FBE141EE

File PE Metadata
Compilation timestamp:
6/8/2014 10:40:31 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
192:CgfRllUwfX51SKnEk/QOWaz8x484mUnS/q8eou7+wse+PjPPz78oPY2RT/:5RlnhQZ0NPqW7nStuSPLn8od/

Entry address:
0x5112

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, E4, FE, FF, FF, CC, CC, 80, 51, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 1C, 53, 00, 00, 20, 20, 00, 00, 60, 51, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, F0, 53, 00, 00, 00, 20, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B8, 53, 00, 00, 9A, 53, 00, 00, 7E, 53, 00, 00, 62, 53, 00, 00, 4C, 53, 00, 00, 36, 53, 00, 00, DC, 53, 00, 00, 00, 00, 00, 00, 3A, 52, 00, 00, 56, 52, 00, 00, 6C, 52, 00, 00, 88, 52, 00, 00, 98, 52...
 
[+]

Entropy:
6.4158

Code size:
4 KB (4,096 bytes)

Driver
Display name:
PMCore32

Type:
Kernel device driver (KernelDriver)


Scan ___temp.sys - Powered by Reason Core Security