vportbus.sys

FabulaTech Virtual serial ports bus

FabulaTech

It runs as a Windows kernel mode device driver named “vportbus”.
Publisher:
FabulaTech  (signed and verified)

Product:
FabulaTech Virtual serial ports bus

Description:
Virtual serial ports bus

Version:
5, 8, 6, 0

MD5:
aa5136d5c0cc6cb96b8d1930de57464a

SHA-1:
b5eaf61bb0488f5d442f0a7cdc47d1f036180d4e

SHA-256:
07854aeee699e0beb87ab17952c856f96291826dcb0fed54787349594441b448

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/5/2024 8:36:21 AM UTC  (today)

File size:
40 KB (40,928 bytes)

Product version:
5, 8, 6, 0

Copyright:
Copyright © 2000-2008 FabulaTech

Original file name:
vportbus.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\vportbus.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/11/2008 4:45:16 AM

Valid to:
2/11/2009 4:45:16 AM

Subject:
E=contacts@fabulatech.com, CN=FabulaTech, O=FabulaTech, C=GB

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000011807E25479

File PE Metadata
Compilation timestamp:
5/13/2008 3:39:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
6.0

CTPH (ssdeep):
384:zhKkH03plsEaaBfQ8uet7MsJRQkQu0Sq0XKnyB0UTUI5TDXVgqLbufgT+/Bk0GoF:dniDiaBZFJMsGnyXHDN6a0BUdsxBQiF

Entry address:
0x7920

Entry point:
56, 8B, 74, 24, 0C, 68, 56, 42, 75, 73, 66, 8B, 06, 66, 05, 02, 00, 66, A3, 52, 5D, 01, 00, 66, 8B, 0E, 0F, B7, C0, 50, 6A, 01, 66, 89, 0D, 50, 5D, 01, 00, FF, 15, 9C, 03, 01, 00, 85, C0, A3, 54, 5D, 01, 00, 75, 07, B8, 9A, 00, 00, C0, EB, 53, 56, 68, 50, 5D, 01, 00, FF, 15, A0, 03, 01, 00, B9, 60, 5D, 01, 00, 8B, 44, 24, 08, 89, 48, 38, 89, 48, 40, C7, 80, A4, 00, 00, 00, 95, 6E, 01, 00, C7, 80, 90, 00, 00, 00, AE, 27, 01, 00, C7, 40, 70, BA, 5D, 01, 00, C7, 80, 94, 00, 00, 00, 99, 77, 01, 00, C7, 40, 34...
 
[+]

Entropy:
6.5621

Code size:
31.3 KB (32,032 bytes)

Driver
Display name:
vportbus

Type:
Kernel device driver (KernelDriver)

Group:
Extended Base


Scan vportbus.sys - Powered by Reason Core Security