xxlhasp.sys

NGO

It runs as a Windows kernel mode device driver named “XXLHASP”.
Publisher:
NGO  (signed and verified)

MD5:
02bd111a9acc2cc8e2259a698ced1dae

SHA-1:
09a516f114db8a03781d3e79fb826b98b30650ae

SHA-256:
ab6aaca2ba8677c36c55fc53925427da7892aa81707a073537ecb236044bb6eb

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 8:25:18 AM UTC  (today)

File size:
843 KB (863,232 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\xxlhasp.sys

Digital Signature
Signed by:

Authority:
NGO

Valid from:
8/4/2009 8:55:45 AM

Valid to:
12/31/2039 6:59:59 PM

Subject:
CN=NGO

Issuer:
CN=NGO

Serial number:
CB213AC9B9E9FE9B4366E084CAE30A53

File PE Metadata
Compilation timestamp:
11/18/2009 5:38:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

CTPH (ssdeep):
12288:zlDs/b9X7yywVgpRN6JgVJHtCO+41tte5kj1ENoYuigihHVR8Hm/h8SDBZQQ:JDsRLypgpT/tCb5kuBVhHMHm/++

Entry address:
0xCF726

Entry point:
68, 54, 83, DC, 23, E8, B2, 14, 00, 00, 0F, 82, 95, D5, FF, FF, 84, E4, 60, 60, 38, D2, 80, 7F, FF, 00, FF, 74, 24, 04, 66, 89, 4C, 24, 04, 8D, 64, 24, 44, 0F, 85, 75, E7, FF, FF, D3, C7, 0F, CF, 68, 97, C8, B4, 82, 8B, 7A, 24, F5, E9, C0, E7, FF, FF, F8, 69, D2, 0A, 00, 00, 00, F9, 38, FF, 01, C2, 9C, 8D, 64, 24, 08, E9, AF, D5, FF, FF, 68, E7, A3, DC, 23, E8, B3, 1B, 00, 00, 67, 32, 10, AD, 57, D2, B7, B7, E8, 7B, 0A, DC, 4C, 6D, AD, CE, 70, C8, 23, 55, 08, DC, D8, BE, 1B, 77, 8C, 3B, 96, 9E, E3, 02, 4A...
 
[+]

Code size:
840 KB (860,160 bytes)

Driver
Display name:
XXLHASP

Type:
Kernel device driver (KernelDriver)

Depends on:
Hardlock


Scan xxlhasp.sys - Powered by Reason Core Security