mbrfilter.sys

Cisco Systems, Inc.

Publisher:
Cisco Systems, Inc.  (signed and verified)

MD5:
a9685ca7a610f24573e999d8a009c319

SHA-1:
af8f0432fa3c11629e030f17dfb4a2cd3baa2c45

SHA-256:
e79682cf1d1c9f68eea68fe504abe960e2efc025eaa9b7dc83c83f88d77d807a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 2:06:39 PM UTC  (today)

File size:
19.1 KB (19,600 bytes)

File type:
Driver (Win64 SYS)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\64\mbrfilter.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/27/2014 8:00:00 PM

Valid to:
12/26/2017 6:59:59 PM

Subject:
CN="Cisco Systems, Inc.", O="Cisco Systems, Inc.", L=San Jose, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
707D1B670339C1015805353837A7C3D1

File PE Metadata
Compilation timestamp:
9/21/2016 7:23:53 PM

OS version:
6.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
11.0

CTPH (ssdeep):
384:FXop92aDfCVG12rzRor4TUHeMLyifjA/CV:up8m4G12rzy

Entry address:
0x6070

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8B, DA, 48, 8B, F9, E8, 83, FF, FF, FF, 48, 8B, D3, 48, 8B, CF, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, E9, 6E, AF, FF, FF, CC, CC, F0, 60, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, C4, 63, 00, 00, 18, 30, 00, 00, D8, 60, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FC, 63, 00, 00, 00, 30, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D2, 63, 00, 00, 00, 00, 00, 00, E8, 63, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.2758

Code size:
7 KB (7,168 bytes)