SangforTcp.dll

TCP Service Module

Sangfor Technologies Co.,Ltd

It is installed as a Winsock Layered Service Provider (LSP) named “SangforLSP over [MSAFD Tcpip [TCP/IP]]” as a layered chain entry (32).
Publisher:
Sangfor Technologies Co.,Ltd  (signed and verified)

Product:
TCP Service Module

Version:
6, 8, 0, 0

MD5:
a1eeabbeb8ebd98a3ddc0fd05d5664ce

SHA-1:
d5e7927eb5c763b3ebbf1da2da3ce34da3594e30

SHA-256:
ec2954a0ab2290da5ec09a61ee6af654bb38b4b872d032a76a745814179ad0cd

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/28/2024 5:34:43 AM UTC  (today)

File size:
2.3 MB (2,423,992 bytes)

Product version:
6, 8, 0, 0

Copyright:
Copyright 2010 - 2015

Original file name:
SangforTcp.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\sangfor\ssl\clientcomponent\sangfortcp.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/22/2012 8:00:00 AM

Valid to:
8/23/2015 7:59:59 AM

Subject:
CN="Sangfor Technologies Co.,Ltd", OU=research and development department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Sangfor Technologies Co.,Ltd", L=shenzhen, S=guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6E4DD7962582C784F2DDA8FFB8EA67A7

File PE Metadata
Compilation timestamp:
2/5/2015 4:16:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x2EFD5

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 57, 8B, 7D, 10, 85, F6, 75, 09, 83, 3D, B8, 74, 1A, 10, 00, EB, 26, 83, FE, 01, 74, 05, 83, FE, 02, 75, 22, A1, FC, FF, 04, 10, 85, C0, 74, 09, 57, 56, 53, FF, D0, 85, C0, 74, 0C, 57, 56, 53, E8, 15, FF, FF, FF, 85, C0, 75, 04, 33, C0, EB, 4E, 57, 56, 53, E8, 29, FA, FF, FF, 83, FE, 01, 89, 45, 0C, 75, 0C, 85, C0, 75, 37, 57, 50, 53, E8, F1, FE, FF, FF, 85, F6, 74, 05, 83, FE, 03, 75, 26, 57, 56, 53, E8, E0, FE, FF, FF, 85, C0, 75, 03, 21, 45, 0C, 83, 7D, 0C, 00...
 
[+]

Entropy:
2.1738

Developed / compiled with:
Microsoft Visual C++ 6.0

Code size:
200 KB (204,800 bytes)

Winsock2 LSP
Name:
SangforLSP over [MSAFD Tcpip [TCP/IP]]

Type:
Layered Chain Entry (32)

Provider ID:
{EA61909E-2337-4E4A-AB27-44AA5B9183CE}

Service flags:
0x20066


Scan SangforTcp.dll - Powered by Reason Core Security