sangfortcpdrv.sys

WfpDriver

Sangfor Technologies Co.,Ltd

It runs as a Windows 64-bit kernel mode device driver named “SangforTcpDrv_7,1,1,0”.
Publisher:
Sangfor  (signed by Sangfor Technologies Co.,Ltd)

Product:
WfpDriver

Description:
Sangfor WfpDriver

Version:
7.1.1.0

MD5:
3a3f35b7041e08313c4ae9dc1db311b3

SHA-1:
b90dfda120b9fec591fbfca1aa555cafcd2cce14

SHA-256:
01416e94b8d22519bddd11ca02f174493fe52cbefb7f45f322a1baad2f9f753d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 10:08:01 AM UTC  (today)

File size:
51.5 KB (52,776 bytes)

Product version:
7.1.1.0

Copyright:
Sangfor Copyright ? 2010

Original file name:
WfpDriver.sys

File type:
Driver (Win64 SYS)

Common path:
C:\Program Files\sangfor\ssl\tcpdriver3\sangfortcpdrv.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/17/2015 8:00:00 AM

Valid to:
9/15/2018 7:59:59 AM

Subject:
CN="Sangfor Technologies Co.,Ltd", OU=research and development department, O="Sangfor Technologies Co.,Ltd", L=shenzhen, S=guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
121876DB06E834DA35C19890E6E650D0

File PE Metadata
Compilation timestamp:
10/24/2016 4:58:27 PM

OS version:
6.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
11.0

Entry address:
0xC070

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8B, DA, 48, 8B, F9, E8, 83, FF, FF, FF, 48, 8B, D3, 48, 8B, CF, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, E9, 32, 5E, FF, FF, CC, CC, 80, C1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, E0, C3, 00, 00, A8, 90, 00, 00, D8, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, EC, C5, 00, 00, 00, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, C2, C5, 00, 00, 00, 00, 00, 00, A8, C5, 00, 00, 00, 00, 00, 00, 8E, C5, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7451

Code size:
30.5 KB (31,232 bytes)

Driver
Display name:
SangforTcpDrv_7,1,1,0

Type:
Kernel device driver (KernelDriver)


Scan sangfortcpdrv.sys - Powered by Reason Core Security