sgp_x86.sys

snail游戏安全组

苏州蜗牛数字科技股份有限公司

It runs as a Windows kernel mode device driver named “sgp”.
Publisher:
snail.cn  (signed by 苏州蜗牛数字科技股份有限公司)

Product:
snail游戏安全组

Description:
游戏安全

Version:
1.4.0.309

MD5:
ab69122b39211c6a40ad4ae87a77344f

SHA-1:
df9efa6d3b65077382f747e5b965b1f4ba49ff5c

SHA-256:
069d88f2cd8c625cedf12c6ea8dbc57b59eb365b50de91b7e0228fc38fb90759

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/17/2024 5:55:39 PM UTC  (today)

File size:
210.7 KB (215,776 bytes)

Product version:
1.4.0

Copyright:
版权所有(c) 2015, snail.cn

Original file name:
sdprotect.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\sgp_x86.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/16/2016 8:00:00 AM

Valid to:
12/20/2017 7:59:59 AM

Subject:
CN=苏州蜗牛数字科技股份有限公司, OU=研发部, O=苏州蜗牛数字科技股份有限公司, L=苏州, S=江苏, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
10A0FC32CB19D8E678B77A01D0F8755A

File PE Metadata
Compilation timestamp:
11/21/2016 8:20:40 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

Entry address:
0x57F5A

Entry point:
68, 5E, 51, 95, 38, E9, 57, 02, 00, 00, 66, C7, 04, 24, 0B, 33, 8B, 35, 34, B0, 03, 00, 9C, 8D, 64, 24, 0C, E9, 2B, 14, 00, 00, 58, 8B, 44, 24, 44, E9, DD, 0A, 00, 00, B2, E7, F2, 43, 40, 6D, 6A, C6, BB, 18, 2F, 8C, A8, BA, 15, 00, 65, 98, B1, 24, BB, 06, 05, 26, 29, 05, 50, 6D, 8E, BD, E0, 09, 04, E0, DB, E4, 49, 48, 6B, 6E, 75, 9F, B5, B8, 64, A7, 0C, 1E, 5A, 94, 74, 86, 80, A7, BF, 01, 6E, 00, 90, 93, 6E, 5B, 59, 45, 70, 77, FD, D3, E8, F1, 26, 1F, 4C, 19, 75, 3C, A5, 17, B0, B3, D4, FB, 72, 21, 2A, D7...
 
[+]

Entropy:
7.8249  (probably packed)

Code size:
10.5 KB (10,752 bytes)

Driver
Display name:
sgp

Type:
Kernel device driver (KernelDriver)


Scan sgp_x86.sys - Powered by Reason Core Security