shisuning.sys

苏宁易付宝网络支付平台密码安全控件

Nanjing Suning yifubao Network Technology Co., Ltd.

It runs as a Windows kernel mode device driver named “SHISUNING”.
Publisher:
南京苏宁易付宝网络科技有限公司  (signed by Nanjing Suning yifubao Network Technology Co., Ltd.)

Product:
苏宁易付宝网络支付平台密码安全控件

Description:
Suning Yifubao Password Plugin

Version:
3, 0, 0, 0

MD5:
6fcce79bb2819c3c0cdd4f07f2317fc3

SHA-1:
3b756ec9e18dc56b9b18e08761f40041907049f5

SHA-256:
7183f0d494ec111b7be82ad2c1bba73c50e3f52ff17790736e1a70065a662aa6

Scanner detections:
5 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/24/2024 12:59:17 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Win32/Patched
2017.0.2692

IKARUS anti.virus
Virus.Win32.Patched
t3scan.1.6.1.0

K7 AntiVirus
Backdoor
13.177.12128

McAfee
Artemis!6FCCE79BB281
5600.6348

Trend Micro House Call
TROJ_GEN.F47V0227
7.2.186

File size:
149.3 KB (152,912 bytes)

Product version:
3, 0, 0, 0

Copyright:
shahaiinfo. All rights reserved.

Original file name:
shsuning.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\shisuning.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/20/2013 8:00:00 AM

Valid to:
4/19/2016 7:59:59 AM

Subject:
CN="Nanjing Suning yifubao Network Technology Co., Ltd.", OU=yifubao, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Nanjing Suning yifubao Network Technology Co., Ltd.", L=jiangsu, S=nanjing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
678A635D718CDE7CD20189555FBBD131

File PE Metadata
Compilation timestamp:
12/4/2013 11:17:26 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
3072:eC6m84+i8yGwsIkfQcei9lHXw3cxS999tqC3:e4z1GwYei/g3kS999tl3

Entry address:
0x7EF60

Entry point:
E9, 50, 09, FF, FF, 9C, 8D, 64, 24, 08, E8, 25, 46, FF, FF, 56, 88, 24, 24, E8, 60, 07, FF, FF, 66, 0F, B6, C3, 9F, 37, 8B, 45, F8, 0F, 8A, 25, 3F, FF, FF, F8, D1, E0, 9C, 9C, E8, 23, 54, FE, FF, 88, 0C, 24, 8D, 64, 24, 10, 0F, 82, 84, 0D, FF, FF, F9, 52, F9, 3B, 45, F0, C6, 04, 24, 80, E9, 96, 06, FF, FF, 8D, 64, 24, 2C, 0F, 86, 2C, 51, FF, FF, 66, C1, D7, 06, 80, FE, 08, 66, 0F, BC, D8, E9, 45, 09, FF, FF, 66, 0F, B6, F3, 5E, 8B, 35, 34, 60, 08, 00, 9C, 9C, C6, 04, 24, FB, 8D, 64, 24, 08, E9, 5E, B0, FF...
 
[+]

Entropy:
7.7521

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
42.5 KB (43,520 bytes)

Driver
Display name:
SHISUNING

Type:
Kernel device driver (KernelDriver)


Scan shisuning.sys - Powered by Reason Core Security