usbpcap.sys

USBPcap Sniffer Driver

Wireshark Foundation, Inc.

It runs as a Windows 64-bit kernel mode device driver named “USBPcap Capture Service”.
Publisher:
USBPcap  (signed by Wireshark Foundation, Inc.)

Product:
USBPcap Sniffer Driver

Description:
USBPcap Driver

Version:
1.1.0.0-g794bf26

MD5:
9e1742739a06ea3816c3b1588d54545c

SHA-1:
16db65aedd2a40613055a4d162d193d0ecfd8ae2

SHA-256:
6ff8d76be912eb13cb54a3e8c74644ea7c4060aabeb7ea5b9b8b5154dd0ce0ba

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 4:47:27 PM UTC  (today)

File size:
47.6 KB (48,752 bytes)

Product version:
1.1.0.0-g794bf26

Copyright:
(c) 2013-2015 Tomasz Mon

Original file name:
USBPcap

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\usbpcap.sys

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/20/2015 8:00:00 PM

Valid to:
7/27/2016 8:00:00 AM

Subject:
CN="Wireshark Foundation, Inc.", O="Wireshark Foundation, Inc.", L=Davis, S=California, C=US, PostalCode=95618, STREET=338 Madson Pl, SERIALNUMBER=C3061103, OID.1.3.6.1.4.1.311.60.2.1.2=California, OID.1.3.6.1.4.1.311.60.2.1.3=US, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0B49E2E7A42940E43EDAC36D6386A3FC

File PE Metadata
Compilation timestamp:
10/2/2015 5:07:51 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:UyBPnNQ5qEOuXJ3GNHC+XUGrXr4cTf/NXSZz1aAsTP16Bnr0u3EoVhb:a5V/2tprXBiQjP16v0oVl

Entry address:
0x69E4

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, D2, AE, FF, FF, CC, CC, 50, 6A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 72, 6F, 00, 00, 10, 37, 00, 00, 40, 6A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 8C, 72, 00, 00, 00, 37, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 66, 72, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 8C, 6C, 00, 00, 00, 00, 00, 00, A0, 6C, 00, 00, 00, 00, 00, 00, B2, 6C, 00, 00...
 
[+]

Entropy:
6.8359

Code size:
23.6 KB (24,192 bytes)

Driver
Display name:
USBPcap Capture Service

Service name:
USBPcap

Type:
Kernel device driver (KernelDriver)


Scan usbpcap.sys - Powered by Reason Core Security