wayprotect32.sys

Btra Away Ltda - ME

It runs as a Windows kernel mode device driver named “WayProtect”.
Publisher:
Btra Away Ltda - ME  (signed and verified)

MD5:
8fc551128a3c12d56ec6e8bf0aeb40c5

SHA-1:
900fa34857477b1f8c93eea9a0e5bde4283b8fc8

SHA-256:
6f843c2d15c1d7f3f9c30710f2bbff11ac5fd5ec3cd4fa4c8d5540cb9201e273

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 11:09:52 AM UTC  (today)

File size:
740.6 KB (758,352 bytes)

File type:
Driver (Win32 SYS)

Common path:
C:\users\muaway\wayprotect32.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/7/2016 10:00:00 PM

Valid to:
10/16/2016 9:59:59 PM

Subject:
CN=Btra Away Ltda - ME, O=Btra Away Ltda - ME, L=Maraba, S=Para, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4C8EFFAD508C0E801EE50F6BEA0A6B99

File PE Metadata
Compilation timestamp:
1/11/2016 8:27:58 PM

OS version:
6.3

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
12.0

CTPH (ssdeep):
12288:TkLAWvgQJuknlcjc74sivXyY0HJTgDwvlgXukjZWgcvH3Jjn3XPJOwf3V/F:Tk0WoEDnjivXpoTgDUrktWxZjncGlt

Entry address:
0xE5CBB

Entry point:
68, 02, B6, E3, 52, E8, 6A, DC, FF, FF, B8, 51, 43, A7, C1, D2, 2C, 33, 5F, A7, E1, 8C, 11, E1, 53, 6D, 94, 56, 91, DB, B3, B1, 6B, CB, 07, 18, DE, 21, BA, 49, ED, 37, A7, F2, 48, E4, 99, 1F, FB, 44, 5A, F8, 2F, B7, F6, A3, 7F, C9, F8, CC, B5, 1F, 2E, 3D, 03, E2, 7E, D0, BD, 9F, 6D, E9, 26, 4B, 14, 54, 0A, AD, 0C, DC, 3D, 06, BD, AF, 5E, AE, E6, 51, 4D, 16, 83, D8, 70, 36, BD, C2, 54, 3F, 23, 65, 44, C8, FB, EC, F2, F8, 88, 22, 0D, 4E, 80, 77, 96, D5, 73, 91, B4, 93, 18, 71, C1, C4, 20, 3B, 4A, 3A, B4, 68...
 
[+]

Code size:
731.5 KB (749,056 bytes)

Driver
Display name:
WayProtect

Type:
Kernel device driver (KernelDriver)


Scan wayprotect32.sys - Powered by Reason Core Security