080a834f-3e19-4cae-b940-a4ecf901db28
HWiNFO64I.SYS
Description
Confirmed vulnerable driver from Microsoft Block List
Use Case | Privileges | Operating System |
---|---|---|
Elevate privileges | kernel | Windows |
Detections
YARA 🏹
Expand
Resources
CVE
Known Vulnerable Samples
Property | Value |
---|---|
Filename | |
Creation Timestamp | 2012-05-10 07:05:22 |
MD5 | 31e8d7b070dcc6cd92cec9d6d2254afe |
SHA1 | 2ea7907525b8375457235c3d85a928dcd5354df2 |
SHA256 | 33c6c622464f80a8d8017a03ff3aa196840da8bb03bfb5212b51612b5cf953dc |
Authentihash MD5 | 3c96154a55e5b0cb40f5c0500639b4a7 |
Authentihash SHA1 | 4f812a2781379912292efed09e43292117753dbb |
Authentihash SHA256 | 548c44566d19ba0975c9a22e7b592fda45bfa8831e56f55c1c3e7241d84dd175 |
RichPEHeaderHash MD5 | bd87ea0955778a277b3f9ae3a8975d88 |
RichPEHeaderHash SHA1 | d34cad0a1be5a7f5774e9832791e55475ad18a0a |
RichPEHeaderHash SHA256 | 9527799d818cd48b11774da7ee7831a449f1b5fc91cdd308cdb620c03a0d419a |
Company | REALiX(tm) |
Description | HWiNFO IA64 Kernel Driver |
Product | HWiNFO IA64 Kernel Driver |
OriginalFilename | HWiNFO64I.SYS |
Certificates
Expand
Certificate 3825d7faf861af9ef490e726b5d65ad5
Field | Value |
---|---|
ToBeSigned (TBS) MD5 | d6c7684e9aaa508cf268335f83afe040 |
ToBeSigned (TBS) SHA1 | 18066d20ad92409c567cdfde745279ff71c75226 |
ToBeSigned (TBS) SHA256 | a612fb22ce8be6dab75e47c98508f98496583e79c9c97b936a8caee9ea9f3fff |
Subject | C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services Signer , G2 |
ValidFrom | 2007-06-15 00:00:00 |
ValidTo | 2012-06-14 23:59:59 |
Signature | 50c54bc82480dfe40d24c2de1ab1a102a1a6822d0c831581370a820e2cb05a1761b5d805fe88dbf19191b3561a40a6eb92be3839b07536743a984fe437ba9989ca95421db0b9c7a08d57e0fad5640442354e01d133a217c84daa27c7f2e1864c02384d8378c6fc53e0ebe00687dda4969e5e0c98e2a5bebf8285c360e1dfad28d8c7a54b64dac71b5bbdac3908d53822a1338b2f8a9aebbc07213f44410907b5651c24bc48d34480eba1cfc902b414cf54c716a3805cf9793e5d727d88179e2c43a2ca53ce7d3df62a3ab84f9400a56d0a835df95e53f418b3570f70c3fbf5ad95a00e17dec4168060c90f2b6e8604f1ebf47827d105c5ee345b5eb94932f233 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | False |
SerialNumber | 3825d7faf861af9ef490e726b5d65ad5 |
Version | 3 |
Certificate 47bf1995df8d524643f7db6d480d31a4
Field | Value |
---|---|
ToBeSigned (TBS) MD5 | 518d2ea8a21e879c942d504824ac211c |
ToBeSigned (TBS) SHA1 | 21ce87d827077e61abddf2beba69fde5432ea031 |
ToBeSigned (TBS) SHA256 | 1ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7 |
Subject | C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA |
ValidFrom | 2003-12-04 00:00:00 |
ValidTo | 2013-12-03 23:59:59 |
Signature | 4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 47bf1995df8d524643f7db6d480d31a4 |
Version | 3 |
Certificate 010000000001228403475b
Field | Value |
---|---|
ToBeSigned (TBS) MD5 | c08c341aadc50a4843dc7f12d2b7dda6 |
ToBeSigned (TBS) SHA1 | 0077567a36c455505f2cfed87b2e47d6e836fb9e |
ToBeSigned (TBS) SHA256 | 5b17af75beca4abe098882f6b4fe2ed4975f428d81b964c648b1ac5df313233b |
Subject | C=SK, L=Bratislava, O=REALiX, CN=REALiX |
ValidFrom | 2009-07-16 13:59:23 |
ValidTo | 2012-07-16 13:59:20 |
Signature | 8df4772e78f08e0872af4bc472c4ee3c2f5ece224e8b2184bf7d965af06b1c82548b3f8593f824afe1bc343a0318e42379118602ff1253b7763526d857be6cdeafe2ac497de87a76fbb6fb1fd3bbabc84f0873d357a0b9d7d51d373db582a2300f87f5004635ccd1d8d519211406cc91c5724895cdf00f3cc4cfb8f907e37a048f47a1949e92e5a2faf60149ea1d4fdbbc3a2a5e224c1163f5023b4db7611cc916601d3ca8dc74fb99cd013033777a0a3f0a4ab88c67327c9aeb1489ac814b76d3fc67e293b58e39daf6506abae275224a72b4fb1c8c7b03b4d788a93baa902be4a346aec10f6c2c64b4cd0a61286eb8c42f9b2a25277a16a0a11af612dd02af |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | False |
SerialNumber | 010000000001228403475b |
Version | 3 |
Certificate 0400000000011e44a5e24e
Field | Value |
---|---|
ToBeSigned (TBS) MD5 | 1523b60530a241a9dc96e8890e42a0fa |
ToBeSigned (TBS) SHA1 | 879269f3f467a6d59641960a62fe9cb419355ff6 |
ToBeSigned (TBS) SHA256 | 6811f3e33268aef810dc3277f8f9356adcbc3c36446a0420593b82f3cd526022 |
Subject | C=BE, O=GlobalSign nv,sa, OU=Primary Object Publishing CA, CN=GlobalSign Primary Object Publishing CA |
ValidFrom | 1999-01-28 13:00:00 |
ValidTo | 2017-01-27 12:00:00 |
Signature | 4016df43e479ce76f248f698483061e2f1b452708ed8c612214d4f28831a648e03f731840f1f01d4a418fc008b2c6f1bb837fa4b97c05727b83109267832eef4e45912bd45a159e23511c0d6fc1e987ad982f990f36e07eeb0939acb31ed2c17bc921afa92cd821e2f0f31d328c03ce81c2926ab5a8d9fa1f0303289b68e516f8b5b90ad21f3f4209c909bb0ac2b37161e1db859bb49a63b75ae99d9b64b870194df91e1720e75079fcb05b59e7226fc2e21f5f62377eb6614d3ca3deae6f20b40ae553d02718821eb6a04b0945e9d9274ef292ebd4a4d85a4233ce31066901d3b63d23c481030e9e35cb67729ff3406f27da103406617df628d2b34a7426725 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 0400000000011e44a5e24e |
Version | 3 |
Certificate 0400000000011e44a5ecbe
Field | Value |
---|---|
ToBeSigned (TBS) MD5 | 16fb30314f4f5ff4dac603580f605778 |
ToBeSigned (TBS) SHA1 | 55c862df1f775f6a4c8e4f963115962a5cffc4ee |
ToBeSigned (TBS) SHA256 | aec84e1206957180ccf4e598fa10864ef4ee18ff9fc126b9a54af79c618f0492 |
Subject | C=BE, O=GlobalSign nv,sa, OU=ObjectSign CA, CN=GlobalSign ObjectSign CA |
ValidFrom | 2004-01-22 10:00:00 |
ValidTo | 2017-01-27 11:00:00 |
Signature | 762e2fe996fef4c3678bf1b07e321701ddb41c0f9e42d179569684be68afa554dbc7a9b55981d41cded9606baec05214fbab2b8e75f853ad91308efc04e4c58803d13f1861eab3d2b1d899f0754509ce7874d4d79e70bd120be405b64d3cf6af38c2881858a7958e7d1671e9b40df726a98f55de60ebc48d046b7b068feefea9c9c80a64240169df2f182058aa3e854c64e3e3832f860d4cf076a982c464981ec3cf5c7c863ec2ee5e9268b1483c857959e93bb4de5123d26648d1f7db967b82fac971e4caa7baca47c34b9183d3cab18f39bb38cccdc14caa9a6353051e1dd75377054d8f8ff7679b5ecebfdc4905ff7ef55180a01638d8b680a0514facf698 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 0400000000011e44a5ecbe |
Version | 3 |
Certificate 610b7f6b000000000019
Field | Value |
---|---|
ToBeSigned (TBS) MD5 | 4798d55be7663a75649cda4dedc686ef |
ToBeSigned (TBS) SHA1 | 0f1ab2937b245d9466ea6f9bf056a5942e3989cf |
ToBeSigned (TBS) SHA256 | ef14ea05bb066ee9f4188196dd69cd769b283ac4d7555db52f5e76922d3456e1 |
Subject | C=BE, O=GlobalSign nv,sa, OU=Root CA, CN=GlobalSign Root CA |
ValidFrom | 2006-05-23 17:00:51 |
ValidTo | 2016-05-23 17:10:51 |
Signature | 13c56c5e077f3c57ff9b315f3fbd955425c679f92c31034d64694b56d95b976f7cf3f0d024657538639813701613f7a701f1c623e085866c0bf080945a75e87ce41e92b473bfc1b3a7b00bd31884cbcc09a35c9c4f3eb03a9c2d1bc404ef9737966fe5ecbaac6ab3d4e23cdf8b25e7acbc624531dda40a72e41bf8784301ccba3914de5d90aed85acf5eca46815133d5a60e5867d3d8665888169beeb11acaad91138421da9a6e20efda007428bac95ff34d5dc3da25692554ea44bcc39b29331cd63c961f8781c553d72a2733d42e197c08586ddb4e1999a9ea5ff39a9d8c513a5a5cbd2fa908359b54a7db351a521633343aa380046afdb4838cad90cf0c3a6596ec334e1826b849bbeb8192ff134d324b23c733e7b6716b15f69c80e6bcb76cbe41d5033a7133150050743b0e5df996aaed903eab134c809926bc38a5eb0236891db620be83ab10f8199ed76379d4aeb12f6136f94a4ba833c70e7241f9f1b1907eae46efde397b75a0411459041d42bc4788b8130e05fa1df0808dff70c677d84bdc460e231a72d5bfdefeaaae69583cfc5c46e4d5819a8b6e6559771a32a590a6b6649364fd0753c9a0de28ad2a6cc638d181ce98f54019e92c1743a4265fd3443053e41d02baa40a2f16dd7a60275242bbad98372897e4b8d27911e3108c48d5305d0a0c52def588ea8d1a2d67c9f4801484b7850cd16628a5c66f2461 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 610b7f6b000000000019 |
Version | 3 |
Imports
Expand
- ntoskrnl.exe
- HAL.dll
Imported Functions
Expand
- IofCompleteRequest
- ZwClose
- ZwDeviceIoControlFile
- ZwOpenFile
- RtlInitUnicodeString
- IoGetDeviceObjectPointer
- RtlAnsiStringToUnicodeString
- RtlInitAnsiString
- KeLowerIrql
- KeRaiseIrql
- KeInitializeEvent
- IoDeleteDevice
- IoDeleteSymbolicLink
- RtlFreeUnicodeString
- ObfDereferenceObject
- ExFreePoolWithTag
- MmUnmapIoSpace
- ExInterlockedRemoveHeadList
- IoCreateSymbolicLink
- IoCreateDevice
- KeTickCount
- IoAllocateIrp
- IofCallDriver
- KeWaitForSingleObject
- IoFreeIrp
- KeSetEvent
- KeAcquireSpinLockRaiseToDpc
- KeReleaseSpinLock
- MmMapIoSpace
- ExAllocatePoolWithTag
- __C_specific_handler
- ExInterlockedInsertTailList
- READ_PORT_UCHAR
- READ_PORT_ULONG
- READ_PORT_USHORT
- HalGetBusDataByOffset
- WRITE_PORT_ULONG
- WRITE_PORT_USHORT
- HalSetBusDataByOffset
- HalCallPal
- KeStallExecutionProcessor
- WRITE_PORT_UCHAR
Exported Functions
Expand
Sections
Expand
- .text
- .rdata
- .pdata
- .srdata
- .sdata
- .data
- INIT
- .rsrc
- .reloc
Signature
Expand
{
"Certificates": [
{
"IsCertificateAuthority": false,
"SerialNumber": "3825d7faf861af9ef490e726b5d65ad5",
"Signature": "50c54bc82480dfe40d24c2de1ab1a102a1a6822d0c831581370a820e2cb05a1761b5d805fe88dbf19191b3561a40a6eb92be3839b07536743a984fe437ba9989ca95421db0b9c7a08d57e0fad5640442354e01d133a217c84daa27c7f2e1864c02384d8378c6fc53e0ebe00687dda4969e5e0c98e2a5bebf8285c360e1dfad28d8c7a54b64dac71b5bbdac3908d53822a1338b2f8a9aebbc07213f44410907b5651c24bc48d34480eba1cfc902b414cf54c716a3805cf9793e5d727d88179e2c43a2ca53ce7d3df62a3ab84f9400a56d0a835df95e53f418b3570f70c3fbf5ad95a00e17dec4168060c90f2b6e8604f1ebf47827d105c5ee345b5eb94932f233",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services Signer , G2",
"TBS": {
"MD5": "d6c7684e9aaa508cf268335f83afe040",
"SHA1": "18066d20ad92409c567cdfde745279ff71c75226",
"SHA256": "a612fb22ce8be6dab75e47c98508f98496583e79c9c97b936a8caee9ea9f3fff",
"SHA384": "35c249d6ad0261a6229b2a727067ac6ba32a5d24b30b9249051f748c7735fbe2ec2ef26a702c50df1790fbe32a65aee7"
},
"ValidFrom": "2007-06-15 00:00:00",
"ValidTo": "2012-06-14 23:59:59",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "47bf1995df8d524643f7db6d480d31a4",
"Signature": "4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA",
"TBS": {
"MD5": "518d2ea8a21e879c942d504824ac211c",
"SHA1": "21ce87d827077e61abddf2beba69fde5432ea031",
"SHA256": "1ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7",
"SHA384": "53e346bbde23779a5d116cc9d86fdd71c97b1f1b343439f8a11aa1d3c87af63864bb8488a5aeb2d0c26a6a1e0b15f03f"
},
"ValidFrom": "2003-12-04 00:00:00",
"ValidTo": "2013-12-03 23:59:59",
"Version": 3
},
{
"IsCertificateAuthority": false,
"SerialNumber": "010000000001228403475b",
"Signature": "8df4772e78f08e0872af4bc472c4ee3c2f5ece224e8b2184bf7d965af06b1c82548b3f8593f824afe1bc343a0318e42379118602ff1253b7763526d857be6cdeafe2ac497de87a76fbb6fb1fd3bbabc84f0873d357a0b9d7d51d373db582a2300f87f5004635ccd1d8d519211406cc91c5724895cdf00f3cc4cfb8f907e37a048f47a1949e92e5a2faf60149ea1d4fdbbc3a2a5e224c1163f5023b4db7611cc916601d3ca8dc74fb99cd013033777a0a3f0a4ab88c67327c9aeb1489ac814b76d3fc67e293b58e39daf6506abae275224a72b4fb1c8c7b03b4d788a93baa902be4a346aec10f6c2c64b4cd0a61286eb8c42f9b2a25277a16a0a11af612dd02af",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=SK, L=Bratislava, O=REALiX, CN=REALiX",
"TBS": {
"MD5": "c08c341aadc50a4843dc7f12d2b7dda6",
"SHA1": "0077567a36c455505f2cfed87b2e47d6e836fb9e",
"SHA256": "5b17af75beca4abe098882f6b4fe2ed4975f428d81b964c648b1ac5df313233b",
"SHA384": "b0ad18a16f199f8ee3efc9bc5d21bb209674a4e3d1013b7943c08eeae9b47ce706da1fd8707f86dbd31651ad4a2e886c"
},
"ValidFrom": "2009-07-16 13:59:23",
"ValidTo": "2012-07-16 13:59:20",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "0400000000011e44a5e24e",
"Signature": "4016df43e479ce76f248f698483061e2f1b452708ed8c612214d4f28831a648e03f731840f1f01d4a418fc008b2c6f1bb837fa4b97c05727b83109267832eef4e45912bd45a159e23511c0d6fc1e987ad982f990f36e07eeb0939acb31ed2c17bc921afa92cd821e2f0f31d328c03ce81c2926ab5a8d9fa1f0303289b68e516f8b5b90ad21f3f4209c909bb0ac2b37161e1db859bb49a63b75ae99d9b64b870194df91e1720e75079fcb05b59e7226fc2e21f5f62377eb6614d3ca3deae6f20b40ae553d02718821eb6a04b0945e9d9274ef292ebd4a4d85a4233ce31066901d3b63d23c481030e9e35cb67729ff3406f27da103406617df628d2b34a7426725",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=BE, O=GlobalSign nv,sa, OU=Primary Object Publishing CA, CN=GlobalSign Primary Object Publishing CA",
"TBS": {
"MD5": "1523b60530a241a9dc96e8890e42a0fa",
"SHA1": "879269f3f467a6d59641960a62fe9cb419355ff6",
"SHA256": "6811f3e33268aef810dc3277f8f9356adcbc3c36446a0420593b82f3cd526022",
"SHA384": "92f5e55d6eb6d965c1b698e56cbb8087d80eda1a24eb6ed178abeddafe2fcf524e9f8311ca232be7f5b4555b89b97c6b"
},
"ValidFrom": "1999-01-28 13:00:00",
"ValidTo": "2017-01-27 12:00:00",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "0400000000011e44a5ecbe",
"Signature": "762e2fe996fef4c3678bf1b07e321701ddb41c0f9e42d179569684be68afa554dbc7a9b55981d41cded9606baec05214fbab2b8e75f853ad91308efc04e4c58803d13f1861eab3d2b1d899f0754509ce7874d4d79e70bd120be405b64d3cf6af38c2881858a7958e7d1671e9b40df726a98f55de60ebc48d046b7b068feefea9c9c80a64240169df2f182058aa3e854c64e3e3832f860d4cf076a982c464981ec3cf5c7c863ec2ee5e9268b1483c857959e93bb4de5123d26648d1f7db967b82fac971e4caa7baca47c34b9183d3cab18f39bb38cccdc14caa9a6353051e1dd75377054d8f8ff7679b5ecebfdc4905ff7ef55180a01638d8b680a0514facf698",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=BE, O=GlobalSign nv,sa, OU=ObjectSign CA, CN=GlobalSign ObjectSign CA",
"TBS": {
"MD5": "16fb30314f4f5ff4dac603580f605778",
"SHA1": "55c862df1f775f6a4c8e4f963115962a5cffc4ee",
"SHA256": "aec84e1206957180ccf4e598fa10864ef4ee18ff9fc126b9a54af79c618f0492",
"SHA384": "a2b0c7b9ffe6e8244a4662099132406aea0a47889ecde7b336c4f09296da2ffbb3718597a0fb570bd1e97e88a24f8fbb"
},
"ValidFrom": "2004-01-22 10:00:00",
"ValidTo": "2017-01-27 11:00:00",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "610b7f6b000000000019",
"Signature": "13c56c5e077f3c57ff9b315f3fbd955425c679f92c31034d64694b56d95b976f7cf3f0d024657538639813701613f7a701f1c623e085866c0bf080945a75e87ce41e92b473bfc1b3a7b00bd31884cbcc09a35c9c4f3eb03a9c2d1bc404ef9737966fe5ecbaac6ab3d4e23cdf8b25e7acbc624531dda40a72e41bf8784301ccba3914de5d90aed85acf5eca46815133d5a60e5867d3d8665888169beeb11acaad91138421da9a6e20efda007428bac95ff34d5dc3da25692554ea44bcc39b29331cd63c961f8781c553d72a2733d42e197c08586ddb4e1999a9ea5ff39a9d8c513a5a5cbd2fa908359b54a7db351a521633343aa380046afdb4838cad90cf0c3a6596ec334e1826b849bbeb8192ff134d324b23c733e7b6716b15f69c80e6bcb76cbe41d5033a7133150050743b0e5df996aaed903eab134c809926bc38a5eb0236891db620be83ab10f8199ed76379d4aeb12f6136f94a4ba833c70e7241f9f1b1907eae46efde397b75a0411459041d42bc4788b8130e05fa1df0808dff70c677d84bdc460e231a72d5bfdefeaaae69583cfc5c46e4d5819a8b6e6559771a32a590a6b6649364fd0753c9a0de28ad2a6cc638d181ce98f54019e92c1743a4265fd3443053e41d02baa40a2f16dd7a60275242bbad98372897e4b8d27911e3108c48d5305d0a0c52def588ea8d1a2d67c9f4801484b7850cd16628a5c66f2461",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=BE, O=GlobalSign nv,sa, OU=Root CA, CN=GlobalSign Root CA",
"TBS": {
"MD5": "4798d55be7663a75649cda4dedc686ef",
"SHA1": "0f1ab2937b245d9466ea6f9bf056a5942e3989cf",
"SHA256": "ef14ea05bb066ee9f4188196dd69cd769b283ac4d7555db52f5e76922d3456e1",
"SHA384": "6e7450a139856aeda6fa6284ff89b3752a9b646e096b4d33dd7e8e727742a2111481531581c0aa2cda0338e22cfdbad3"
},
"ValidFrom": "2006-05-23 17:00:51",
"ValidTo": "2016-05-23 17:10:51",
"Version": 3
}
],
"CertificatesInfo": "",
"Signer": [
{
"Issuer": "C=BE, O=GlobalSign nv,sa, OU=ObjectSign CA, CN=GlobalSign ObjectSign CA",
"SerialNumber": "010000000001228403475b",
"Version": 1
}
],
"SignerInfo": ""
}
last_updated: 2024-09-26