Description
semav6msr.sys is a vulnerable driver and more information will be added as found.
- UUID: 142453a2-a24d-4b35-8922-6d5939f1c0fc
- Created: 2023-01-09
- Author: Michael Haag
- Acknowledgement: |
DownloadBlock
This download link contains the vulnerable driver!
Commands
sc.exe create semav6msr.sys binPath=C:\windows\temp\semav6msr.sys type=kernel && sc.exe start semav6msr.sys
Use Case | Privileges | Operating System |
---|
Elevate privileges | kernel | Windows 10 |
Detections
Sigma 🛡️
Expand
Names
detects loading using name only
Hashes
detects loading using hashes only
Resources
https://github.com/eclypsium/Screwed-Drivers/blob/master/DRIVERS.mdhttps://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rulesKnown Vulnerable Samples
Download
Certificates
Expand
Certificate 330000b6712f575e402cf8708400020000b671
Field | Value |
---|
ToBeSigned (TBS) MD5 | 0ddb50f4d347b1641521dfecf6525c50 |
ToBeSigned (TBS) SHA1 | 32a2b77cbfe58b3804618edd9435588f24b92695 |
ToBeSigned (TBS) SHA256 | 65c1bffcd837ffb534b0641fb137580d7bcf46c905d4c946fbc1fb27281082f2 |
Subject | C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel(R) Code Signing External |
ValidFrom | 2015-04-16 17:22:30 |
ValidTo | 2016-04-15 17:22:30 |
Signature | 47ef93216b05a90df10512c9bb24dc20894c255a5943bd567c461f9d76dd3bfeebd65fa524ed3774b4894150c798d9647d64b8c45e0516cf03bdbc819185f494db80e56758fbad4b62f3aed983120533327039d23d550ee32f40d785fa8624a10bbcc4bf531db4c07f1a793be86b015098a62884970e3e58268820f7698ae23d609d2e20b4a75ebacbc98f01edb71c12049594593fd65f62c62b59ac0f269eeb113185fb7ae56cc8da9bd4a9abb7d3332d8ce732638afb3b2b786e56c256bf6211362b498b348b7e370c638b634d7fbd947b57e5c9f923612869cf1d9737fc51075ae92763045c2d2fed944763c14521521bab177c2aad1301d43a8679187077 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | False |
SerialNumber | 330000b6712f575e402cf8708400020000b671 |
Version | 3 |
Certificate 612cff88000100000010
Field | Value |
---|
ToBeSigned (TBS) MD5 | da9a02953cdcc039174d11b07dd2967d |
ToBeSigned (TBS) SHA1 | 568cfca269ff49615d305e680988337f0a90bc32 |
ToBeSigned (TBS) SHA256 | fad628f5236458a9116a99f2d64fb9131a28f9942fca6239a5e7be0dddf4ce9f |
Subject | C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel External Basic Issuing CA 3B |
ValidFrom | 2013-02-08 22:21:23 |
ValidTo | 2018-02-08 22:31:23 |
Signature | 47bb93e603b1d9570eff60e90fc75e86e623f7defa6dc27732ef23f68fcc6f2572d4a94bad11a273bb8bd2b7b8879474890ccc5cea3a9ac0753a97597c22003d7ac7c55be8d49313ec8f94cda833dfa4d79aa1c8d8a3b4497e173a02e96656978d16b470abbc6b1048e7457b13c74d05bca02c0516be067ef679678f9c3454e67eea197714f19d3b55e4339f69bba7a72254512c677d0452aa7b66dea96aad8ca15c7939cd1c85ec890699854627a001576e93365145e15a3a59af5b41f9709dc4160e05e795b401b4931a590b8a31f7b648c86af6228c9e92286fa893b4a772533ada2cfad43dbf09237fdfcc652ad091aa5031c865f53858d4b39be6311008 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 612cff88000100000010 |
Version | 3 |
Certificate 79174aa9141736fe15a7ca9f2cff4588
Field | Value |
---|
ToBeSigned (TBS) MD5 | 6ce466d55ab160317ee9b13522c2a82a |
ToBeSigned (TBS) SHA1 | 53b052ba209c525233293274854b264bc0f68b73 |
ToBeSigned (TBS) SHA256 | f71790e057380a0cbafdfc25bc8b3dafd6cfbeb01077bb3d8194e91254a2fc9b |
Subject | C=US, O=Intel Corporation, CN=Intel External Basic Policy CA |
ValidFrom | 2013-02-01 00:00:00 |
ValidTo | 2020-05-30 10:48:38 |
Signature | 586fbfcd43074213fcb8d0ad8121f28a6fef87bc268a7c00bd680c2b19642c1167b3a9d9790aac395d6500163b53466ea2a6b56799dbe8bfa225ae049511093a2fdeacb73db8bc017430804748544ca0fb6ba8b8a284b7f434e57bcedc5278f4316d4251ae87bf94acbe9616fb55e5798264fdac5038e4dccb812ce7776f9d9b235c7d0403f4079e7ed457e266944debb55c5c629e8c2d83e64614e2a11380fddae0862711922bbd87174fcb19184b5e8ce60dd98f7d23766fa4ffa0ba3de36d37d62638e81a9c2392c8561f1a1a8e00d633a66b95fa821e740b0fa486df23337c9e3614b35ce2a3ed48a08e28f1d74cf6c09bb4f53ca3e5a863a22c08a5d5fe |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 79174aa9141736fe15a7ca9f2cff4588 |
Version | 3 |
Certificate 69b2d1ccf02e20dcc95c62894f7f9e5f5fc057bf
Field | Value |
---|
ToBeSigned (TBS) MD5 | 4e0fbd79a99e4a55f97ef41efee38a9f |
ToBeSigned (TBS) SHA1 | 114f36d5f22b84de97893469fc00b7035b3ef734 |
ToBeSigned (TBS) SHA256 | f6dd9683708786a413d4d6a3661fa4e4aeb328adbd181b398b5b6aa02bb0bc16 |
Subject | C=BM, O=QuoVadis Limited, CN=QuoVadis Issuing CA G4 |
ValidFrom | 2014-05-30 16:35:55 |
ValidTo | 2021-03-17 18:33:33 |
Signature | b9f61352b517a72a4d84774309a4dba067b4600e42f403bdc4ff2c5a0f902e78c563c84aec27f67ce429d0cf6018fa6822da0252760df21754c6f6081ea1cc82e4c33a6d99227cc4c077b4e6052047934039cfdc55adc346af294d799c644c205f8a1c56fc46a05fcb98dd917a39b4afc477996b9eacde6f2d79ea7fd7132498521cfd693eed72ac3fd0b4011914edb0f0cbf39c5114238cc7dc697d328196e41d478f017694833e888d925b1858986903c7f5d3f2615250eb34a0fd2630300fb5fd70e7272c370b1cf3e71ea62c0743b64b885e971fc1307d60642af30c7068445163599fdb57c21fff80e5c21192d82fefd51743ff642d64845c521a63c267 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.11 |
IsCertificateAuthority | True |
SerialNumber | 69b2d1ccf02e20dcc95c62894f7f9e5f5fc057bf |
Version | 3 |
Certificate 385dccec5fe14d3974c9591a3ab1c2caad188c2d
Field | Value |
---|
ToBeSigned (TBS) MD5 | 4d35161b8be0a29812bb748b548e94b1 |
ToBeSigned (TBS) SHA1 | bf27e048115892363598dec245759aa7529eb154 |
ToBeSigned (TBS) SHA256 | d5c67eb0b73915a6f12dbe19f662205172cc9c97b9988b78a07f14c3b7e1e2b0 |
Subject | C=US, ST=CA, L=Santa Clara, O=Intel Corporation, OU=Authenticode, OU=Thales TSS ESN:A6A7,71B2,73F1, CN=Timestamp.intel.com |
ValidFrom | 2014-12-09 21:30:38 |
ValidTo | 2017-12-09 21:30:35 |
Signature | 946aee51ab48079d01882edffbe887d87828778d30da382cacb0c1d5a4c0fc8437badc00c2c16454a82564ba4bcf776b79eb1feedc4e4ccd02514bbaea7c9b755d88a43a9493e07ebaa22358f95dabd995d4c572134e266dfb4bbd3a4c95c3191abbba7b1d1d0587c4a3e3911e1037fda9dacd9fe9c63383f0c21ece4e829c9c7e40e96a64139dfda69d0255a9588dbff28bfec8d343ca34decb755531b384a6cf388a5f06685870f79a321c3fc0e221cf8bba3b1e0b5d0486eb02f6e9008ebc4c2741215451b0ba6e1ec9d9e202b4e38c9184838c5e948df1c051aa0d0122c32810c11cb3458735c726b9e252558e0257b3360f85ec5ba949c3a3f8841c1938b5661ea9bde4f0894b40bd9567e89b17b373faaeeb1de7b7b27e4f52b46add679ac3dbd35bbdb48c9c6fb7aae98058c99002e9e53e0a0d5d88d21289ecce372c63afc6a08ca8f61d013695e40c48b67b9725dab9607e3f80e82d2f56afdd10b453d2e82d488b69a7ca63ced68f9bdc855d62fd79103e8b4abfef936e430dee4ea4e2a199a43a03783e4e4489807170fd63f12272c865861419fe6f2c474948f8749cb696446054b3e0913bba0f5483640dd33e955421beb4574f8398398e1323b3f24f83f640c5146aa90c6e314d6ccdcf8d21bbd09e4ff883e369adc6b742c021d833a2d4fefbba1080d8ca8eade080908a626fb8396451e2616afc943e1f74 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.11 |
IsCertificateAuthority | True |
SerialNumber | 385dccec5fe14d3974c9591a3ab1c2caad188c2d |
Version | 3 |
Certificate 3300000035d8d5595b0671412b000000000035
Field | Value |
---|
ToBeSigned (TBS) MD5 | 3d488d41aaeb5661974952080abef2fd |
ToBeSigned (TBS) SHA1 | df01e35e6befc7d65625319f17397b861e618d56 |
ToBeSigned (TBS) SHA256 | 3d6ef38b5d26773dc77392e415e88b3a744b30ea9f2081e2a992b5818db2f0c4 |
Subject | C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root |
ValidFrom | 2013-08-15 20:26:30 |
ValidTo | 2023-08-15 20:36:30 |
Signature | 362ba2f2e1331fe493f7f26985c6640ec99b632fe4703798fd94ec7bcff8a14246f9ed6a4e8d34693605557a1ebbad8c99429606e925a82684bec1bf16a97caa5b04b7fdd1c0f402be28edf577c79bfe3af6e8c17bd382abfa144ecf2bcfe5d5b54840b1a38f838bad2b2553aba634cef243f74f2ce9dd1e4e5ab6bae83b10992400bc50fd78f6e523a8899493f7b74130374a57b7e644d9c9df9905aa44fc74af8264cc07cb01b609c32ee3e832a7b49f4178c7a184365462f2ec150ac8ead084f8f1e06bf456125f95e0fcddb77693fe294a25e90400f1b4110ec9849edb177df51ea58e3629193a6d6c464bd7ab7024288d05a3d9d524f2f8a0d13c8239d4a8820e693a8109fc06f0c75933843693064191232c22a5a7012b50b428aedb46b0591b86b39b87e8494e390b6d14df4c03301e1f5f74aef55b590353ec9816e0d06235751b48b87d13e57a48b87752a40798253b069b7a4e6a6f44864f144f2779273d5073414c9c413edd290c73b1c7fb1f760c176504ebd25010924149ece4067d3615446f89bf697df94d40c13a98b6a07e31d2b5aecafb53d53f5086cd5e933b6d5d7c9a3f3ff7a9255884dd114900a2c7c89e37dd778e6d718be05b81345d54baccf59347886de7ef5be228e4801b40e40f2ad17f2315655aac9994433f465526d6c4fa8895e2919aa32d0b85deac8ce0f967709f71790231f761a229c4 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 3300000035d8d5595b0671412b000000000035 |
Version | 3 |
Imports
Expand
Imported Functions
Expand
- KeQueryActiveProcessors
- KeQueryActiveProcessorCount
- IoDeleteSymbolicLink
- KeSetSystemAffinityThreadEx
- RtlInitUnicodeString
- IoDeleteDevice
- MmUnmapIoSpace
- MmMapIoSpace
- IofCompleteRequest
- KeRevertToUserAffinityThreadEx
- IoCreateSymbolicLink
- IoCreateDevice
- RtlAssert
- DbgPrint
- KeBugCheckEx
- __C_specific_handler
Exported Functions
Expand
Sections
Expand
- .text
- .rdata
- .data
- .pdata
- PAGE
- INIT
Signature
Expand
{
"Certificates": [
{
"IsCertificateAuthority": false,
"SerialNumber": "330000b6712f575e402cf8708400020000b671",
"Signature": "47ef93216b05a90df10512c9bb24dc20894c255a5943bd567c461f9d76dd3bfeebd65fa524ed3774b4894150c798d9647d64b8c45e0516cf03bdbc819185f494db80e56758fbad4b62f3aed983120533327039d23d550ee32f40d785fa8624a10bbcc4bf531db4c07f1a793be86b015098a62884970e3e58268820f7698ae23d609d2e20b4a75ebacbc98f01edb71c12049594593fd65f62c62b59ac0f269eeb113185fb7ae56cc8da9bd4a9abb7d3332d8ce732638afb3b2b786e56c256bf6211362b498b348b7e370c638b634d7fbd947b57e5c9f923612869cf1d9737fc51075ae92763045c2d2fed944763c14521521bab177c2aad1301d43a8679187077",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel(R) Code Signing External",
"TBS": {
"MD5": "0ddb50f4d347b1641521dfecf6525c50",
"SHA1": "32a2b77cbfe58b3804618edd9435588f24b92695",
"SHA256": "65c1bffcd837ffb534b0641fb137580d7bcf46c905d4c946fbc1fb27281082f2",
"SHA384": "078be3addebd5c1e84cb34f7d1a5144d42b3bb3049d08eb6b3024e3b667d782b7d73fac6481404672a5ba91822c971bc"
},
"ValidFrom": "2015-04-16 17:22:30",
"ValidTo": "2016-04-15 17:22:30",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "612cff88000100000010",
"Signature": "47bb93e603b1d9570eff60e90fc75e86e623f7defa6dc27732ef23f68fcc6f2572d4a94bad11a273bb8bd2b7b8879474890ccc5cea3a9ac0753a97597c22003d7ac7c55be8d49313ec8f94cda833dfa4d79aa1c8d8a3b4497e173a02e96656978d16b470abbc6b1048e7457b13c74d05bca02c0516be067ef679678f9c3454e67eea197714f19d3b55e4339f69bba7a72254512c677d0452aa7b66dea96aad8ca15c7939cd1c85ec890699854627a001576e93365145e15a3a59af5b41f9709dc4160e05e795b401b4931a590b8a31f7b648c86af6228c9e92286fa893b4a772533ada2cfad43dbf09237fdfcc652ad091aa5031c865f53858d4b39be6311008",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel External Basic Issuing CA 3B",
"TBS": {
"MD5": "da9a02953cdcc039174d11b07dd2967d",
"SHA1": "568cfca269ff49615d305e680988337f0a90bc32",
"SHA256": "fad628f5236458a9116a99f2d64fb9131a28f9942fca6239a5e7be0dddf4ce9f",
"SHA384": "5edeab0248f63cdc4c10b748618cd6fa4aa53ffb0ddfd51a2e35de2ea55a56822aa53fa734a46705655e8f5878b24ffd"
},
"ValidFrom": "2013-02-08 22:21:23",
"ValidTo": "2018-02-08 22:31:23",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "79174aa9141736fe15a7ca9f2cff4588",
"Signature": "586fbfcd43074213fcb8d0ad8121f28a6fef87bc268a7c00bd680c2b19642c1167b3a9d9790aac395d6500163b53466ea2a6b56799dbe8bfa225ae049511093a2fdeacb73db8bc017430804748544ca0fb6ba8b8a284b7f434e57bcedc5278f4316d4251ae87bf94acbe9616fb55e5798264fdac5038e4dccb812ce7776f9d9b235c7d0403f4079e7ed457e266944debb55c5c629e8c2d83e64614e2a11380fddae0862711922bbd87174fcb19184b5e8ce60dd98f7d23766fa4ffa0ba3de36d37d62638e81a9c2392c8561f1a1a8e00d633a66b95fa821e740b0fa486df23337c9e3614b35ce2a3ed48a08e28f1d74cf6c09bb4f53ca3e5a863a22c08a5d5fe",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, O=Intel Corporation, CN=Intel External Basic Policy CA",
"TBS": {
"MD5": "6ce466d55ab160317ee9b13522c2a82a",
"SHA1": "53b052ba209c525233293274854b264bc0f68b73",
"SHA256": "f71790e057380a0cbafdfc25bc8b3dafd6cfbeb01077bb3d8194e91254a2fc9b",
"SHA384": "c0cc37f9505ff2bab958c8ef1ea94736efae52bcf5948c866446c46b64fb9f5e603fbad4bc70270ae74e58ac8ab055f9"
},
"ValidFrom": "2013-02-01 00:00:00",
"ValidTo": "2020-05-30 10:48:38",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "69b2d1ccf02e20dcc95c62894f7f9e5f5fc057bf",
"Signature": "b9f61352b517a72a4d84774309a4dba067b4600e42f403bdc4ff2c5a0f902e78c563c84aec27f67ce429d0cf6018fa6822da0252760df21754c6f6081ea1cc82e4c33a6d99227cc4c077b4e6052047934039cfdc55adc346af294d799c644c205f8a1c56fc46a05fcb98dd917a39b4afc477996b9eacde6f2d79ea7fd7132498521cfd693eed72ac3fd0b4011914edb0f0cbf39c5114238cc7dc697d328196e41d478f017694833e888d925b1858986903c7f5d3f2615250eb34a0fd2630300fb5fd70e7272c370b1cf3e71ea62c0743b64b885e971fc1307d60642af30c7068445163599fdb57c21fff80e5c21192d82fefd51743ff642d64845c521a63c267",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=BM, O=QuoVadis Limited, CN=QuoVadis Issuing CA G4",
"TBS": {
"MD5": "4e0fbd79a99e4a55f97ef41efee38a9f",
"SHA1": "114f36d5f22b84de97893469fc00b7035b3ef734",
"SHA256": "f6dd9683708786a413d4d6a3661fa4e4aeb328adbd181b398b5b6aa02bb0bc16",
"SHA384": "a26fe570a01b0e15cf94b41ce48ebd39ed9e9d18493d4c117f0fbb5a5b33ed8ef06c069b9638dda957547f0b0645e447"
},
"ValidFrom": "2014-05-30 16:35:55",
"ValidTo": "2021-03-17 18:33:33",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "385dccec5fe14d3974c9591a3ab1c2caad188c2d",
"Signature": "946aee51ab48079d01882edffbe887d87828778d30da382cacb0c1d5a4c0fc8437badc00c2c16454a82564ba4bcf776b79eb1feedc4e4ccd02514bbaea7c9b755d88a43a9493e07ebaa22358f95dabd995d4c572134e266dfb4bbd3a4c95c3191abbba7b1d1d0587c4a3e3911e1037fda9dacd9fe9c63383f0c21ece4e829c9c7e40e96a64139dfda69d0255a9588dbff28bfec8d343ca34decb755531b384a6cf388a5f06685870f79a321c3fc0e221cf8bba3b1e0b5d0486eb02f6e9008ebc4c2741215451b0ba6e1ec9d9e202b4e38c9184838c5e948df1c051aa0d0122c32810c11cb3458735c726b9e252558e0257b3360f85ec5ba949c3a3f8841c1938b5661ea9bde4f0894b40bd9567e89b17b373faaeeb1de7b7b27e4f52b46add679ac3dbd35bbdb48c9c6fb7aae98058c99002e9e53e0a0d5d88d21289ecce372c63afc6a08ca8f61d013695e40c48b67b9725dab9607e3f80e82d2f56afdd10b453d2e82d488b69a7ca63ced68f9bdc855d62fd79103e8b4abfef936e430dee4ea4e2a199a43a03783e4e4489807170fd63f12272c865861419fe6f2c474948f8749cb696446054b3e0913bba0f5483640dd33e955421beb4574f8398398e1323b3f24f83f640c5146aa90c6e314d6ccdcf8d21bbd09e4ff883e369adc6b742c021d833a2d4fefbba1080d8ca8eade080908a626fb8396451e2616afc943e1f74",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, ST=CA, L=Santa Clara, O=Intel Corporation, OU=Authenticode, OU=Thales TSS ESN:A6A7,71B2,73F1, CN=Timestamp.intel.com",
"TBS": {
"MD5": "4d35161b8be0a29812bb748b548e94b1",
"SHA1": "bf27e048115892363598dec245759aa7529eb154",
"SHA256": "d5c67eb0b73915a6f12dbe19f662205172cc9c97b9988b78a07f14c3b7e1e2b0",
"SHA384": "8b0e411b3fc02dd3a8f5f7d248699a7d882c160a6e3753c1b223d2b0671a6d3f9efa4894172a3bfa3525787be2d6f20e"
},
"ValidFrom": "2014-12-09 21:30:38",
"ValidTo": "2017-12-09 21:30:35",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "3300000035d8d5595b0671412b000000000035",
"Signature": "362ba2f2e1331fe493f7f26985c6640ec99b632fe4703798fd94ec7bcff8a14246f9ed6a4e8d34693605557a1ebbad8c99429606e925a82684bec1bf16a97caa5b04b7fdd1c0f402be28edf577c79bfe3af6e8c17bd382abfa144ecf2bcfe5d5b54840b1a38f838bad2b2553aba634cef243f74f2ce9dd1e4e5ab6bae83b10992400bc50fd78f6e523a8899493f7b74130374a57b7e644d9c9df9905aa44fc74af8264cc07cb01b609c32ee3e832a7b49f4178c7a184365462f2ec150ac8ead084f8f1e06bf456125f95e0fcddb77693fe294a25e90400f1b4110ec9849edb177df51ea58e3629193a6d6c464bd7ab7024288d05a3d9d524f2f8a0d13c8239d4a8820e693a8109fc06f0c75933843693064191232c22a5a7012b50b428aedb46b0591b86b39b87e8494e390b6d14df4c03301e1f5f74aef55b590353ec9816e0d06235751b48b87d13e57a48b87752a40798253b069b7a4e6a6f44864f144f2779273d5073414c9c413edd290c73b1c7fb1f760c176504ebd25010924149ece4067d3615446f89bf697df94d40c13a98b6a07e31d2b5aecafb53d53f5086cd5e933b6d5d7c9a3f3ff7a9255884dd114900a2c7c89e37dd778e6d718be05b81345d54baccf59347886de7ef5be228e4801b40e40f2ad17f2315655aac9994433f465526d6c4fa8895e2919aa32d0b85deac8ce0f967709f71790231f761a229c4",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root",
"TBS": {
"MD5": "3d488d41aaeb5661974952080abef2fd",
"SHA1": "df01e35e6befc7d65625319f17397b861e618d56",
"SHA256": "3d6ef38b5d26773dc77392e415e88b3a744b30ea9f2081e2a992b5818db2f0c4",
"SHA384": "ac7c06916fe4a00307834b2499f12799d3fe463c2e63d1881df669a2786745beeee2b3a7d87cd6bc9e4fe293c22e5a59"
},
"ValidFrom": "2013-08-15 20:26:30",
"ValidTo": "2023-08-15 20:36:30",
"Version": 3
}
],
"CertificatesInfo": "",
"Signer": [
{
"Issuer": "C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel External Basic Issuing CA 3B",
"SerialNumber": "330000b6712f575e402cf8708400020000b671",
"Version": 1
}
],
"SignerInfo": ""
}
Download
Certificates
Expand
Certificate 330000b6712f575e402cf8708400020000b671
Field | Value |
---|
ToBeSigned (TBS) MD5 | 0ddb50f4d347b1641521dfecf6525c50 |
ToBeSigned (TBS) SHA1 | 32a2b77cbfe58b3804618edd9435588f24b92695 |
ToBeSigned (TBS) SHA256 | 65c1bffcd837ffb534b0641fb137580d7bcf46c905d4c946fbc1fb27281082f2 |
Subject | C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel(R) Code Signing External |
ValidFrom | 2015-04-16 17:22:30 |
ValidTo | 2016-04-15 17:22:30 |
Signature | 47ef93216b05a90df10512c9bb24dc20894c255a5943bd567c461f9d76dd3bfeebd65fa524ed3774b4894150c798d9647d64b8c45e0516cf03bdbc819185f494db80e56758fbad4b62f3aed983120533327039d23d550ee32f40d785fa8624a10bbcc4bf531db4c07f1a793be86b015098a62884970e3e58268820f7698ae23d609d2e20b4a75ebacbc98f01edb71c12049594593fd65f62c62b59ac0f269eeb113185fb7ae56cc8da9bd4a9abb7d3332d8ce732638afb3b2b786e56c256bf6211362b498b348b7e370c638b634d7fbd947b57e5c9f923612869cf1d9737fc51075ae92763045c2d2fed944763c14521521bab177c2aad1301d43a8679187077 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | False |
SerialNumber | 330000b6712f575e402cf8708400020000b671 |
Version | 3 |
Certificate 612cff88000100000010
Field | Value |
---|
ToBeSigned (TBS) MD5 | da9a02953cdcc039174d11b07dd2967d |
ToBeSigned (TBS) SHA1 | 568cfca269ff49615d305e680988337f0a90bc32 |
ToBeSigned (TBS) SHA256 | fad628f5236458a9116a99f2d64fb9131a28f9942fca6239a5e7be0dddf4ce9f |
Subject | C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel External Basic Issuing CA 3B |
ValidFrom | 2013-02-08 22:21:23 |
ValidTo | 2018-02-08 22:31:23 |
Signature | 47bb93e603b1d9570eff60e90fc75e86e623f7defa6dc27732ef23f68fcc6f2572d4a94bad11a273bb8bd2b7b8879474890ccc5cea3a9ac0753a97597c22003d7ac7c55be8d49313ec8f94cda833dfa4d79aa1c8d8a3b4497e173a02e96656978d16b470abbc6b1048e7457b13c74d05bca02c0516be067ef679678f9c3454e67eea197714f19d3b55e4339f69bba7a72254512c677d0452aa7b66dea96aad8ca15c7939cd1c85ec890699854627a001576e93365145e15a3a59af5b41f9709dc4160e05e795b401b4931a590b8a31f7b648c86af6228c9e92286fa893b4a772533ada2cfad43dbf09237fdfcc652ad091aa5031c865f53858d4b39be6311008 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 612cff88000100000010 |
Version | 3 |
Certificate 79174aa9141736fe15a7ca9f2cff4588
Field | Value |
---|
ToBeSigned (TBS) MD5 | 6ce466d55ab160317ee9b13522c2a82a |
ToBeSigned (TBS) SHA1 | 53b052ba209c525233293274854b264bc0f68b73 |
ToBeSigned (TBS) SHA256 | f71790e057380a0cbafdfc25bc8b3dafd6cfbeb01077bb3d8194e91254a2fc9b |
Subject | C=US, O=Intel Corporation, CN=Intel External Basic Policy CA |
ValidFrom | 2013-02-01 00:00:00 |
ValidTo | 2020-05-30 10:48:38 |
Signature | 586fbfcd43074213fcb8d0ad8121f28a6fef87bc268a7c00bd680c2b19642c1167b3a9d9790aac395d6500163b53466ea2a6b56799dbe8bfa225ae049511093a2fdeacb73db8bc017430804748544ca0fb6ba8b8a284b7f434e57bcedc5278f4316d4251ae87bf94acbe9616fb55e5798264fdac5038e4dccb812ce7776f9d9b235c7d0403f4079e7ed457e266944debb55c5c629e8c2d83e64614e2a11380fddae0862711922bbd87174fcb19184b5e8ce60dd98f7d23766fa4ffa0ba3de36d37d62638e81a9c2392c8561f1a1a8e00d633a66b95fa821e740b0fa486df23337c9e3614b35ce2a3ed48a08e28f1d74cf6c09bb4f53ca3e5a863a22c08a5d5fe |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 79174aa9141736fe15a7ca9f2cff4588 |
Version | 3 |
Certificate 69b2d1ccf02e20dcc95c62894f7f9e5f5fc057bf
Field | Value |
---|
ToBeSigned (TBS) MD5 | 4e0fbd79a99e4a55f97ef41efee38a9f |
ToBeSigned (TBS) SHA1 | 114f36d5f22b84de97893469fc00b7035b3ef734 |
ToBeSigned (TBS) SHA256 | f6dd9683708786a413d4d6a3661fa4e4aeb328adbd181b398b5b6aa02bb0bc16 |
Subject | C=BM, O=QuoVadis Limited, CN=QuoVadis Issuing CA G4 |
ValidFrom | 2014-05-30 16:35:55 |
ValidTo | 2021-03-17 18:33:33 |
Signature | b9f61352b517a72a4d84774309a4dba067b4600e42f403bdc4ff2c5a0f902e78c563c84aec27f67ce429d0cf6018fa6822da0252760df21754c6f6081ea1cc82e4c33a6d99227cc4c077b4e6052047934039cfdc55adc346af294d799c644c205f8a1c56fc46a05fcb98dd917a39b4afc477996b9eacde6f2d79ea7fd7132498521cfd693eed72ac3fd0b4011914edb0f0cbf39c5114238cc7dc697d328196e41d478f017694833e888d925b1858986903c7f5d3f2615250eb34a0fd2630300fb5fd70e7272c370b1cf3e71ea62c0743b64b885e971fc1307d60642af30c7068445163599fdb57c21fff80e5c21192d82fefd51743ff642d64845c521a63c267 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.11 |
IsCertificateAuthority | True |
SerialNumber | 69b2d1ccf02e20dcc95c62894f7f9e5f5fc057bf |
Version | 3 |
Certificate 385dccec5fe14d3974c9591a3ab1c2caad188c2d
Field | Value |
---|
ToBeSigned (TBS) MD5 | 4d35161b8be0a29812bb748b548e94b1 |
ToBeSigned (TBS) SHA1 | bf27e048115892363598dec245759aa7529eb154 |
ToBeSigned (TBS) SHA256 | d5c67eb0b73915a6f12dbe19f662205172cc9c97b9988b78a07f14c3b7e1e2b0 |
Subject | C=US, ST=CA, L=Santa Clara, O=Intel Corporation, OU=Authenticode, OU=Thales TSS ESN:A6A7,71B2,73F1, CN=Timestamp.intel.com |
ValidFrom | 2014-12-09 21:30:38 |
ValidTo | 2017-12-09 21:30:35 |
Signature | 946aee51ab48079d01882edffbe887d87828778d30da382cacb0c1d5a4c0fc8437badc00c2c16454a82564ba4bcf776b79eb1feedc4e4ccd02514bbaea7c9b755d88a43a9493e07ebaa22358f95dabd995d4c572134e266dfb4bbd3a4c95c3191abbba7b1d1d0587c4a3e3911e1037fda9dacd9fe9c63383f0c21ece4e829c9c7e40e96a64139dfda69d0255a9588dbff28bfec8d343ca34decb755531b384a6cf388a5f06685870f79a321c3fc0e221cf8bba3b1e0b5d0486eb02f6e9008ebc4c2741215451b0ba6e1ec9d9e202b4e38c9184838c5e948df1c051aa0d0122c32810c11cb3458735c726b9e252558e0257b3360f85ec5ba949c3a3f8841c1938b5661ea9bde4f0894b40bd9567e89b17b373faaeeb1de7b7b27e4f52b46add679ac3dbd35bbdb48c9c6fb7aae98058c99002e9e53e0a0d5d88d21289ecce372c63afc6a08ca8f61d013695e40c48b67b9725dab9607e3f80e82d2f56afdd10b453d2e82d488b69a7ca63ced68f9bdc855d62fd79103e8b4abfef936e430dee4ea4e2a199a43a03783e4e4489807170fd63f12272c865861419fe6f2c474948f8749cb696446054b3e0913bba0f5483640dd33e955421beb4574f8398398e1323b3f24f83f640c5146aa90c6e314d6ccdcf8d21bbd09e4ff883e369adc6b742c021d833a2d4fefbba1080d8ca8eade080908a626fb8396451e2616afc943e1f74 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.11 |
IsCertificateAuthority | True |
SerialNumber | 385dccec5fe14d3974c9591a3ab1c2caad188c2d |
Version | 3 |
Certificate 3300000035d8d5595b0671412b000000000035
Field | Value |
---|
ToBeSigned (TBS) MD5 | 3d488d41aaeb5661974952080abef2fd |
ToBeSigned (TBS) SHA1 | df01e35e6befc7d65625319f17397b861e618d56 |
ToBeSigned (TBS) SHA256 | 3d6ef38b5d26773dc77392e415e88b3a744b30ea9f2081e2a992b5818db2f0c4 |
Subject | C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root |
ValidFrom | 2013-08-15 20:26:30 |
ValidTo | 2023-08-15 20:36:30 |
Signature | 362ba2f2e1331fe493f7f26985c6640ec99b632fe4703798fd94ec7bcff8a14246f9ed6a4e8d34693605557a1ebbad8c99429606e925a82684bec1bf16a97caa5b04b7fdd1c0f402be28edf577c79bfe3af6e8c17bd382abfa144ecf2bcfe5d5b54840b1a38f838bad2b2553aba634cef243f74f2ce9dd1e4e5ab6bae83b10992400bc50fd78f6e523a8899493f7b74130374a57b7e644d9c9df9905aa44fc74af8264cc07cb01b609c32ee3e832a7b49f4178c7a184365462f2ec150ac8ead084f8f1e06bf456125f95e0fcddb77693fe294a25e90400f1b4110ec9849edb177df51ea58e3629193a6d6c464bd7ab7024288d05a3d9d524f2f8a0d13c8239d4a8820e693a8109fc06f0c75933843693064191232c22a5a7012b50b428aedb46b0591b86b39b87e8494e390b6d14df4c03301e1f5f74aef55b590353ec9816e0d06235751b48b87d13e57a48b87752a40798253b069b7a4e6a6f44864f144f2779273d5073414c9c413edd290c73b1c7fb1f760c176504ebd25010924149ece4067d3615446f89bf697df94d40c13a98b6a07e31d2b5aecafb53d53f5086cd5e933b6d5d7c9a3f3ff7a9255884dd114900a2c7c89e37dd778e6d718be05b81345d54baccf59347886de7ef5be228e4801b40e40f2ad17f2315655aac9994433f465526d6c4fa8895e2919aa32d0b85deac8ce0f967709f71790231f761a229c4 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 3300000035d8d5595b0671412b000000000035 |
Version | 3 |
Imports
Expand
Imported Functions
Expand
- KeQueryActiveProcessors
- KeQueryActiveProcessorCount
- IoDeleteSymbolicLink
- KeSetSystemAffinityThreadEx
- RtlInitUnicodeString
- IoDeleteDevice
- MmUnmapIoSpace
- MmMapIoSpace
- IofCompleteRequest
- KeRevertToUserAffinityThreadEx
- IoCreateSymbolicLink
- IoCreateDevice
- RtlAssert
- DbgPrint
- KeBugCheckEx
- __C_specific_handler
Exported Functions
Expand
Sections
Expand
- .text
- .rdata
- .data
- .pdata
- PAGE
- INIT
Signature
Expand
{
"Certificates": [
{
"IsCertificateAuthority": false,
"SerialNumber": "330000b6712f575e402cf8708400020000b671",
"Signature": "47ef93216b05a90df10512c9bb24dc20894c255a5943bd567c461f9d76dd3bfeebd65fa524ed3774b4894150c798d9647d64b8c45e0516cf03bdbc819185f494db80e56758fbad4b62f3aed983120533327039d23d550ee32f40d785fa8624a10bbcc4bf531db4c07f1a793be86b015098a62884970e3e58268820f7698ae23d609d2e20b4a75ebacbc98f01edb71c12049594593fd65f62c62b59ac0f269eeb113185fb7ae56cc8da9bd4a9abb7d3332d8ce732638afb3b2b786e56c256bf6211362b498b348b7e370c638b634d7fbd947b57e5c9f923612869cf1d9737fc51075ae92763045c2d2fed944763c14521521bab177c2aad1301d43a8679187077",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel(R) Code Signing External",
"TBS": {
"MD5": "0ddb50f4d347b1641521dfecf6525c50",
"SHA1": "32a2b77cbfe58b3804618edd9435588f24b92695",
"SHA256": "65c1bffcd837ffb534b0641fb137580d7bcf46c905d4c946fbc1fb27281082f2",
"SHA384": "078be3addebd5c1e84cb34f7d1a5144d42b3bb3049d08eb6b3024e3b667d782b7d73fac6481404672a5ba91822c971bc"
},
"ValidFrom": "2015-04-16 17:22:30",
"ValidTo": "2016-04-15 17:22:30",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "612cff88000100000010",
"Signature": "47bb93e603b1d9570eff60e90fc75e86e623f7defa6dc27732ef23f68fcc6f2572d4a94bad11a273bb8bd2b7b8879474890ccc5cea3a9ac0753a97597c22003d7ac7c55be8d49313ec8f94cda833dfa4d79aa1c8d8a3b4497e173a02e96656978d16b470abbc6b1048e7457b13c74d05bca02c0516be067ef679678f9c3454e67eea197714f19d3b55e4339f69bba7a72254512c677d0452aa7b66dea96aad8ca15c7939cd1c85ec890699854627a001576e93365145e15a3a59af5b41f9709dc4160e05e795b401b4931a590b8a31f7b648c86af6228c9e92286fa893b4a772533ada2cfad43dbf09237fdfcc652ad091aa5031c865f53858d4b39be6311008",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel External Basic Issuing CA 3B",
"TBS": {
"MD5": "da9a02953cdcc039174d11b07dd2967d",
"SHA1": "568cfca269ff49615d305e680988337f0a90bc32",
"SHA256": "fad628f5236458a9116a99f2d64fb9131a28f9942fca6239a5e7be0dddf4ce9f",
"SHA384": "5edeab0248f63cdc4c10b748618cd6fa4aa53ffb0ddfd51a2e35de2ea55a56822aa53fa734a46705655e8f5878b24ffd"
},
"ValidFrom": "2013-02-08 22:21:23",
"ValidTo": "2018-02-08 22:31:23",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "79174aa9141736fe15a7ca9f2cff4588",
"Signature": "586fbfcd43074213fcb8d0ad8121f28a6fef87bc268a7c00bd680c2b19642c1167b3a9d9790aac395d6500163b53466ea2a6b56799dbe8bfa225ae049511093a2fdeacb73db8bc017430804748544ca0fb6ba8b8a284b7f434e57bcedc5278f4316d4251ae87bf94acbe9616fb55e5798264fdac5038e4dccb812ce7776f9d9b235c7d0403f4079e7ed457e266944debb55c5c629e8c2d83e64614e2a11380fddae0862711922bbd87174fcb19184b5e8ce60dd98f7d23766fa4ffa0ba3de36d37d62638e81a9c2392c8561f1a1a8e00d633a66b95fa821e740b0fa486df23337c9e3614b35ce2a3ed48a08e28f1d74cf6c09bb4f53ca3e5a863a22c08a5d5fe",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, O=Intel Corporation, CN=Intel External Basic Policy CA",
"TBS": {
"MD5": "6ce466d55ab160317ee9b13522c2a82a",
"SHA1": "53b052ba209c525233293274854b264bc0f68b73",
"SHA256": "f71790e057380a0cbafdfc25bc8b3dafd6cfbeb01077bb3d8194e91254a2fc9b",
"SHA384": "c0cc37f9505ff2bab958c8ef1ea94736efae52bcf5948c866446c46b64fb9f5e603fbad4bc70270ae74e58ac8ab055f9"
},
"ValidFrom": "2013-02-01 00:00:00",
"ValidTo": "2020-05-30 10:48:38",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "69b2d1ccf02e20dcc95c62894f7f9e5f5fc057bf",
"Signature": "b9f61352b517a72a4d84774309a4dba067b4600e42f403bdc4ff2c5a0f902e78c563c84aec27f67ce429d0cf6018fa6822da0252760df21754c6f6081ea1cc82e4c33a6d99227cc4c077b4e6052047934039cfdc55adc346af294d799c644c205f8a1c56fc46a05fcb98dd917a39b4afc477996b9eacde6f2d79ea7fd7132498521cfd693eed72ac3fd0b4011914edb0f0cbf39c5114238cc7dc697d328196e41d478f017694833e888d925b1858986903c7f5d3f2615250eb34a0fd2630300fb5fd70e7272c370b1cf3e71ea62c0743b64b885e971fc1307d60642af30c7068445163599fdb57c21fff80e5c21192d82fefd51743ff642d64845c521a63c267",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=BM, O=QuoVadis Limited, CN=QuoVadis Issuing CA G4",
"TBS": {
"MD5": "4e0fbd79a99e4a55f97ef41efee38a9f",
"SHA1": "114f36d5f22b84de97893469fc00b7035b3ef734",
"SHA256": "f6dd9683708786a413d4d6a3661fa4e4aeb328adbd181b398b5b6aa02bb0bc16",
"SHA384": "a26fe570a01b0e15cf94b41ce48ebd39ed9e9d18493d4c117f0fbb5a5b33ed8ef06c069b9638dda957547f0b0645e447"
},
"ValidFrom": "2014-05-30 16:35:55",
"ValidTo": "2021-03-17 18:33:33",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "385dccec5fe14d3974c9591a3ab1c2caad188c2d",
"Signature": "946aee51ab48079d01882edffbe887d87828778d30da382cacb0c1d5a4c0fc8437badc00c2c16454a82564ba4bcf776b79eb1feedc4e4ccd02514bbaea7c9b755d88a43a9493e07ebaa22358f95dabd995d4c572134e266dfb4bbd3a4c95c3191abbba7b1d1d0587c4a3e3911e1037fda9dacd9fe9c63383f0c21ece4e829c9c7e40e96a64139dfda69d0255a9588dbff28bfec8d343ca34decb755531b384a6cf388a5f06685870f79a321c3fc0e221cf8bba3b1e0b5d0486eb02f6e9008ebc4c2741215451b0ba6e1ec9d9e202b4e38c9184838c5e948df1c051aa0d0122c32810c11cb3458735c726b9e252558e0257b3360f85ec5ba949c3a3f8841c1938b5661ea9bde4f0894b40bd9567e89b17b373faaeeb1de7b7b27e4f52b46add679ac3dbd35bbdb48c9c6fb7aae98058c99002e9e53e0a0d5d88d21289ecce372c63afc6a08ca8f61d013695e40c48b67b9725dab9607e3f80e82d2f56afdd10b453d2e82d488b69a7ca63ced68f9bdc855d62fd79103e8b4abfef936e430dee4ea4e2a199a43a03783e4e4489807170fd63f12272c865861419fe6f2c474948f8749cb696446054b3e0913bba0f5483640dd33e955421beb4574f8398398e1323b3f24f83f640c5146aa90c6e314d6ccdcf8d21bbd09e4ff883e369adc6b742c021d833a2d4fefbba1080d8ca8eade080908a626fb8396451e2616afc943e1f74",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, ST=CA, L=Santa Clara, O=Intel Corporation, OU=Authenticode, OU=Thales TSS ESN:A6A7,71B2,73F1, CN=Timestamp.intel.com",
"TBS": {
"MD5": "4d35161b8be0a29812bb748b548e94b1",
"SHA1": "bf27e048115892363598dec245759aa7529eb154",
"SHA256": "d5c67eb0b73915a6f12dbe19f662205172cc9c97b9988b78a07f14c3b7e1e2b0",
"SHA384": "8b0e411b3fc02dd3a8f5f7d248699a7d882c160a6e3753c1b223d2b0671a6d3f9efa4894172a3bfa3525787be2d6f20e"
},
"ValidFrom": "2014-12-09 21:30:38",
"ValidTo": "2017-12-09 21:30:35",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "3300000035d8d5595b0671412b000000000035",
"Signature": "362ba2f2e1331fe493f7f26985c6640ec99b632fe4703798fd94ec7bcff8a14246f9ed6a4e8d34693605557a1ebbad8c99429606e925a82684bec1bf16a97caa5b04b7fdd1c0f402be28edf577c79bfe3af6e8c17bd382abfa144ecf2bcfe5d5b54840b1a38f838bad2b2553aba634cef243f74f2ce9dd1e4e5ab6bae83b10992400bc50fd78f6e523a8899493f7b74130374a57b7e644d9c9df9905aa44fc74af8264cc07cb01b609c32ee3e832a7b49f4178c7a184365462f2ec150ac8ead084f8f1e06bf456125f95e0fcddb77693fe294a25e90400f1b4110ec9849edb177df51ea58e3629193a6d6c464bd7ab7024288d05a3d9d524f2f8a0d13c8239d4a8820e693a8109fc06f0c75933843693064191232c22a5a7012b50b428aedb46b0591b86b39b87e8494e390b6d14df4c03301e1f5f74aef55b590353ec9816e0d06235751b48b87d13e57a48b87752a40798253b069b7a4e6a6f44864f144f2779273d5073414c9c413edd290c73b1c7fb1f760c176504ebd25010924149ece4067d3615446f89bf697df94d40c13a98b6a07e31d2b5aecafb53d53f5086cd5e933b6d5d7c9a3f3ff7a9255884dd114900a2c7c89e37dd778e6d718be05b81345d54baccf59347886de7ef5be228e4801b40e40f2ad17f2315655aac9994433f465526d6c4fa8895e2919aa32d0b85deac8ce0f967709f71790231f761a229c4",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root",
"TBS": {
"MD5": "3d488d41aaeb5661974952080abef2fd",
"SHA1": "df01e35e6befc7d65625319f17397b861e618d56",
"SHA256": "3d6ef38b5d26773dc77392e415e88b3a744b30ea9f2081e2a992b5818db2f0c4",
"SHA384": "ac7c06916fe4a00307834b2499f12799d3fe463c2e63d1881df669a2786745beeee2b3a7d87cd6bc9e4fe293c22e5a59"
},
"ValidFrom": "2013-08-15 20:26:30",
"ValidTo": "2023-08-15 20:36:30",
"Version": 3
}
],
"CertificatesInfo": "",
"Signer": [
{
"Issuer": "C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel External Basic Issuing CA 3B",
"SerialNumber": "330000b6712f575e402cf8708400020000b671",
"Version": 1
}
],
"SignerInfo": ""
}
Download
Certificates
Expand
Certificate 05b0ff
Field | Value |
---|
ToBeSigned (TBS) MD5 | f532f9999c3f7a078f0f973c726a2a04 |
ToBeSigned (TBS) SHA1 | f56832bc9412c372f9a8744591258f8bb11af2d8 |
ToBeSigned (TBS) SHA256 | 4c75ce4be51027c4e1f7422775c3ae79d5195ffc0ff7f379123a603ccb702c60 |
Subject | C=US, O=Intel Corporation, CN=Intel External Basic Policy CA |
ValidFrom | 2006-02-16 18:01:30 |
ValidTo | 2016-02-19 18:01:30 |
Signature | 131038ada454a5489545b02d3772c09f9ed8ef8f0bfb9096d2b6177951cab3df067ebdb4e9083f84a00c939fb31ca86c8acf2deef99012f0f83a26d773810e9fc4319259d4282541f555f1ca3d993dda64c8d21864223209092d1de331fafdd347d764a8f95dea8227e24fd2612124611d54263e145964b098d5f3a7c3aead50 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 05b0ff |
Version | 3 |
Certificate 7e93ebfb7cc64e59ea4b9a77d406fc3b
Field | Value |
---|
ToBeSigned (TBS) MD5 | d0785ad36e427c92b19f6826ab1e8020 |
ToBeSigned (TBS) SHA1 | 365b7a9c21bd9373e49052c3e7b3e4646ddd4d43 |
ToBeSigned (TBS) SHA256 | c2abb7484da91a658548de089d52436175fdb760a1387d225611dc0613a1e2ff |
Subject | C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA , G2 |
ValidFrom | 2012-12-21 00:00:00 |
ValidTo | 2020-12-30 23:59:59 |
Signature | 03099b8f79ef7f5930aaef68b5fae3091dbb4f82065d375fa6529f168dea1c9209446ef56deb587c30e8f9698d23730b126f47a9ae3911f82ab19bb01ac38eeb599600adce0c4db2d031a6085c2a7afce27a1d574ca86518e979406225966ec7c7376a8321088e41eaddd9573f1d7749872a16065ea6386a2212a35119837eb6 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 7e93ebfb7cc64e59ea4b9a77d406fc3b |
Version | 3 |
Certificate 0ecff438c8febf356e04d86a981b1a50
Field | Value |
---|
ToBeSigned (TBS) MD5 | e9d38360b914c8863f6cba3ee58764d3 |
ToBeSigned (TBS) SHA1 | 4cba8eae47b6bf76f20b3504b98b8f062694a89b |
ToBeSigned (TBS) SHA256 | 88901d86a4cc1f1bb193d08e1fb63d27452e63f83e228c657ab1a92e4ade3976 |
Subject | C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G4 |
ValidFrom | 2012-10-18 00:00:00 |
ValidTo | 2020-12-29 23:59:59 |
Signature | 783bb4912a004cf08f62303778a38427076f18b2de25dca0d49403aa864e259f9a40031cddcee379cb216806dab632b46dbff42c266333e449646d0de6c3670ef705a4356c7c8916c6e9b2dfb2e9dd20c6710fcd9574dcb65cdebd371f4378e678b5cd280420a3aaf14bc48829910e80d111fcdd5c766e4f5e0e4546416e0db0ea389ab13ada097110fc1c79b4807bac69f4fd9cb60c162bf17f5b093d9b5be216ca13816d002e380da8298f2ce1b2f45aa901af159c2c2f491bdb22bbc3fe789451c386b182885df03db451a179332b2e7bb9dc20091371eb6a195bcfe8a530572c89493fb9cf7fc9bf3e226863539abd6974acc51d3c7f92e0c3bc1cd80475 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | False |
SerialNumber | 0ecff438c8febf356e04d86a981b1a50 |
Version | 3 |
Certificate 610bdc8f00000000001a
Field | Value |
---|
ToBeSigned (TBS) MD5 | 6e11ed171e9a07e607b8ca65bf0e8858 |
ToBeSigned (TBS) SHA1 | 6d329a72420f76868584957854cdc45172e9f902 |
ToBeSigned (TBS) SHA256 | 75efb8656a18ba5dacc596757bfb0fa11f0d3d81fd5f8cf9bb8975ced87e7b1b |
Subject | C=US, O=Equifax, OU=Equifax Secure Certificate Authority |
ValidFrom | 2006-05-23 17:01:15 |
ValidTo | 2016-05-23 17:11:15 |
Signature | 87a40f6b55916248ff54811ccf5db6c5a514aa671df485f6860d38b31c8d22ce7c867946fb71e16114d0ed4e46a48bca64654094f92ad7870ca9b7bedcc40bbd09c106eb9530841b9d8de7bc70c6f86539c4e5c4e65c8fcda130baef065e555290edd8587f15142ecc21a593dab8508d805e6e22a70fde8093add71d24b02aa2f4f20b98750131cc69bc359b3d13662f21bde54ec3639cc8518d59f5b600937ef10c35b0f4180dbfa7bdb2aae16b9f3ce6bb41b5d904e7c8a63abf8a5bdcaa9a3cd2c8dfcb1774163d78470b4c108e406616a0f300ede034998af0f9460ff27fbf202c972616d59e81da94a6dc61c8f18e092d4e32d03df682267d91d7a6c67bc1311d210ed4a342c1b4dfc0446b4f2aeebb29d62787b0a450ae1a9ab5f996f4ccabe52b3df166e2d5e1c3f0c687b659536638026e6194df1563aa415052f9bb64dc95e05b6c2aacfed6e603c21ff65557fe7e813fcb5a0bc1029cac84e47cd3f4c25a17c312706009ec82e5eccdd0b2106d69868c8da60e0416c57164ebd95bb8b08cfc32427e60846f655b7244272b846181f461d50fd51dbc05a27a5f937f26d1c8b3afa0190723e43e225d32d14a0fcee7b72a5c7b6e1c57126864e8337e8c501340a487b0d3a69b1eacbd3d7812bc52af09e0bab0508e5c81f98383af1482f50a6d035721bb9ac32e66fb04215b0a120fc1c907d63cecabf9a52f90883a |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 610bdc8f00000000001a |
Version | 3 |
Certificate 1b9a8f3100010000916c
Field | Value |
---|
ToBeSigned (TBS) MD5 | b94186e712a30346b6aec85b267f1ccf |
ToBeSigned (TBS) SHA1 | e6df41e3f543c4f54b4cecf8c45a941b5f79087c |
ToBeSigned (TBS) SHA256 | 955af30020a5027583bcbb5b546442a68c574ca151662d2c63d38b20c4924c6c |
Subject | CN=SEMA Software |
ValidFrom | 2012-08-13 20:15:00 |
ValidTo | 2015-05-15 19:35:13 |
Signature | 759b16da09fbcae52729fd7739d9a29d9e5c83d61bf897d352b330cb0ef2e85f6675674f8fa4f0205fdaf097d766dada95c6a00012de4c8bcc2b91f462c30e8884f2262edae6482a497ebe024c266db370545536498feed2699b85d32892b19d10fa36ebad821790a82d4a9d17b1088950afbdfa4ab13e3082ab7e9ea705911ef91284430bf69b5b8b69a528b6896d87cdfb3e0e5f934278fed63d494a82025aa24f9e75ef54cc7453c29f9ab6ffc79adeca70be5fe54891fd2804f019624d430222c1b5e5862b67de49363b9e41b96f0a1f45dd63458ff4aeffe0d8701c11b2eb8a50399123a21f822f7b1bed5cc03c470ed396d927851e3b7069f4228b1ca4 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | False |
SerialNumber | 1b9a8f3100010000916c |
Version | 3 |
Certificate 611e80b7000000000007
Field | Value |
---|
ToBeSigned (TBS) MD5 | baca708678523cc174d8591aee607fa0 |
ToBeSigned (TBS) SHA1 | ccb0c6bea0e8d844bce4c981fb29a4784b85ad34 |
ToBeSigned (TBS) SHA256 | 11b7a4f10026418d92ba91b7d639a49b0f24ba1406bb0f3bb9a4fb6d2bede02c |
Subject | C=US, O=Intel Corporation, CN=Intel External Basic Issuing CA 3A |
ValidFrom | 2009-05-15 19:25:13 |
ValidTo | 2015-05-15 19:35:13 |
Signature | 9463fd5dd0c4ba54f4e521c3a1a355d6875f773c3e642432523dda612c741d335a0a03ec2131d201a18d55cd30c32be0be132e097329daedfa42f2e5669ff473fe2f4c66dc9ceea7b33ed6539fd532391bc999d747f8ec7f472706c1edda82cf2351db29102a2b60e909c9992c9c32254d552f6d1ef0c98fa018962ac565eaadc54512232c5aef3f38895fec5da0018301c35919e79767e2558120cd16aaf45e5a93ef85878ded8fb730a11d48c910ed366235b7dd6790fff0a7d634c4c9e151e5b4e8022f5940e6dc7f178475f76d2c9292f97aedd28fae744547b7ace5ec695e4dc89cc1c01df5fb5cec9a57957450f493f170f47c576c0404df9b9c37fec2 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.5 |
IsCertificateAuthority | True |
SerialNumber | 611e80b7000000000007 |
Version | 3 |
Imports
Expand
Imported Functions
Expand
- KeQueryActiveProcessors
- KeQueryActiveProcessorCount
- IoDeleteSymbolicLink
- KeSetSystemAffinityThreadEx
- RtlInitUnicodeString
- IoDeleteDevice
- MmUnmapIoSpace
- MmMapIoSpace
- IofCompleteRequest
- KeRevertToUserAffinityThreadEx
- IoCreateSymbolicLink
- IoCreateDevice
- RtlAssert
- DbgPrint
- KeBugCheckEx
- __C_specific_handler
Exported Functions
Expand
Sections
Expand
- .text
- .rdata
- .data
- .pdata
- PAGE
- INIT
Signature
Expand
{
"Certificates": [
{
"IsCertificateAuthority": false,
"SerialNumber": "330000b6712f575e402cf8708400020000b671",
"Signature": "47ef93216b05a90df10512c9bb24dc20894c255a5943bd567c461f9d76dd3bfeebd65fa524ed3774b4894150c798d9647d64b8c45e0516cf03bdbc819185f494db80e56758fbad4b62f3aed983120533327039d23d550ee32f40d785fa8624a10bbcc4bf531db4c07f1a793be86b015098a62884970e3e58268820f7698ae23d609d2e20b4a75ebacbc98f01edb71c12049594593fd65f62c62b59ac0f269eeb113185fb7ae56cc8da9bd4a9abb7d3332d8ce732638afb3b2b786e56c256bf6211362b498b348b7e370c638b634d7fbd947b57e5c9f923612869cf1d9737fc51075ae92763045c2d2fed944763c14521521bab177c2aad1301d43a8679187077",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel(R) Code Signing External",
"TBS": {
"MD5": "0ddb50f4d347b1641521dfecf6525c50",
"SHA1": "32a2b77cbfe58b3804618edd9435588f24b92695",
"SHA256": "65c1bffcd837ffb534b0641fb137580d7bcf46c905d4c946fbc1fb27281082f2",
"SHA384": "078be3addebd5c1e84cb34f7d1a5144d42b3bb3049d08eb6b3024e3b667d782b7d73fac6481404672a5ba91822c971bc"
},
"ValidFrom": "2015-04-16 17:22:30",
"ValidTo": "2016-04-15 17:22:30",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "612cff88000100000010",
"Signature": "47bb93e603b1d9570eff60e90fc75e86e623f7defa6dc27732ef23f68fcc6f2572d4a94bad11a273bb8bd2b7b8879474890ccc5cea3a9ac0753a97597c22003d7ac7c55be8d49313ec8f94cda833dfa4d79aa1c8d8a3b4497e173a02e96656978d16b470abbc6b1048e7457b13c74d05bca02c0516be067ef679678f9c3454e67eea197714f19d3b55e4339f69bba7a72254512c677d0452aa7b66dea96aad8ca15c7939cd1c85ec890699854627a001576e93365145e15a3a59af5b41f9709dc4160e05e795b401b4931a590b8a31f7b648c86af6228c9e92286fa893b4a772533ada2cfad43dbf09237fdfcc652ad091aa5031c865f53858d4b39be6311008",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel External Basic Issuing CA 3B",
"TBS": {
"MD5": "da9a02953cdcc039174d11b07dd2967d",
"SHA1": "568cfca269ff49615d305e680988337f0a90bc32",
"SHA256": "fad628f5236458a9116a99f2d64fb9131a28f9942fca6239a5e7be0dddf4ce9f",
"SHA384": "5edeab0248f63cdc4c10b748618cd6fa4aa53ffb0ddfd51a2e35de2ea55a56822aa53fa734a46705655e8f5878b24ffd"
},
"ValidFrom": "2013-02-08 22:21:23",
"ValidTo": "2018-02-08 22:31:23",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "79174aa9141736fe15a7ca9f2cff4588",
"Signature": "586fbfcd43074213fcb8d0ad8121f28a6fef87bc268a7c00bd680c2b19642c1167b3a9d9790aac395d6500163b53466ea2a6b56799dbe8bfa225ae049511093a2fdeacb73db8bc017430804748544ca0fb6ba8b8a284b7f434e57bcedc5278f4316d4251ae87bf94acbe9616fb55e5798264fdac5038e4dccb812ce7776f9d9b235c7d0403f4079e7ed457e266944debb55c5c629e8c2d83e64614e2a11380fddae0862711922bbd87174fcb19184b5e8ce60dd98f7d23766fa4ffa0ba3de36d37d62638e81a9c2392c8561f1a1a8e00d633a66b95fa821e740b0fa486df23337c9e3614b35ce2a3ed48a08e28f1d74cf6c09bb4f53ca3e5a863a22c08a5d5fe",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, O=Intel Corporation, CN=Intel External Basic Policy CA",
"TBS": {
"MD5": "6ce466d55ab160317ee9b13522c2a82a",
"SHA1": "53b052ba209c525233293274854b264bc0f68b73",
"SHA256": "f71790e057380a0cbafdfc25bc8b3dafd6cfbeb01077bb3d8194e91254a2fc9b",
"SHA384": "c0cc37f9505ff2bab958c8ef1ea94736efae52bcf5948c866446c46b64fb9f5e603fbad4bc70270ae74e58ac8ab055f9"
},
"ValidFrom": "2013-02-01 00:00:00",
"ValidTo": "2020-05-30 10:48:38",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "69b2d1ccf02e20dcc95c62894f7f9e5f5fc057bf",
"Signature": "b9f61352b517a72a4d84774309a4dba067b4600e42f403bdc4ff2c5a0f902e78c563c84aec27f67ce429d0cf6018fa6822da0252760df21754c6f6081ea1cc82e4c33a6d99227cc4c077b4e6052047934039cfdc55adc346af294d799c644c205f8a1c56fc46a05fcb98dd917a39b4afc477996b9eacde6f2d79ea7fd7132498521cfd693eed72ac3fd0b4011914edb0f0cbf39c5114238cc7dc697d328196e41d478f017694833e888d925b1858986903c7f5d3f2615250eb34a0fd2630300fb5fd70e7272c370b1cf3e71ea62c0743b64b885e971fc1307d60642af30c7068445163599fdb57c21fff80e5c21192d82fefd51743ff642d64845c521a63c267",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=BM, O=QuoVadis Limited, CN=QuoVadis Issuing CA G4",
"TBS": {
"MD5": "4e0fbd79a99e4a55f97ef41efee38a9f",
"SHA1": "114f36d5f22b84de97893469fc00b7035b3ef734",
"SHA256": "f6dd9683708786a413d4d6a3661fa4e4aeb328adbd181b398b5b6aa02bb0bc16",
"SHA384": "a26fe570a01b0e15cf94b41ce48ebd39ed9e9d18493d4c117f0fbb5a5b33ed8ef06c069b9638dda957547f0b0645e447"
},
"ValidFrom": "2014-05-30 16:35:55",
"ValidTo": "2021-03-17 18:33:33",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "385dccec5fe14d3974c9591a3ab1c2caad188c2d",
"Signature": "946aee51ab48079d01882edffbe887d87828778d30da382cacb0c1d5a4c0fc8437badc00c2c16454a82564ba4bcf776b79eb1feedc4e4ccd02514bbaea7c9b755d88a43a9493e07ebaa22358f95dabd995d4c572134e266dfb4bbd3a4c95c3191abbba7b1d1d0587c4a3e3911e1037fda9dacd9fe9c63383f0c21ece4e829c9c7e40e96a64139dfda69d0255a9588dbff28bfec8d343ca34decb755531b384a6cf388a5f06685870f79a321c3fc0e221cf8bba3b1e0b5d0486eb02f6e9008ebc4c2741215451b0ba6e1ec9d9e202b4e38c9184838c5e948df1c051aa0d0122c32810c11cb3458735c726b9e252558e0257b3360f85ec5ba949c3a3f8841c1938b5661ea9bde4f0894b40bd9567e89b17b373faaeeb1de7b7b27e4f52b46add679ac3dbd35bbdb48c9c6fb7aae98058c99002e9e53e0a0d5d88d21289ecce372c63afc6a08ca8f61d013695e40c48b67b9725dab9607e3f80e82d2f56afdd10b453d2e82d488b69a7ca63ced68f9bdc855d62fd79103e8b4abfef936e430dee4ea4e2a199a43a03783e4e4489807170fd63f12272c865861419fe6f2c474948f8749cb696446054b3e0913bba0f5483640dd33e955421beb4574f8398398e1323b3f24f83f640c5146aa90c6e314d6ccdcf8d21bbd09e4ff883e369adc6b742c021d833a2d4fefbba1080d8ca8eade080908a626fb8396451e2616afc943e1f74",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, ST=CA, L=Santa Clara, O=Intel Corporation, OU=Authenticode, OU=Thales TSS ESN:A6A7,71B2,73F1, CN=Timestamp.intel.com",
"TBS": {
"MD5": "4d35161b8be0a29812bb748b548e94b1",
"SHA1": "bf27e048115892363598dec245759aa7529eb154",
"SHA256": "d5c67eb0b73915a6f12dbe19f662205172cc9c97b9988b78a07f14c3b7e1e2b0",
"SHA384": "8b0e411b3fc02dd3a8f5f7d248699a7d882c160a6e3753c1b223d2b0671a6d3f9efa4894172a3bfa3525787be2d6f20e"
},
"ValidFrom": "2014-12-09 21:30:38",
"ValidTo": "2017-12-09 21:30:35",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "3300000035d8d5595b0671412b000000000035",
"Signature": "362ba2f2e1331fe493f7f26985c6640ec99b632fe4703798fd94ec7bcff8a14246f9ed6a4e8d34693605557a1ebbad8c99429606e925a82684bec1bf16a97caa5b04b7fdd1c0f402be28edf577c79bfe3af6e8c17bd382abfa144ecf2bcfe5d5b54840b1a38f838bad2b2553aba634cef243f74f2ce9dd1e4e5ab6bae83b10992400bc50fd78f6e523a8899493f7b74130374a57b7e644d9c9df9905aa44fc74af8264cc07cb01b609c32ee3e832a7b49f4178c7a184365462f2ec150ac8ead084f8f1e06bf456125f95e0fcddb77693fe294a25e90400f1b4110ec9849edb177df51ea58e3629193a6d6c464bd7ab7024288d05a3d9d524f2f8a0d13c8239d4a8820e693a8109fc06f0c75933843693064191232c22a5a7012b50b428aedb46b0591b86b39b87e8494e390b6d14df4c03301e1f5f74aef55b590353ec9816e0d06235751b48b87d13e57a48b87752a40798253b069b7a4e6a6f44864f144f2779273d5073414c9c413edd290c73b1c7fb1f760c176504ebd25010924149ece4067d3615446f89bf697df94d40c13a98b6a07e31d2b5aecafb53d53f5086cd5e933b6d5d7c9a3f3ff7a9255884dd114900a2c7c89e37dd778e6d718be05b81345d54baccf59347886de7ef5be228e4801b40e40f2ad17f2315655aac9994433f465526d6c4fa8895e2919aa32d0b85deac8ce0f967709f71790231f761a229c4",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root",
"TBS": {
"MD5": "3d488d41aaeb5661974952080abef2fd",
"SHA1": "df01e35e6befc7d65625319f17397b861e618d56",
"SHA256": "3d6ef38b5d26773dc77392e415e88b3a744b30ea9f2081e2a992b5818db2f0c4",
"SHA384": "ac7c06916fe4a00307834b2499f12799d3fe463c2e63d1881df669a2786745beeee2b3a7d87cd6bc9e4fe293c22e5a59"
},
"ValidFrom": "2013-08-15 20:26:30",
"ValidTo": "2023-08-15 20:36:30",
"Version": 3
}
],
"CertificatesInfo": "",
"Signer": [
{
"Issuer": "C=US, ST=CA, L=Santa Clara, O=Intel Corporation, CN=Intel External Basic Issuing CA 3B",
"SerialNumber": "330000b6712f575e402cf8708400020000b671",
"Version": 1
}
],
"SignerInfo": ""
}
source
last_updated: 2024-09-26