a285591e-ad3c-46a3-a648-c58589ff5efc

amsdk.sys :inline :inline

Description

Vulnerable driver found in https://github.com/hfiref0x/KDU.

  • UUID: a285591e-ad3c-46a3-a648-c58589ff5efc
  • Created: 2023-05-22
  • Author: Michael Haag
  • Acknowledgement: hfiref0x | hfiref0x

DownloadBlock

This download link contains the vulnerable driver!

Commands

sc.exe create amsdk.sys binPath=C:\windows\temp\amsdk.sys type=kernel && sc.exe start amsdk.sys
Use CasePrivilegesOperating System
Elevate privilegeskernelWindows 10

Detections

YARA 🏹

Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed driver files

Sigma 🛡️

Expand

Names

detects loading using name only

Hashes

detects loading using hashes only

Sysmon 🔎

Expand

Block

on hashes

Alert

on hashes

Resources


  • https://github.com/magicsword-io/LOLDrivers/issues/55#issuecomment-1537161951

  • Known Vulnerable Samples

    PropertyValue
    Filenameamsdk.sys
    Creation Timestamp2019-04-23 03:04:57
    MD5eb525d99a31eb4fff09814e83593a494
    SHA1290d6376658cf0f8182de0fae40b503098fa09fd
    SHA2566f55c148bb27c14408cf0f16f344abcd63539174ac855e510a42d78cfaec451c
    Authentihash MD589627ebd29f4ae929d7f40fd4dabead3
    Authentihash SHA1084553447bdbc056bbe49bad8acfaf25eb83462a
    Authentihash SHA25660571dbcaec96d9517e0d116d066e70ae747aa4396d7857b2eea0f4c1a5a70b4
    RichPEHeaderHash MD5538cd5afb8509a14342d4a050452744b
    RichPEHeaderHash SHA1af8e1d754d89a2c862fd68cee30add8efb16ac34
    RichPEHeaderHash SHA256f3c4c4d8cba6ebe5127ccbe7eec2a8cc847c56e45b87963b1cd731aee7399677
    CompanyCopyright 2018.
    DescriptionAdvanced Malware Protection
    ProductAdvanced Malware Protection
    OriginalFilenameZAM.exe

    Download

    Certificates

    Expand
    Certificate 01ee5f169dff97352b6465d66a
    FieldValue
    ToBeSigned (TBS) MD551c3959a45cecf3d21a3effb05762573
    ToBeSigned (TBS) SHA1ecfcd25fd0525448a74875ba271566bc0bfbf061
    ToBeSigned (TBS) SHA256de1da11668f0a8d5e13346ed3ab2755f5d25bebffcfd1d0bde5b9f87bc292c91
    SubjectOU=GlobalSign Root CA , R3, O=GlobalSign, CN=GlobalSign
    ValidFrom2018-09-19 00:00:00
    ValidTo2028-01-28 12:00:00
    Signature2370e9cfe2bef559ae94426fc44333aacd3f3ab96417f262064b48f140880617a1feabd15f3cc633f2f38edd1f1d3ecc1a6099820bacc7fc7e9a872aa57d0fa657eeac3b6a85d6debd4063f8ada6c888b012fcf641df0f09971e38ea539fbe05f43eead39f501276be098bc20b487d1e2e51f68d53d3ab1f401b8a8eed7dfb4f7956705f0cd38e1bb3a7700d372b9795abdae0126b1c40cec5c77eedc26258ec77ed7322c28af5864388adea136efdd8fe422fb97d5ead18ef9490ca3d27ab26949975c7cbd37bf7ca4cd3af5121925b847d2b9f153f74cb51e89e830e166f1be746ce23bdf9e4a28bd2396baa791c912ce261242d8e2a487090c41ec5e8e070
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber01ee5f169dff97352b6465d66a
    Version3
    Certificate 7803184245708a41cf6f01b8eeb4a954
    FieldValue
    ToBeSigned (TBS) MD5a33260428269bc902bc1cd280e4b1837
    ToBeSigned (TBS) SHA1254209ca172cffcc67bd2a88996556d2f09538f0
    ToBeSigned (TBS) SHA256a67411358594f2cf016741a63fd49f36de917f86531b3e3a43eb6a421c654868
    SubjectC=BE, O=GlobalSign nv,sa, CN=GlobalSign Code Signing Root R45
    ValidFrom2020-07-28 00:00:00
    ValidTo2029-03-18 00:00:00
    Signatureacf7cc158b3079a81d0b28881909d71c7ffe86bd7b5a336e0d670e7b62d9e1185cb0bd135d1d23ae39507637aa44fd5f01235986564cccadbc64131430a420a8e03fe89c72dc7ef3d80c23baa82daa3cf6ec9f87310765f539a7518275e1f22f97f6d1e165968364fea11d51fbb5249bf5d27769bc852c5cfa5877d1aea7b10be2d677bba9b4344aa96f3df4f30d955de6f97a45b02517312edbf70f68e6831fa9f7e5d49d988cd3614b2fc3287e7ade930eb47da00a6d92c4b4663f7da758eeacf7ecc30801ab38fc0a1ca9c597b288c8090219f65c9a1af14d6c30d4b306ab0060480d78abcf17ad9293622077756cbdc832b4dc4debd9dfc1909629bdc17f
    SignatureAlgorithmOID1.2.840.113549.1.1.12
    IsCertificateAuthorityTrue
    SerialNumber7803184245708a41cf6f01b8eeb4a954
    Version3
    Certificate 1f7b0de3090ee13a436315a6
    FieldValue
    ToBeSigned (TBS) MD5cf8f84376abaf814f76cb8332f32d76f
    ToBeSigned (TBS) SHA11103e907c83a85682befe4adba4d03b8f6c95543
    ToBeSigned (TBS) SHA2568de6eae4e1479f02dc58281ad5c035e629345ff74a177e559192d03bd23e0f9f
    Subject??=Private Organization, serialNumber=460726, ??=US, ??=Idaho, C=US, ST=Idaho, L=Boise, ??=702 W Idaho Street Suite 1100, O=WATCHDOGDEVELOPMENT.COM, LLC, CN=WATCHDOGDEVELOPMENT.COM, LLC
    ValidFrom2021-04-21 14:24:27
    ValidTo2022-03-25 19:57:48
    Signature9ba0d9eef89f4e9a41f5cf68ac4fe0f024dac877c639b288bae6c89bdbcb5ea6c81f1b8bd62f53be6a880bcd072c82ac2dc99f32f56bc6b02946d0bba3ebefe29dcf49e118dcfd966b4fa9ca56a4845e61910c077fe7fbbbf56daa73a82be2ceff3a9e84b397fe97dfb407c7d9160dd92a371fb76a2d35c8ba04c94e5028b2e3354fb09dc8974298b654f7a2ec4b703cf36aa5dada972d076a5685b5e292e2521c0d1b6ead53911bbe887e49916dca7913ee57cb16da99537f2addeb1cef02465db1b72b4ed09dc275230eec1aba61848a07d34b4d271619a5a6230b73fe406cf6aae6c2d20cbf2ff7d18eb662804680c96b8d390713c22d80e6e84b3933bd519d9ecc0af19282a5ab7d4886da8e0ca6947135691bd2f891258e8ef8f913de42229d87985c96da4b58de561afacaa99800ffcaa2d386fc88d8f6f82e7442cbd51ba9f3f4e8e9d2d1752d467e1d95a06cafd4438ad8648dc3d552126a589b205269b05be5b181c93fedf0a20caab8a185663f56be9e86287db166eb49493a5789e4e95f455d4f032274a63b6e8ad8bf8534aef7a8ab80c73ff24cf42db5d4293f6d5f5c6b7262c211e767e87cbe196ec28ec820eb1e5b138c3604329ed5d0139cc8f2e049c7d416fb7a0c5a55dcd0cc5fcf8e566d644b5583e557f24244296762139a4ee1fd70be0b15402c7193996b25223dd05e9206e0290aa6e1f52f3097b3
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber1f7b0de3090ee13a436315a6
    Version3
    Certificate 77bd0e05b7590bb61d4761531e3f75ed
    FieldValue
    ToBeSigned (TBS) MD565fd1dac1f115d9507f4e1840c8cb36a
    ToBeSigned (TBS) SHA1c7cf5607e19b22fe60c055e71d9b555d70f71f66
    ToBeSigned (TBS) SHA256d9c7db0b704f07089440c56e69a0f31d730edf77cfbf7514630e8b5390a270fe
    SubjectC=BE, O=GlobalSign nv,sa, CN=GlobalSign GCC R45 EV CodeSigning CA 2020
    ValidFrom2020-07-28 00:00:00
    ValidTo2030-07-28 00:00:00
    Signature2575a009c939bab7a139892f189fabd6eb1d4be8947c0d07689b1c9def71b6176a6b024fb33f864587cc659b4ce35806022266d56102c5638fd4a2f1b65e250b7796e9cd7140338829eceef3a26dbc4db53e064bc97333ca08142d3d4ce8b0ba75a6742da4583a6c1349f8a5150a149685b16a68342542af9656f410fa247df12b72c116e16bebe6a998c73e5af4d0189dfd74978677462a3d237d28738aaeef2b1b9abf6c53a7149e3c8771c05e8ec8fbd32a9233ea574d5e075ecac118ac812d1a21fa6ecf97617bdf717a3aca63f7d530443732febb4385dcbafca6ca33192b776ddbcb05f07e5f752ea2b6bf35aa3663c9ce64d9bdfcbc2cf3495600c8122bc627bb37af57efc4cf1e29c4f4e22dce2a61cf57edf50a40e2f518d61ee9902fcad3875f938a481a111de537859f2e66629a5e814e95ac555743dc538b257e3c610f8a0bbaf53fa6d78ef704565e21bb9fd76a7180bf96de7203d8d8222bf327164f38e851400cae92efbe3d7df780c64c36578495a7841548300e5227088d8ea2bd22c719c9a6ca0ea87a36db6aba615f112495a4e28e68ee19a949995ed0b434bdd6f940c710973152393529118724d3c4fba963cb7748d5fa62fc24e0047a4ed0e46edece9e385026f4217165d70925d4c907007ab8c7f377e8c5d4e255d0d31ef67f52e2498db911720c88442633660144dfe4330e21de62894807daf5
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber77bd0e05b7590bb61d4761531e3f75ed
    Version3

    Imports

    Expand
    • FLTMGR.SYS
    • ntoskrnl.exe

    Imported Functions

    Expand
    • FltRegisterFilter
    • FltUnregisterFilter
    • FltStartFiltering
    • FltAllocatePoolAlignedWithTag
    • FltFreePoolAlignedWithTag
    • FltGetFileNameInformation
    • FltReleaseFileNameInformation
    • FltParseFileNameInformation
    • FltReadFile
    • FltQueryInformationFile
    • FltCancelFileOpen
    • FltAllocateContext
    • FltSetStreamHandleContext
    • FltGetStreamHandleContext
    • FltReleaseContext
    • FltCreateCommunicationPort
    • FltCloseCommunicationPort
    • FltSendMessage
    • FltBuildDefaultSecurityDescriptor
    • strstr
    • wcsstr
    • RtlInitUnicodeString
    • RtlCopyUnicodeString
    • DbgPrint
    • RtlGetVersion
    • KeDelayExecutionThread
    • ExAllocatePoolWithTag
    • ExFreePoolWithTag
    • ProbeForRead
    • ObReferenceObjectByHandle
    • ObfDereferenceObject
    • ZwCreateFile
    • ZwClose
    • RtlUpperString
    • RtlUpcaseUnicodeString
    • PsGetCurrentProcessId
    • ZwOpenProcess
    • PsLookupProcessByProcessId
    • ObQueryNameString
    • FsRtlIsNameInExpression
    • PsGetProcessImageFileName
    • ZwQueryInformationProcess
    • __C_specific_handler
    • strchr
    • RtlAppendUnicodeToString
    • KeInitializeSemaphore
    • KeReleaseSemaphore
    • KeWaitForSingleObject
    • KeAcquireSpinLockRaiseToDpc
    • KeReleaseSpinLock
    • PsCreateSystemThread
    • PsTerminateSystemThread
    • ZwQueryInformationFile
    • ZwWriteFile
    • PsGetCurrentThreadId
    • ZwDeleteFile
    • _vsnprintf
    • PsThreadType
    • PsSetCreateProcessNotifyRoutine
    • PsGetProcessSessionId
    • RtlAppendUnicodeStringToString
    • ZwDeleteValueKey
    • ZwSetValueKey
    • towupper
    • RtlIntegerToUnicodeString
    • KeInitializeEvent
    • KeSetEvent
    • KeAcquireSpinLockAtDpcLevel
    • KeReleaseSpinLockFromDpcLevel
    • MmProbeAndLockPages
    • IoAllocateIrp
    • IoAllocateMdl
    • IofCallDriver
    • IoFreeIrp
    • IoFreeMdl
    • IoGetDeviceObjectPointer
    • IoGetRelatedDeviceObject
    • ObCloseHandle
    • ObfReferenceObject
    • ZwSetInformationFile
    • ZwReadFile
    • ZwOpenSymbolicLinkObject
    • ZwQuerySymbolicLinkObject
    • IoCreateFileSpecifyDeviceObjectHint
    • IoGetDeviceAttachmentBaseRef
    • FsRtlGetFileSize
    • ZwQuerySystemInformation
    • IoFileObjectType
    • KeReadStateEvent
    • ExQueueWorkItem
    • ExGetPreviousMode
    • MmGetSystemRoutineAddress
    • NtOpenProcess
    • ZwCreateEvent
    • ZwWaitForSingleObject
    • ZwSetEvent
    • NtQuerySystemInformation
    • ExEventObjectType
    • NtBuildNumber
    • ZwDeleteKey
    • ObReferenceObjectByName
    • IoDriverObjectType
    • MmIsDriverVerifying
    • IofCompleteRequest
    • IoCreateSymbolicLink
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • RtlSetDaclSecurityDescriptor
    • MmMapLockedPagesSpecifyCache
    • PsGetProcessId
    • IoThreadToProcess
    • PsGetCurrentProcessSessionId
    • ZwTerminateProcess
    • KeStackAttachProcess
    • KeUnstackDetachProcess
    • ZwOpenThread
    • PsProcessType
    • ExInterlockedInsertHeadList
    • ExInterlockedRemoveHeadList
    • CmRegisterCallback
    • CmUnRegisterCallback
    • RtlCreateRegistryKey
    • ZwOpenKey
    • ZwEnumerateKey
    • ZwQueryKey
    • ZwQueryValueKey
    • RtlUnicodeStringToAnsiString
    • RtlFreeAnsiString
    • ProbeForWrite
    • PsSetLoadImageNotifyRoutine
    • PsRemoveLoadImageNotifyRoutine
    • PsGetProcessSectionBaseAddress
    • MmSystemRangeStart
    • KeBugCheckEx
    • IoCreateDevice
    • ObOpenObjectByPointer
    • ZwSetSecurityObject
    • IoDeviceObjectType
    • _snwprintf
    • RtlLengthSecurityDescriptor
    • SeCaptureSecurityDescriptor
    • RtlCreateSecurityDescriptor
    • RtlAbsoluteToSelfRelativeSD
    • IoIsWdmVersionAvailable
    • SeExports
    • wcschr
    • _wcsnicmp
    • RtlLengthSid
    • RtlAddAccessAllowedAce
    • RtlGetSaclSecurityDescriptor
    • RtlGetDaclSecurityDescriptor
    • RtlGetGroupSecurityDescriptor
    • RtlGetOwnerSecurityDescriptor
    • ZwCreateKey
    • RtlFreeUnicodeString

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .hook
    • .rdata
    • .data
    • .pdata
    • PAGE
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "01ee5f169dff97352b6465d66a",
          "Signature": "2370e9cfe2bef559ae94426fc44333aacd3f3ab96417f262064b48f140880617a1feabd15f3cc633f2f38edd1f1d3ecc1a6099820bacc7fc7e9a872aa57d0fa657eeac3b6a85d6debd4063f8ada6c888b012fcf641df0f09971e38ea539fbe05f43eead39f501276be098bc20b487d1e2e51f68d53d3ab1f401b8a8eed7dfb4f7956705f0cd38e1bb3a7700d372b9795abdae0126b1c40cec5c77eedc26258ec77ed7322c28af5864388adea136efdd8fe422fb97d5ead18ef9490ca3d27ab26949975c7cbd37bf7ca4cd3af5121925b847d2b9f153f74cb51e89e830e166f1be746ce23bdf9e4a28bd2396baa791c912ce261242d8e2a487090c41ec5e8e070",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "OU=GlobalSign Root CA , R3, O=GlobalSign, CN=GlobalSign",
          "TBS": {
            "MD5": "51c3959a45cecf3d21a3effb05762573",
            "SHA1": "ecfcd25fd0525448a74875ba271566bc0bfbf061",
            "SHA256": "de1da11668f0a8d5e13346ed3ab2755f5d25bebffcfd1d0bde5b9f87bc292c91",
            "SHA384": "f0eab75baf1f24a53d63bd795cd07292a312f603513c8cb0f40fe5acbdb477ed72607d309fad21471a16f6223fb3a838"
          },
          "ValidFrom": "2018-09-19 00:00:00",
          "ValidTo": "2028-01-28 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "7803184245708a41cf6f01b8eeb4a954",
          "Signature": "acf7cc158b3079a81d0b28881909d71c7ffe86bd7b5a336e0d670e7b62d9e1185cb0bd135d1d23ae39507637aa44fd5f01235986564cccadbc64131430a420a8e03fe89c72dc7ef3d80c23baa82daa3cf6ec9f87310765f539a7518275e1f22f97f6d1e165968364fea11d51fbb5249bf5d27769bc852c5cfa5877d1aea7b10be2d677bba9b4344aa96f3df4f30d955de6f97a45b02517312edbf70f68e6831fa9f7e5d49d988cd3614b2fc3287e7ade930eb47da00a6d92c4b4663f7da758eeacf7ecc30801ab38fc0a1ca9c597b288c8090219f65c9a1af14d6c30d4b306ab0060480d78abcf17ad9293622077756cbdc832b4dc4debd9dfc1909629bdc17f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.12",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign Code Signing Root R45",
          "TBS": {
            "MD5": "a33260428269bc902bc1cd280e4b1837",
            "SHA1": "254209ca172cffcc67bd2a88996556d2f09538f0",
            "SHA256": "a67411358594f2cf016741a63fd49f36de917f86531b3e3a43eb6a421c654868",
            "SHA384": "fec727af43d1569995cea26e8eb97167165842a5b185304425a92c03b71254c5d51222837515f33e60cb8ed2e8c625ba"
          },
          "ValidFrom": "2020-07-28 00:00:00",
          "ValidTo": "2029-03-18 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "1f7b0de3090ee13a436315a6",
          "Signature": "9ba0d9eef89f4e9a41f5cf68ac4fe0f024dac877c639b288bae6c89bdbcb5ea6c81f1b8bd62f53be6a880bcd072c82ac2dc99f32f56bc6b02946d0bba3ebefe29dcf49e118dcfd966b4fa9ca56a4845e61910c077fe7fbbbf56daa73a82be2ceff3a9e84b397fe97dfb407c7d9160dd92a371fb76a2d35c8ba04c94e5028b2e3354fb09dc8974298b654f7a2ec4b703cf36aa5dada972d076a5685b5e292e2521c0d1b6ead53911bbe887e49916dca7913ee57cb16da99537f2addeb1cef02465db1b72b4ed09dc275230eec1aba61848a07d34b4d271619a5a6230b73fe406cf6aae6c2d20cbf2ff7d18eb662804680c96b8d390713c22d80e6e84b3933bd519d9ecc0af19282a5ab7d4886da8e0ca6947135691bd2f891258e8ef8f913de42229d87985c96da4b58de561afacaa99800ffcaa2d386fc88d8f6f82e7442cbd51ba9f3f4e8e9d2d1752d467e1d95a06cafd4438ad8648dc3d552126a589b205269b05be5b181c93fedf0a20caab8a185663f56be9e86287db166eb49493a5789e4e95f455d4f032274a63b6e8ad8bf8534aef7a8ab80c73ff24cf42db5d4293f6d5f5c6b7262c211e767e87cbe196ec28ec820eb1e5b138c3604329ed5d0139cc8f2e049c7d416fb7a0c5a55dcd0cc5fcf8e566d644b5583e557f24244296762139a4ee1fd70be0b15402c7193996b25223dd05e9206e0290aa6e1f52f3097b3",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "??=Private Organization, serialNumber=460726, ??=US, ??=Idaho, C=US, ST=Idaho, L=Boise, ??=702 W Idaho Street Suite 1100, O=WATCHDOGDEVELOPMENT.COM, LLC, CN=WATCHDOGDEVELOPMENT.COM, LLC",
          "TBS": {
            "MD5": "cf8f84376abaf814f76cb8332f32d76f",
            "SHA1": "1103e907c83a85682befe4adba4d03b8f6c95543",
            "SHA256": "8de6eae4e1479f02dc58281ad5c035e629345ff74a177e559192d03bd23e0f9f",
            "SHA384": "6fba402fc6da63e224d7b775f3377322607bfda2e9f00ea3a22705921ff4a9ea40b28bc032799ca30fe000df3e429793"
          },
          "ValidFrom": "2021-04-21 14:24:27",
          "ValidTo": "2022-03-25 19:57:48",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "77bd0e05b7590bb61d4761531e3f75ed",
          "Signature": "2575a009c939bab7a139892f189fabd6eb1d4be8947c0d07689b1c9def71b6176a6b024fb33f864587cc659b4ce35806022266d56102c5638fd4a2f1b65e250b7796e9cd7140338829eceef3a26dbc4db53e064bc97333ca08142d3d4ce8b0ba75a6742da4583a6c1349f8a5150a149685b16a68342542af9656f410fa247df12b72c116e16bebe6a998c73e5af4d0189dfd74978677462a3d237d28738aaeef2b1b9abf6c53a7149e3c8771c05e8ec8fbd32a9233ea574d5e075ecac118ac812d1a21fa6ecf97617bdf717a3aca63f7d530443732febb4385dcbafca6ca33192b776ddbcb05f07e5f752ea2b6bf35aa3663c9ce64d9bdfcbc2cf3495600c8122bc627bb37af57efc4cf1e29c4f4e22dce2a61cf57edf50a40e2f518d61ee9902fcad3875f938a481a111de537859f2e66629a5e814e95ac555743dc538b257e3c610f8a0bbaf53fa6d78ef704565e21bb9fd76a7180bf96de7203d8d8222bf327164f38e851400cae92efbe3d7df780c64c36578495a7841548300e5227088d8ea2bd22c719c9a6ca0ea87a36db6aba615f112495a4e28e68ee19a949995ed0b434bdd6f940c710973152393529118724d3c4fba963cb7748d5fa62fc24e0047a4ed0e46edece9e385026f4217165d70925d4c907007ab8c7f377e8c5d4e255d0d31ef67f52e2498db911720c88442633660144dfe4330e21de62894807daf5",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign GCC R45 EV CodeSigning CA 2020",
          "TBS": {
            "MD5": "65fd1dac1f115d9507f4e1840c8cb36a",
            "SHA1": "c7cf5607e19b22fe60c055e71d9b555d70f71f66",
            "SHA256": "d9c7db0b704f07089440c56e69a0f31d730edf77cfbf7514630e8b5390a270fe",
            "SHA384": "defe810317bd1215b4d1ee0ec8a5fb38b21d094ef1173cae670956cd899232638e4f9473fd947bd550a4a77300bbb2ab"
          },
          "ValidFrom": "2020-07-28 00:00:00",
          "ValidTo": "2030-07-28 00:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=BE, O=GlobalSign nv,sa, CN=GlobalSign GCC R45 EV CodeSigning CA 2020",
          "SerialNumber": "1f7b0de3090ee13a436315a6",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    source

    last_updated: 2024-09-26