Description Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
UUID : 0d039ee9-aaa5-49c2-a980-405d4290ee0aCreated : 2023-07-11Author : Michael HaagDownload
This download link contains the malicious driver!
Block telephonuAfY.sys across your endpoints Add this driver to your block policy in minutes with MagicSword, threat-driven application control. Free for up to 100 endpoints.
Start Blocking for Free Commands sc.exe create telephonuAfY.sys binPath=C:\windows\temp\telephonuAfY.sys type=kernel && sc.exe start telephonuAfY.sys
Use Case Privileges Operating System Elevate privileges kernel Windows 10
Detections Sigma 🛡️ Expand Names
detects loading using name only
Hashes
detects loading using hashes only
Resources https://blog.talosintelligence.com/undocumented-reddriver/ Known Vulnerable Samples Download
Certificates Expand Certificate 71a0b73695ddb1afc23b2b9a18ee54cb Field Value ToBeSigned (TBS) MD5 8314595952398203ab24badbbc927d39 ToBeSigned (TBS) SHA1 b07dcf73133408eee2786a208ce4b2543bf6c583 ToBeSigned (TBS) SHA256 c734685d985b8ea13db4fc1a6dcd26aa0dde78b4c3b651ea5d58e32e081b2a41 Subject C=US, O=thawte, Inc., CN=thawte SHA256 Code Signing CA ValidFrom 2013-12-10 00:00:00 ValidTo 2023-12-09 23:59:59 Signature 243bf5d7a03613c743fef0098768d198316e12e43f1e1f967b6b4c1e879e8bc56ca3b10c7b5092d5819cb18f2c29b7eef99105b98e41f12cf6d0592d98e0b9ea8001474095b83d9d03bd79bb35b6ad9c4c27f6674510c9c5bc874e557bd287bbdddc30efc6d46ccc99356d1ce060d3cd688f29594b89960846c98efc754fc5dc09cc4e278b44cd07bcac04e0b533a5879ff4dd730c91ea12816fe375f01eb5936c4417d53e97c9bd072c56771f85dd46e8bfde2c8194a3f7e5b7a7c1379f75ca55774d5e3629ca85d84541725775c0795bfa3410066d642042b73ac81f1d4664025fc647bef0c43a2854daf61e4f9aa21943a46f49f8fc5e422028848b47206e SignatureAlgorithmOID 1.2.840.113549.1.1.11 IsCertificateAuthority True SerialNumber 71a0b73695ddb1afc23b2b9a18ee54cb Version 3
Certificate 0dbdf488aeaa9795e332a1ca2747af0d Field Value ToBeSigned (TBS) MD5 5037c865c427f7d514ac954ef7e66ccf ToBeSigned (TBS) SHA1 cfcc3ebb5c9003e88373beb66781dbdf9e1904d2 ToBeSigned (TBS) SHA256 cd684ad96d510b669c0767e4b845fb7a04fba27c1f3a0935b09a988d94938f6e Subject C=CN, L=, O=, OU=, CN= ValidFrom 2018-08-15 00:00:00 ValidTo 2019-08-15 23:59:59 Signature 3ebdf2009f802c1033d2a14df88ed84c6282db1e8d19d6324b21ffb8e69fbc0752d101bd22ab4fae6c8c45bb82b7ba0d9a7213d7a29a2f587bdf68c7ae3ab6f9ed7cc23e27d6f44a0a5311124381f6f9bdeec2e19c59fc7362d5d59f09951b8ffa03215e5679ae4bcffe45b7059426a96c2897107c07b2b3e6cbcbee46527908db76f7a1bf2af19c986eba31504c9c5c3cb34e81ba2a1eb55965a2d192820cac79f640a3e9672bb507dc3a561de5d94f9a0105a355f42bea235ea5349d7d2b104a71c56640e0170433fe1ef075d9f865f17be8989b590765917215c0f7b709e9820f7106dff8cec57d59ee2777cec96f8b1de8e3a93bc7e7b757d87c9888b9a2 SignatureAlgorithmOID 1.2.840.113549.1.1.11 IsCertificateAuthority False SerialNumber 0dbdf488aeaa9795e332a1ca2747af0d Version 3
Certificate 611fb0a400000000001d Field Value ToBeSigned (TBS) MD5 a3f222107d4e1085e73b5b589c2f480b ToBeSigned (TBS) SHA1 b94aa26cd77c48d91a53ac44506cbd255e1d362c ToBeSigned (TBS) SHA256 a39ed0d6fd4eb1a6f7fed60f726e23eae668b7591bc004644625d22c701213fa Subject C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. , For authorized use only, CN=thawte Primary Root CA ValidFrom 2011-02-22 19:31:57 ValidTo 2021-02-22 19:41:57 Signature 2dcc71b5e8ba94ff5ee64467007b6afc412c3ee70e41855ab12a932ba95b89f2f72b499c8003f297b8e760a80ed7fd5de545467594f4ed1c9de166228b61fb29f2c6a8bdf387c98f7f47e1c058b64a1aa2e7f718606969e083069e26c775c40c0d79da746b52b9fae8ea3359b9bb18dd291a14dfd36a37277a9da0dacffffc22c4faf009ff33e93e17ba1cc742cfce2743d30c0c5581303db96060ce02ece19ee81ddc852ce0a18d966d95ac17a4713ea16741b6281d2ce3b615e5b7e5a2f6256d86e320acf9f8314f8e629b9833376d6af735523e90feb03b5fc5b852a9e06ea0479a279e97aea24a9e531939ec357ec659de3ae0aaf533f06abda0821812dea18c4570ca2bd62e959145995a5c240049bd23b30ceca43df5b9e1d1b1825a38eea3fba1ab483a8c5dffa065223fd3d3fe4990db1446a3852e8a554b09ab38b2ab63a008d1fdad48e273d812bcc26ca516fad09ac05e38383a2b718e553aac42197a1f0d4220e7ab5d8c6880524ca1c0d488d02321fb901309007b4937afa9df486022abf4f6c2363bf8513c34bbc586e43ae19f4b90fe5461024b159c34176aa94b8d4cb69d2326c83af1d6b805cdda1d6240183a2f1b41cd3a993a0aa9d1d77eb8c4aff7b8c980105ed55df6ce7a9a02c50f6381efb564e9fc5bd8d2619a68c37cf9c78df91e87d5fa2cf816ae9dab068fc86dc741cda14e84e3dac26ebcfb SignatureAlgorithmOID 1.2.840.113549.1.1.5 IsCertificateAuthority True SerialNumber 611fb0a400000000001d Version 3
Imports Expand fwpkclnt.sys ntoskrnl.exe WDFLDR.SYS Imported Functions Expand FwpsReleaseClassifyHandle0 FwpsAcquireClassifyHandle0 FwpsApplyModifiedLayerData0 FwpsAcquireWritableLayerDataPointer0 FwpsCalloutRegister1 RtlCompareMemory ExAllocatePool ExFreePoolWithTag CmRegisterCallback PsCreateSystemThread ZwClose MmIsAddressValid PsSetCreateProcessNotifyRoutine PsSetCreateThreadNotifyRoutine PsSetLoadImageNotifyRoutine __C_specific_handler RtlInitUnicodeString IofCompleteRequest IoCreateDevice IoCreateSymbolicLink IoDeleteDevice ObfDereferenceObject PsGetCurrentProcessId ZwOpenProcess PsLookupProcessByProcessId ZwWaitForSingleObject PsReferenceProcessFilePointer RtlCompareUnicodeStrings KeEnterCriticalRegion KeLeaveCriticalRegion KeWaitForSingleObject ExQueryDepthSList ExpInterlockedPopEntrySList ExpInterlockedPushEntrySList ExInitializeNPagedLookasideList ExInitializeResourceLite ExAcquireResourceSharedLite ExAcquireResourceExclusiveLite ExReleaseResourceLite PsTerminateSystemThread ObReferenceObjectByHandle KeStackAttachProcess KeUnstackDetachProcess PsGetProcessWow64Process PsGetProcessImageFileName ZwCreateFile ZwQueryInformationFile ZwReadFile ExAllocatePoolWithTag MmGetSystemRoutineAddress KeAcquireInStackQueuedSpinLock KeReleaseInStackQueuedSpinLock RtlIpv4AddressToStringA IoGetCurrentProcess PsGetProcessId PsProcessType PsGetProcessPeb RtlInitAnsiString RtlAnsiStringToUnicodeString RtlFreeUnicodeString _vsnprintf _vsnwprintf RtlGetVersion KeInitializeEvent KeQueryTimeIncrement RtlRandomEx ZwSetInformationFile ZwWriteFile IoFileObjectType ZwTerminateProcess RtlCopyUnicodeString KeBugCheckEx _wcslwr wcsstr ExSystemTimeToLocalTime RtlTimeToTimeFields WdfVersionBind WdfVersionBindClass WdfVersionUnbindClass WdfVersionUnbind Exported Functions Expand Sections Expand .text .rdata .data .pdata .gfids INIT .reloc Signature Expand {
"Certificates": [
{
"CertificateType": "CA",
"IsCA": true,
"IsCertificateAuthority": true,
"IsCodeSigning": true,
"SerialNumber": "71a0b73695ddb1afc23b2b9a18ee54cb",
"Signature": "243bf5d7a03613c743fef0098768d198316e12e43f1e1f967b6b4c1e879e8bc56ca3b10c7b5092d5819cb18f2c29b7eef99105b98e41f12cf6d0592d98e0b9ea8001474095b83d9d03bd79bb35b6ad9c4c27f6674510c9c5bc874e557bd287bbdddc30efc6d46ccc99356d1ce060d3cd688f29594b89960846c98efc754fc5dc09cc4e278b44cd07bcac04e0b533a5879ff4dd730c91ea12816fe375f01eb5936c4417d53e97c9bd072c56771f85dd46e8bfde2c8194a3f7e5b7a7c1379f75ca55774d5e3629ca85d84541725775c0795bfa3410066d642042b73ac81f1d4664025fc647bef0c43a2854daf61e4f9aa21943a46f49f8fc5e422028848b47206e",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, O=thawte, Inc., CN=thawte SHA256 Code Signing CA",
"TBS": {
"MD5": "8314595952398203ab24badbbc927d39",
"SHA1": "b07dcf73133408eee2786a208ce4b2543bf6c583",
"SHA256": "c734685d985b8ea13db4fc1a6dcd26aa0dde78b4c3b651ea5d58e32e081b2a41",
"SHA384": "874ded773c743b4e18744d7978b41cfe2e55529c61d45a0e34b3950aaad56b6c7a3780880133bcd1df3b1f86d468d46d"
},
"ValidFrom": "2013-12-10 00:00:00",
"ValidTo": "2023-12-09 23:59:59",
"Version": 3
},
{
"CertificateType": "Leaf (Code Signing)",
"IsCA": false,
"IsCertificateAuthority": false,
"IsCodeSigning": true,
"SerialNumber": "0dbdf488aeaa9795e332a1ca2747af0d",
"Signature": "3ebdf2009f802c1033d2a14df88ed84c6282db1e8d19d6324b21ffb8e69fbc0752d101bd22ab4fae6c8c45bb82b7ba0d9a7213d7a29a2f587bdf68c7ae3ab6f9ed7cc23e27d6f44a0a5311124381f6f9bdeec2e19c59fc7362d5d59f09951b8ffa03215e5679ae4bcffe45b7059426a96c2897107c07b2b3e6cbcbee46527908db76f7a1bf2af19c986eba31504c9c5c3cb34e81ba2a1eb55965a2d192820cac79f640a3e9672bb507dc3a561de5d94f9a0105a355f42bea235ea5349d7d2b104a71c56640e0170433fe1ef075d9f865f17be8989b590765917215c0f7b709e9820f7106dff8cec57d59ee2777cec96f8b1de8e3a93bc7e7b757d87c9888b9a2",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=CN, L=, O=, OU=, CN=",
"TBS": {
"MD5": "5037c865c427f7d514ac954ef7e66ccf",
"SHA1": "cfcc3ebb5c9003e88373beb66781dbdf9e1904d2",
"SHA256": "cd684ad96d510b669c0767e4b845fb7a04fba27c1f3a0935b09a988d94938f6e",
"SHA384": "30bf56d04a2a54ae834ea9b111da02fe53c0c13ddd66f815aed8100bb887c6d5b299e518ba1f4abc0f2c3bb02029141b"
},
"ValidFrom": "2018-08-15 00:00:00",
"ValidTo": "2019-08-15 23:59:59",
"Version": 3
},
{
"CertificateType": "CA",
"IsCA": true,
"IsCertificateAuthority": true,
"IsCodeSigning": false,
"SerialNumber": "611fb0a400000000001d",
"Signature": "2dcc71b5e8ba94ff5ee64467007b6afc412c3ee70e41855ab12a932ba95b89f2f72b499c8003f297b8e760a80ed7fd5de545467594f4ed1c9de166228b61fb29f2c6a8bdf387c98f7f47e1c058b64a1aa2e7f718606969e083069e26c775c40c0d79da746b52b9fae8ea3359b9bb18dd291a14dfd36a37277a9da0dacffffc22c4faf009ff33e93e17ba1cc742cfce2743d30c0c5581303db96060ce02ece19ee81ddc852ce0a18d966d95ac17a4713ea16741b6281d2ce3b615e5b7e5a2f6256d86e320acf9f8314f8e629b9833376d6af735523e90feb03b5fc5b852a9e06ea0479a279e97aea24a9e531939ec357ec659de3ae0aaf533f06abda0821812dea18c4570ca2bd62e959145995a5c240049bd23b30ceca43df5b9e1d1b1825a38eea3fba1ab483a8c5dffa065223fd3d3fe4990db1446a3852e8a554b09ab38b2ab63a008d1fdad48e273d812bcc26ca516fad09ac05e38383a2b718e553aac42197a1f0d4220e7ab5d8c6880524ca1c0d488d02321fb901309007b4937afa9df486022abf4f6c2363bf8513c34bbc586e43ae19f4b90fe5461024b159c34176aa94b8d4cb69d2326c83af1d6b805cdda1d6240183a2f1b41cd3a993a0aa9d1d77eb8c4aff7b8c980105ed55df6ce7a9a02c50f6381efb564e9fc5bd8d2619a68c37cf9c78df91e87d5fa2cf816ae9dab068fc86dc741cda14e84e3dac26ebcfb",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. , For authorized use only, CN=thawte Primary Root CA",
"TBS": {
"MD5": "a3f222107d4e1085e73b5b589c2f480b",
"SHA1": "b94aa26cd77c48d91a53ac44506cbd255e1d362c",
"SHA256": "a39ed0d6fd4eb1a6f7fed60f726e23eae668b7591bc004644625d22c701213fa",
"SHA384": "64b7643e4146016cbf83c911eb67e4601b6bb8d66f8ee8dcee67b815f91770d86ab23678b984430f22a963e5484881b7"
},
"ValidFrom": "2011-02-22 19:31:57",
"ValidTo": "2021-02-22 19:41:57",
"Version": 3
}
],
"CertificatesInfo": "",
"Signer": [
{
"Issuer": "C=US, O=thawte, Inc., CN=thawte SHA256 Code Signing CA",
"SerialNumber": "0dbdf488aeaa9795e332a1ca2747af0d",
"Version": 1
}
],
"SignerInfo": ""
}
Download
Certificates Expand Certificate 516ceb03f17e10c24b45ffb6336e5915 Field Value ToBeSigned (TBS) MD5 fe2cc3b135dc2f887e620d33a02ef639 ToBeSigned (TBS) SHA1 a92b0a710c038b8556fb3d74742118f75c5c3d57 ToBeSigned (TBS) SHA256 4b98540e377559d976ea0a9e40920f4a308a060fd16b27665fc7a8f2273df483 Subject C=CN, ST=Fuzhou, L=Fuqing, O=Fuqing Yuntan Network Tech Co.,Ltd., OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=Fuqing Yuntan Network Tech Co.,Ltd. ValidFrom 2013-04-09 00:00:00 ValidTo 2014-04-09 23:59:59 Signature 6946a8e63d6d38e19d41b4b5f4a71715c2c03ea0f9775b97dd3bf2d343be21049f4b78a351a0b1b8d30121393af537dfee0828f051ea2a87bed271ccc0e85e7ed9911d1d36d35da6e1141edc77520be857cf00bf3ac9b7e80722dd3580dd9eb7fab6f4134e4f1f1b794f1c28bc521ee4abbf5be4b6f2b149fca0f2beb4ba69616a0a442b06093c04ece1b42b0c121b0703c6a7d7af421a880bf3e45bfe28bcc4da347397d3aa67c89e3656062e9397dec782863abe49df79527e06388885b9d28c4bd078cc002a41206a266bfbe584b35748d6d0526fef478931c7527be7095fc9c7ee088f1c889834bb2533c3f45cfe41d1b19d0b80863ed52bc8a9d1b1d2ea SignatureAlgorithmOID 1.2.840.113549.1.1.5 IsCertificateAuthority False SerialNumber 516ceb03f17e10c24b45ffb6336e5915 Version 3
Certificate 611993e400000000001c Field Value ToBeSigned (TBS) MD5 78a717e082dcc1cda3458d917e677d14 ToBeSigned (TBS) SHA1 4a872e0e51f9b304469cd1dedb496ee9b8b983a4 ToBeSigned (TBS) SHA256 317fa1d234ebc49040ebc5e8746f8997471496051b185a91bdd9dfbb23fab5f8 Subject C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5 ValidFrom 2011-02-22 19:25:17 ValidTo 2021-02-22 19:35:17 Signature 812a82168c34672be503eb347b8ca2a3508af45586f11e8c8eae7dee0319ce72951848ad6211fd20fd3f4706015ae2e06f8c152c4e3c6a506c0b36a3cf7a0d9c42bc5cf819d560e369e6e22341678c6883762b8f93a32ab57fbe59fba9c9b2268fcaa2f3821b983e919527978661ee5b5d076bcd86a8e26580a8e215e2b2be23056aba0cf347934daca48c077939c061123a050d89a3ec9f578984fbecca7c47661491d8b60f195de6b84aacbc47c8714396e63220a5dc7786fd3ce38b71db7b9b03fcb71d3264eb1652a043a3fa2ead59924e7cc7f233424838513a7c38c71b242228401e1a461f17db18f7f027356cb863d9cdb9645d2ba55eefc629b4f2c7f821cc04ba57fd01b6abc667f9e7d3997ff4f522fa72f5fdff3a1c423aa1f98018a5ee8d1cd4669e4501feaaeefffb178f30f7f1cd29c59decb5d549003d85b8cbbb933a276a49c030ae66c9f723283276f9a48356c848ce5a96aaa0cc0cc47fb48e97af6de35427c39f86c0d6e473089705dbd054625e0348c2d59f7fa7668cd09db04fd4d3985f4b7ac97fb22952d01280c70f54b61e67cdc6a06c110384d34875e72afeb03b6e0a3aa66b769905a3f177686133144706fc537f52bd92145c4a246a678caf8d90aad0f679211b93267cc3ce1ebd883892ae45c6196a4950b305f8ae59378a6a250394b1598150e8ba8380b72335f476b9671d5918ad208d94 SignatureAlgorithmOID 1.2.840.113549.1.1.5 IsCertificateAuthority True SerialNumber 611993e400000000001c Version 3
Certificate 5200e5aa2556fc1a86ed96c9d44b33c7 Field Value ToBeSigned (TBS) MD5 b30c31a572b0409383ed3fbe17e56e81 ToBeSigned (TBS) SHA1 4843a82ed3b1f2bfbee9671960e1940c942f688d ToBeSigned (TBS) SHA256 03cda47a6e654ed85d932714fc09ce4874600eda29ec6628cfbaeb155cab78c9 Subject C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA ValidFrom 2010-02-08 00:00:00 ValidTo 2020-02-07 23:59:59 Signature 5622e634a4c461cb48b901ad56a8640fd98c91c4bbcc0ce5ad7aa0227fdf47384a2d6cd17f711a7cec70a9b1f04fe40f0c53fa155efe749849248581261c911447b04c638cbba134d4c645e80d85267303d0a98c646ddc7192e645056015595139fc58146bfed4a4ed796b080c4172e737220609be23e93f449a1ee9619dccb1905cfc3dd28dac423d6536d4b43d40288f9b10cf2326cc4b20cb901f5d8c4c34ca3cd8e537d66fa520bd34eb26d9ae0de7c59af7a1b42191336f86e858bb257c740e58fe751b633fce317c9b8f1b969ec55376845b9cad91faaced93ba5dc82153c2825363af120d5087111b3d5452968a2c9c3d921a089a052ec793a54891d3 SignatureAlgorithmOID 1.2.840.113549.1.1.5 IsCertificateAuthority True SerialNumber 5200e5aa2556fc1a86ed96c9d44b33c7 Version 3
Imports Expand fwpkclnt.sys ntoskrnl.exe WDFLDR.SYS Imported Functions Expand FwpsReleaseClassifyHandle0 FwpsAcquireClassifyHandle0 FwpsApplyModifiedLayerData0 FwpsAcquireWritableLayerDataPointer0 FwpsCalloutRegister1 RtlCompareMemory ExAllocatePool ExFreePoolWithTag CmRegisterCallback PsCreateSystemThread ZwClose MmIsAddressValid PsSetCreateProcessNotifyRoutine PsSetCreateThreadNotifyRoutine PsSetLoadImageNotifyRoutine __C_specific_handler RtlInitUnicodeString IofCompleteRequest IoCreateDevice IoCreateSymbolicLink IoDeleteDevice ObfDereferenceObject PsGetCurrentProcessId ZwOpenProcess PsLookupProcessByProcessId ZwWaitForSingleObject PsReferenceProcessFilePointer RtlCompareUnicodeStrings KeEnterCriticalRegion KeLeaveCriticalRegion KeWaitForSingleObject ExQueryDepthSList ExpInterlockedPopEntrySList ExpInterlockedPushEntrySList ExInitializeNPagedLookasideList ExInitializeResourceLite ExAcquireResourceSharedLite ExAcquireResourceExclusiveLite ExReleaseResourceLite PsTerminateSystemThread ObReferenceObjectByHandle KeStackAttachProcess KeUnstackDetachProcess PsGetProcessWow64Process PsGetProcessImageFileName ZwCreateFile ZwQueryInformationFile ZwReadFile ExAllocatePoolWithTag MmGetSystemRoutineAddress KeAcquireInStackQueuedSpinLock KeReleaseInStackQueuedSpinLock RtlIpv4AddressToStringA IoGetCurrentProcess PsGetProcessId PsProcessType PsGetProcessPeb RtlInitAnsiString RtlAnsiStringToUnicodeString RtlFreeUnicodeString _vsnprintf _vsnwprintf RtlGetVersion KeInitializeEvent KeQueryTimeIncrement RtlRandomEx ZwSetInformationFile ZwWriteFile IoFileObjectType ZwTerminateProcess RtlCopyUnicodeString KeBugCheckEx _wcslwr wcsstr ExSystemTimeToLocalTime RtlTimeToTimeFields WdfVersionBind WdfVersionBindClass WdfVersionUnbindClass WdfVersionUnbind Exported Functions Expand Sections Expand .text .rdata .data .pdata .gfids INIT .reloc Signature Expand {
"Certificates": [
{
"CertificateType": "CA",
"IsCA": true,
"IsCertificateAuthority": true,
"IsCodeSigning": true,
"SerialNumber": "71a0b73695ddb1afc23b2b9a18ee54cb",
"Signature": "243bf5d7a03613c743fef0098768d198316e12e43f1e1f967b6b4c1e879e8bc56ca3b10c7b5092d5819cb18f2c29b7eef99105b98e41f12cf6d0592d98e0b9ea8001474095b83d9d03bd79bb35b6ad9c4c27f6674510c9c5bc874e557bd287bbdddc30efc6d46ccc99356d1ce060d3cd688f29594b89960846c98efc754fc5dc09cc4e278b44cd07bcac04e0b533a5879ff4dd730c91ea12816fe375f01eb5936c4417d53e97c9bd072c56771f85dd46e8bfde2c8194a3f7e5b7a7c1379f75ca55774d5e3629ca85d84541725775c0795bfa3410066d642042b73ac81f1d4664025fc647bef0c43a2854daf61e4f9aa21943a46f49f8fc5e422028848b47206e",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, O=thawte, Inc., CN=thawte SHA256 Code Signing CA",
"TBS": {
"MD5": "8314595952398203ab24badbbc927d39",
"SHA1": "b07dcf73133408eee2786a208ce4b2543bf6c583",
"SHA256": "c734685d985b8ea13db4fc1a6dcd26aa0dde78b4c3b651ea5d58e32e081b2a41",
"SHA384": "874ded773c743b4e18744d7978b41cfe2e55529c61d45a0e34b3950aaad56b6c7a3780880133bcd1df3b1f86d468d46d"
},
"ValidFrom": "2013-12-10 00:00:00",
"ValidTo": "2023-12-09 23:59:59",
"Version": 3
},
{
"CertificateType": "Leaf (Code Signing)",
"IsCA": false,
"IsCertificateAuthority": false,
"IsCodeSigning": true,
"SerialNumber": "0dbdf488aeaa9795e332a1ca2747af0d",
"Signature": "3ebdf2009f802c1033d2a14df88ed84c6282db1e8d19d6324b21ffb8e69fbc0752d101bd22ab4fae6c8c45bb82b7ba0d9a7213d7a29a2f587bdf68c7ae3ab6f9ed7cc23e27d6f44a0a5311124381f6f9bdeec2e19c59fc7362d5d59f09951b8ffa03215e5679ae4bcffe45b7059426a96c2897107c07b2b3e6cbcbee46527908db76f7a1bf2af19c986eba31504c9c5c3cb34e81ba2a1eb55965a2d192820cac79f640a3e9672bb507dc3a561de5d94f9a0105a355f42bea235ea5349d7d2b104a71c56640e0170433fe1ef075d9f865f17be8989b590765917215c0f7b709e9820f7106dff8cec57d59ee2777cec96f8b1de8e3a93bc7e7b757d87c9888b9a2",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=CN, L=, O=, OU=, CN=",
"TBS": {
"MD5": "5037c865c427f7d514ac954ef7e66ccf",
"SHA1": "cfcc3ebb5c9003e88373beb66781dbdf9e1904d2",
"SHA256": "cd684ad96d510b669c0767e4b845fb7a04fba27c1f3a0935b09a988d94938f6e",
"SHA384": "30bf56d04a2a54ae834ea9b111da02fe53c0c13ddd66f815aed8100bb887c6d5b299e518ba1f4abc0f2c3bb02029141b"
},
"ValidFrom": "2018-08-15 00:00:00",
"ValidTo": "2019-08-15 23:59:59",
"Version": 3
},
{
"CertificateType": "CA",
"IsCA": true,
"IsCertificateAuthority": true,
"IsCodeSigning": false,
"SerialNumber": "611fb0a400000000001d",
"Signature": "2dcc71b5e8ba94ff5ee64467007b6afc412c3ee70e41855ab12a932ba95b89f2f72b499c8003f297b8e760a80ed7fd5de545467594f4ed1c9de166228b61fb29f2c6a8bdf387c98f7f47e1c058b64a1aa2e7f718606969e083069e26c775c40c0d79da746b52b9fae8ea3359b9bb18dd291a14dfd36a37277a9da0dacffffc22c4faf009ff33e93e17ba1cc742cfce2743d30c0c5581303db96060ce02ece19ee81ddc852ce0a18d966d95ac17a4713ea16741b6281d2ce3b615e5b7e5a2f6256d86e320acf9f8314f8e629b9833376d6af735523e90feb03b5fc5b852a9e06ea0479a279e97aea24a9e531939ec357ec659de3ae0aaf533f06abda0821812dea18c4570ca2bd62e959145995a5c240049bd23b30ceca43df5b9e1d1b1825a38eea3fba1ab483a8c5dffa065223fd3d3fe4990db1446a3852e8a554b09ab38b2ab63a008d1fdad48e273d812bcc26ca516fad09ac05e38383a2b718e553aac42197a1f0d4220e7ab5d8c6880524ca1c0d488d02321fb901309007b4937afa9df486022abf4f6c2363bf8513c34bbc586e43ae19f4b90fe5461024b159c34176aa94b8d4cb69d2326c83af1d6b805cdda1d6240183a2f1b41cd3a993a0aa9d1d77eb8c4aff7b8c980105ed55df6ce7a9a02c50f6381efb564e9fc5bd8d2619a68c37cf9c78df91e87d5fa2cf816ae9dab068fc86dc741cda14e84e3dac26ebcfb",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. , For authorized use only, CN=thawte Primary Root CA",
"TBS": {
"MD5": "a3f222107d4e1085e73b5b589c2f480b",
"SHA1": "b94aa26cd77c48d91a53ac44506cbd255e1d362c",
"SHA256": "a39ed0d6fd4eb1a6f7fed60f726e23eae668b7591bc004644625d22c701213fa",
"SHA384": "64b7643e4146016cbf83c911eb67e4601b6bb8d66f8ee8dcee67b815f91770d86ab23678b984430f22a963e5484881b7"
},
"ValidFrom": "2011-02-22 19:31:57",
"ValidTo": "2021-02-22 19:41:57",
"Version": 3
}
],
"CertificatesInfo": "",
"Signer": [
{
"Issuer": "C=US, O=thawte, Inc., CN=thawte SHA256 Code Signing CA",
"SerialNumber": "0dbdf488aeaa9795e332a1ca2747af0d",
"Version": 1
}
],
"SignerInfo": ""
}
Download
Certificates Expand Certificate 2ac01de88063badb080008853fdd8c6c Field Value ToBeSigned (TBS) MD5 bac0d95b77a36eed50d84415420e56bd ToBeSigned (TBS) SHA1 c107a2a8939e3ff203847e4ba576c7e3767c063a ToBeSigned (TBS) SHA256 7f648cc593ad1a699a8d5a5c972bf1cce89bf3dfd83a67f46de3230c61429fe2 Subject C=CN, ST=湖南省, L=长沙市, O=湖南蓝途方鼎科技有限公司, CN=湖南蓝途方鼎科技有限公司 ValidFrom 2015-04-02 00:00:00 ValidTo 2016-05-01 23:59:59 Signature 9331a576a43dc4e3a4132367b220e74c25851759c04d2db3b42beadbbd370c57aa3990faf580df88d99f8a5ac7836940ebce2b68b7b6b4e804e51b663a10d705b1dc5bc621a7b36ce633ae37e603fb0ae46d0fdaa1bf5ceb7d3262de99aaddeacd2672567bf55dda8e4b839cc1bc772574f0c6808763418a3cf63f596ef1ec038f05a2eab3c476b167fff75d6320069352409f4768f73c3af2b6438ab5279f511e1f8ebd3bed90a81c87338af839a538cb15f4b49de377c039847517a334f72130a8e4b7085a65ebe32cbdda528524dbdd27f74f4e75ff427d7bf40807faff55adcf287fc6aa06d10863511de08a00a546367efa0faeed0c587582d566f798db SignatureAlgorithmOID 1.2.840.113549.1.1.5 IsCertificateAuthority False SerialNumber 2ac01de88063badb080008853fdd8c6c Version 3
Certificate 611993e400000000001c Field Value ToBeSigned (TBS) MD5 78a717e082dcc1cda3458d917e677d14 ToBeSigned (TBS) SHA1 4a872e0e51f9b304469cd1dedb496ee9b8b983a4 ToBeSigned (TBS) SHA256 317fa1d234ebc49040ebc5e8746f8997471496051b185a91bdd9dfbb23fab5f8 Subject C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5 ValidFrom 2011-02-22 19:25:17 ValidTo 2021-02-22 19:35:17 Signature 812a82168c34672be503eb347b8ca2a3508af45586f11e8c8eae7dee0319ce72951848ad6211fd20fd3f4706015ae2e06f8c152c4e3c6a506c0b36a3cf7a0d9c42bc5cf819d560e369e6e22341678c6883762b8f93a32ab57fbe59fba9c9b2268fcaa2f3821b983e919527978661ee5b5d076bcd86a8e26580a8e215e2b2be23056aba0cf347934daca48c077939c061123a050d89a3ec9f578984fbecca7c47661491d8b60f195de6b84aacbc47c8714396e63220a5dc7786fd3ce38b71db7b9b03fcb71d3264eb1652a043a3fa2ead59924e7cc7f233424838513a7c38c71b242228401e1a461f17db18f7f027356cb863d9cdb9645d2ba55eefc629b4f2c7f821cc04ba57fd01b6abc667f9e7d3997ff4f522fa72f5fdff3a1c423aa1f98018a5ee8d1cd4669e4501feaaeefffb178f30f7f1cd29c59decb5d549003d85b8cbbb933a276a49c030ae66c9f723283276f9a48356c848ce5a96aaa0cc0cc47fb48e97af6de35427c39f86c0d6e473089705dbd054625e0348c2d59f7fa7668cd09db04fd4d3985f4b7ac97fb22952d01280c70f54b61e67cdc6a06c110384d34875e72afeb03b6e0a3aa66b769905a3f177686133144706fc537f52bd92145c4a246a678caf8d90aad0f679211b93267cc3ce1ebd883892ae45c6196a4950b305f8ae59378a6a250394b1598150e8ba8380b72335f476b9671d5918ad208d94 SignatureAlgorithmOID 1.2.840.113549.1.1.5 IsCertificateAuthority True SerialNumber 611993e400000000001c Version 3
Certificate 5200e5aa2556fc1a86ed96c9d44b33c7 Field Value ToBeSigned (TBS) MD5 b30c31a572b0409383ed3fbe17e56e81 ToBeSigned (TBS) SHA1 4843a82ed3b1f2bfbee9671960e1940c942f688d ToBeSigned (TBS) SHA256 03cda47a6e654ed85d932714fc09ce4874600eda29ec6628cfbaeb155cab78c9 Subject C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA ValidFrom 2010-02-08 00:00:00 ValidTo 2020-02-07 23:59:59 Signature 5622e634a4c461cb48b901ad56a8640fd98c91c4bbcc0ce5ad7aa0227fdf47384a2d6cd17f711a7cec70a9b1f04fe40f0c53fa155efe749849248581261c911447b04c638cbba134d4c645e80d85267303d0a98c646ddc7192e645056015595139fc58146bfed4a4ed796b080c4172e737220609be23e93f449a1ee9619dccb1905cfc3dd28dac423d6536d4b43d40288f9b10cf2326cc4b20cb901f5d8c4c34ca3cd8e537d66fa520bd34eb26d9ae0de7c59af7a1b42191336f86e858bb257c740e58fe751b633fce317c9b8f1b969ec55376845b9cad91faaced93ba5dc82153c2825363af120d5087111b3d5452968a2c9c3d921a089a052ec793a54891d3 SignatureAlgorithmOID 1.2.840.113549.1.1.5 IsCertificateAuthority True SerialNumber 5200e5aa2556fc1a86ed96c9d44b33c7 Version 3
Imports Expand fwpkclnt.sys ntoskrnl.exe WDFLDR.SYS Imported Functions Expand FwpsReleaseClassifyHandle0 FwpsAcquireClassifyHandle0 FwpsApplyModifiedLayerData0 FwpsAcquireWritableLayerDataPointer0 FwpsCalloutRegister1 RtlCompareMemory ExAllocatePool ExFreePoolWithTag CmRegisterCallback PsCreateSystemThread ZwClose MmIsAddressValid PsSetCreateProcessNotifyRoutine PsSetCreateThreadNotifyRoutine PsSetLoadImageNotifyRoutine __C_specific_handler RtlInitUnicodeString IofCompleteRequest IoCreateDevice IoCreateSymbolicLink IoDeleteDevice ObfDereferenceObject PsGetCurrentProcessId ZwOpenProcess PsLookupProcessByProcessId ZwWaitForSingleObject PsReferenceProcessFilePointer RtlCompareUnicodeStrings KeEnterCriticalRegion KeLeaveCriticalRegion KeWaitForSingleObject ExQueryDepthSList ExpInterlockedPopEntrySList ExpInterlockedPushEntrySList ExInitializeNPagedLookasideList ExInitializeResourceLite ExAcquireResourceSharedLite ExAcquireResourceExclusiveLite ExReleaseResourceLite PsTerminateSystemThread ObReferenceObjectByHandle KeStackAttachProcess KeUnstackDetachProcess PsGetProcessWow64Process PsGetProcessImageFileName ZwCreateFile ZwQueryInformationFile ZwReadFile ExAllocatePoolWithTag MmGetSystemRoutineAddress KeAcquireInStackQueuedSpinLock KeReleaseInStackQueuedSpinLock RtlIpv4AddressToStringA IoGetCurrentProcess PsGetProcessId PsProcessType PsGetProcessPeb RtlInitAnsiString RtlAnsiStringToUnicodeString RtlFreeUnicodeString _vsnprintf _vsnwprintf RtlGetVersion KeInitializeEvent KeQueryTimeIncrement RtlRandomEx ZwSetInformationFile ZwWriteFile IoFileObjectType ZwTerminateProcess RtlCopyUnicodeString KeBugCheckEx _wcslwr wcsstr ExSystemTimeToLocalTime RtlTimeToTimeFields WdfVersionBind WdfVersionBindClass WdfVersionUnbindClass WdfVersionUnbind Exported Functions Expand Sections Expand .text .rdata .data .pdata .gfids INIT .reloc Signature Expand {
"Certificates": [
{
"CertificateType": "CA",
"IsCA": true,
"IsCertificateAuthority": true,
"IsCodeSigning": true,
"SerialNumber": "71a0b73695ddb1afc23b2b9a18ee54cb",
"Signature": "243bf5d7a03613c743fef0098768d198316e12e43f1e1f967b6b4c1e879e8bc56ca3b10c7b5092d5819cb18f2c29b7eef99105b98e41f12cf6d0592d98e0b9ea8001474095b83d9d03bd79bb35b6ad9c4c27f6674510c9c5bc874e557bd287bbdddc30efc6d46ccc99356d1ce060d3cd688f29594b89960846c98efc754fc5dc09cc4e278b44cd07bcac04e0b533a5879ff4dd730c91ea12816fe375f01eb5936c4417d53e97c9bd072c56771f85dd46e8bfde2c8194a3f7e5b7a7c1379f75ca55774d5e3629ca85d84541725775c0795bfa3410066d642042b73ac81f1d4664025fc647bef0c43a2854daf61e4f9aa21943a46f49f8fc5e422028848b47206e",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, O=thawte, Inc., CN=thawte SHA256 Code Signing CA",
"TBS": {
"MD5": "8314595952398203ab24badbbc927d39",
"SHA1": "b07dcf73133408eee2786a208ce4b2543bf6c583",
"SHA256": "c734685d985b8ea13db4fc1a6dcd26aa0dde78b4c3b651ea5d58e32e081b2a41",
"SHA384": "874ded773c743b4e18744d7978b41cfe2e55529c61d45a0e34b3950aaad56b6c7a3780880133bcd1df3b1f86d468d46d"
},
"ValidFrom": "2013-12-10 00:00:00",
"ValidTo": "2023-12-09 23:59:59",
"Version": 3
},
{
"CertificateType": "Leaf (Code Signing)",
"IsCA": false,
"IsCertificateAuthority": false,
"IsCodeSigning": true,
"SerialNumber": "0dbdf488aeaa9795e332a1ca2747af0d",
"Signature": "3ebdf2009f802c1033d2a14df88ed84c6282db1e8d19d6324b21ffb8e69fbc0752d101bd22ab4fae6c8c45bb82b7ba0d9a7213d7a29a2f587bdf68c7ae3ab6f9ed7cc23e27d6f44a0a5311124381f6f9bdeec2e19c59fc7362d5d59f09951b8ffa03215e5679ae4bcffe45b7059426a96c2897107c07b2b3e6cbcbee46527908db76f7a1bf2af19c986eba31504c9c5c3cb34e81ba2a1eb55965a2d192820cac79f640a3e9672bb507dc3a561de5d94f9a0105a355f42bea235ea5349d7d2b104a71c56640e0170433fe1ef075d9f865f17be8989b590765917215c0f7b709e9820f7106dff8cec57d59ee2777cec96f8b1de8e3a93bc7e7b757d87c9888b9a2",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=CN, L=, O=, OU=, CN=",
"TBS": {
"MD5": "5037c865c427f7d514ac954ef7e66ccf",
"SHA1": "cfcc3ebb5c9003e88373beb66781dbdf9e1904d2",
"SHA256": "cd684ad96d510b669c0767e4b845fb7a04fba27c1f3a0935b09a988d94938f6e",
"SHA384": "30bf56d04a2a54ae834ea9b111da02fe53c0c13ddd66f815aed8100bb887c6d5b299e518ba1f4abc0f2c3bb02029141b"
},
"ValidFrom": "2018-08-15 00:00:00",
"ValidTo": "2019-08-15 23:59:59",
"Version": 3
},
{
"CertificateType": "CA",
"IsCA": true,
"IsCertificateAuthority": true,
"IsCodeSigning": false,
"SerialNumber": "611fb0a400000000001d",
"Signature": "2dcc71b5e8ba94ff5ee64467007b6afc412c3ee70e41855ab12a932ba95b89f2f72b499c8003f297b8e760a80ed7fd5de545467594f4ed1c9de166228b61fb29f2c6a8bdf387c98f7f47e1c058b64a1aa2e7f718606969e083069e26c775c40c0d79da746b52b9fae8ea3359b9bb18dd291a14dfd36a37277a9da0dacffffc22c4faf009ff33e93e17ba1cc742cfce2743d30c0c5581303db96060ce02ece19ee81ddc852ce0a18d966d95ac17a4713ea16741b6281d2ce3b615e5b7e5a2f6256d86e320acf9f8314f8e629b9833376d6af735523e90feb03b5fc5b852a9e06ea0479a279e97aea24a9e531939ec357ec659de3ae0aaf533f06abda0821812dea18c4570ca2bd62e959145995a5c240049bd23b30ceca43df5b9e1d1b1825a38eea3fba1ab483a8c5dffa065223fd3d3fe4990db1446a3852e8a554b09ab38b2ab63a008d1fdad48e273d812bcc26ca516fad09ac05e38383a2b718e553aac42197a1f0d4220e7ab5d8c6880524ca1c0d488d02321fb901309007b4937afa9df486022abf4f6c2363bf8513c34bbc586e43ae19f4b90fe5461024b159c34176aa94b8d4cb69d2326c83af1d6b805cdda1d6240183a2f1b41cd3a993a0aa9d1d77eb8c4aff7b8c980105ed55df6ce7a9a02c50f6381efb564e9fc5bd8d2619a68c37cf9c78df91e87d5fa2cf816ae9dab068fc86dc741cda14e84e3dac26ebcfb",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. , For authorized use only, CN=thawte Primary Root CA",
"TBS": {
"MD5": "a3f222107d4e1085e73b5b589c2f480b",
"SHA1": "b94aa26cd77c48d91a53ac44506cbd255e1d362c",
"SHA256": "a39ed0d6fd4eb1a6f7fed60f726e23eae668b7591bc004644625d22c701213fa",
"SHA384": "64b7643e4146016cbf83c911eb67e4601b6bb8d66f8ee8dcee67b815f91770d86ab23678b984430f22a963e5484881b7"
},
"ValidFrom": "2011-02-22 19:31:57",
"ValidTo": "2021-02-22 19:41:57",
"Version": 3
}
],
"CertificatesInfo": "",
"Signer": [
{
"Issuer": "C=US, O=thawte, Inc., CN=thawte SHA256 Code Signing CA",
"SerialNumber": "0dbdf488aeaa9795e332a1ca2747af0d",
"Version": 1
}
],
"SignerInfo": ""
}
Download
Certificates Expand Certificate 2ac01de88063badb080008853fdd8c6c Field Value ToBeSigned (TBS) MD5 bac0d95b77a36eed50d84415420e56bd ToBeSigned (TBS) SHA1 c107a2a8939e3ff203847e4ba576c7e3767c063a ToBeSigned (TBS) SHA256 7f648cc593ad1a699a8d5a5c972bf1cce89bf3dfd83a67f46de3230c61429fe2 Subject C=CN, ST=湖南省, L=长沙市, O=湖南蓝途方鼎科技有限公司, CN=湖南蓝途方鼎科技有限公司 ValidFrom 2015-04-02 00:00:00 ValidTo 2016-05-01 23:59:59 Signature 9331a576a43dc4e3a4132367b220e74c25851759c04d2db3b42beadbbd370c57aa3990faf580df88d99f8a5ac7836940ebce2b68b7b6b4e804e51b663a10d705b1dc5bc621a7b36ce633ae37e603fb0ae46d0fdaa1bf5ceb7d3262de99aaddeacd2672567bf55dda8e4b839cc1bc772574f0c6808763418a3cf63f596ef1ec038f05a2eab3c476b167fff75d6320069352409f4768f73c3af2b6438ab5279f511e1f8ebd3bed90a81c87338af839a538cb15f4b49de377c039847517a334f72130a8e4b7085a65ebe32cbdda528524dbdd27f74f4e75ff427d7bf40807faff55adcf287fc6aa06d10863511de08a00a546367efa0faeed0c587582d566f798db SignatureAlgorithmOID 1.2.840.113549.1.1.5 IsCertificateAuthority False SerialNumber 2ac01de88063badb080008853fdd8c6c Version 3
Certificate 611993e400000000001c Field Value ToBeSigned (TBS) MD5 78a717e082dcc1cda3458d917e677d14 ToBeSigned (TBS) SHA1 4a872e0e51f9b304469cd1dedb496ee9b8b983a4 ToBeSigned (TBS) SHA256 317fa1d234ebc49040ebc5e8746f8997471496051b185a91bdd9dfbb23fab5f8 Subject C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5 ValidFrom 2011-02-22 19:25:17 ValidTo 2021-02-22 19:35:17 Signature 812a82168c34672be503eb347b8ca2a3508af45586f11e8c8eae7dee0319ce72951848ad6211fd20fd3f4706015ae2e06f8c152c4e3c6a506c0b36a3cf7a0d9c42bc5cf819d560e369e6e22341678c6883762b8f93a32ab57fbe59fba9c9b2268fcaa2f3821b983e919527978661ee5b5d076bcd86a8e26580a8e215e2b2be23056aba0cf347934daca48c077939c061123a050d89a3ec9f578984fbecca7c47661491d8b60f195de6b84aacbc47c8714396e63220a5dc7786fd3ce38b71db7b9b03fcb71d3264eb1652a043a3fa2ead59924e7cc7f233424838513a7c38c71b242228401e1a461f17db18f7f027356cb863d9cdb9645d2ba55eefc629b4f2c7f821cc04ba57fd01b6abc667f9e7d3997ff4f522fa72f5fdff3a1c423aa1f98018a5ee8d1cd4669e4501feaaeefffb178f30f7f1cd29c59decb5d549003d85b8cbbb933a276a49c030ae66c9f723283276f9a48356c848ce5a96aaa0cc0cc47fb48e97af6de35427c39f86c0d6e473089705dbd054625e0348c2d59f7fa7668cd09db04fd4d3985f4b7ac97fb22952d01280c70f54b61e67cdc6a06c110384d34875e72afeb03b6e0a3aa66b769905a3f177686133144706fc537f52bd92145c4a246a678caf8d90aad0f679211b93267cc3ce1ebd883892ae45c6196a4950b305f8ae59378a6a250394b1598150e8ba8380b72335f476b9671d5918ad208d94 SignatureAlgorithmOID 1.2.840.113549.1.1.5 IsCertificateAuthority True SerialNumber 611993e400000000001c Version 3
Certificate 5200e5aa2556fc1a86ed96c9d44b33c7 Field Value ToBeSigned (TBS) MD5 b30c31a572b0409383ed3fbe17e56e81 ToBeSigned (TBS) SHA1 4843a82ed3b1f2bfbee9671960e1940c942f688d ToBeSigned (TBS) SHA256 03cda47a6e654ed85d932714fc09ce4874600eda29ec6628cfbaeb155cab78c9 Subject C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA ValidFrom 2010-02-08 00:00:00 ValidTo 2020-02-07 23:59:59 Signature 5622e634a4c461cb48b901ad56a8640fd98c91c4bbcc0ce5ad7aa0227fdf47384a2d6cd17f711a7cec70a9b1f04fe40f0c53fa155efe749849248581261c911447b04c638cbba134d4c645e80d85267303d0a98c646ddc7192e645056015595139fc58146bfed4a4ed796b080c4172e737220609be23e93f449a1ee9619dccb1905cfc3dd28dac423d6536d4b43d40288f9b10cf2326cc4b20cb901f5d8c4c34ca3cd8e537d66fa520bd34eb26d9ae0de7c59af7a1b42191336f86e858bb257c740e58fe751b633fce317c9b8f1b969ec55376845b9cad91faaced93ba5dc82153c2825363af120d5087111b3d5452968a2c9c3d921a089a052ec793a54891d3 SignatureAlgorithmOID 1.2.840.113549.1.1.5 IsCertificateAuthority True SerialNumber 5200e5aa2556fc1a86ed96c9d44b33c7 Version 3
Imports Expand fwpkclnt.sys ntoskrnl.exe WDFLDR.SYS Imported Functions Expand FwpsReleaseClassifyHandle0 FwpsAcquireClassifyHandle0 FwpsApplyModifiedLayerData0 FwpsAcquireWritableLayerDataPointer0 FwpsCalloutRegister1 RtlCompareMemory ExAllocatePool ExFreePoolWithTag CmRegisterCallback PsCreateSystemThread ZwClose MmIsAddressValid PsSetCreateProcessNotifyRoutine PsSetCreateThreadNotifyRoutine PsSetLoadImageNotifyRoutine __C_specific_handler RtlInitUnicodeString IofCompleteRequest IoCreateDevice IoCreateSymbolicLink IoDeleteDevice ObfDereferenceObject PsGetCurrentProcessId ZwOpenProcess PsLookupProcessByProcessId ZwWaitForSingleObject PsReferenceProcessFilePointer RtlCompareUnicodeStrings KeEnterCriticalRegion KeLeaveCriticalRegion KeWaitForSingleObject ExQueryDepthSList ExpInterlockedPopEntrySList ExpInterlockedPushEntrySList ExInitializeNPagedLookasideList ExInitializeResourceLite ExAcquireResourceSharedLite ExAcquireResourceExclusiveLite ExReleaseResourceLite PsTerminateSystemThread ObReferenceObjectByHandle KeStackAttachProcess KeUnstackDetachProcess PsGetProcessWow64Process PsGetProcessImageFileName ZwCreateFile ZwQueryInformationFile ZwReadFile ExAllocatePoolWithTag MmGetSystemRoutineAddress KeAcquireInStackQueuedSpinLock KeReleaseInStackQueuedSpinLock RtlIpv4AddressToStringA IoGetCurrentProcess PsGetProcessId PsProcessType PsGetProcessPeb RtlInitAnsiString RtlAnsiStringToUnicodeString RtlFreeUnicodeString _vsnprintf _vsnwprintf RtlGetVersion KeInitializeEvent KeQueryTimeIncrement RtlRandomEx ZwSetInformationFile ZwWriteFile IoFileObjectType ZwTerminateProcess RtlCopyUnicodeString KeBugCheckEx _wcslwr wcsstr ExSystemTimeToLocalTime RtlTimeToTimeFields WdfVersionBind WdfVersionBindClass WdfVersionUnbindClass WdfVersionUnbind Exported Functions Expand Sections Expand .text .rdata .data .pdata .gfids INIT .reloc Signature Expand {
"Certificates": [
{
"CertificateType": "CA",
"IsCA": true,
"IsCertificateAuthority": true,
"IsCodeSigning": true,
"SerialNumber": "71a0b73695ddb1afc23b2b9a18ee54cb",
"Signature": "243bf5d7a03613c743fef0098768d198316e12e43f1e1f967b6b4c1e879e8bc56ca3b10c7b5092d5819cb18f2c29b7eef99105b98e41f12cf6d0592d98e0b9ea8001474095b83d9d03bd79bb35b6ad9c4c27f6674510c9c5bc874e557bd287bbdddc30efc6d46ccc99356d1ce060d3cd688f29594b89960846c98efc754fc5dc09cc4e278b44cd07bcac04e0b533a5879ff4dd730c91ea12816fe375f01eb5936c4417d53e97c9bd072c56771f85dd46e8bfde2c8194a3f7e5b7a7c1379f75ca55774d5e3629ca85d84541725775c0795bfa3410066d642042b73ac81f1d4664025fc647bef0c43a2854daf61e4f9aa21943a46f49f8fc5e422028848b47206e",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, O=thawte, Inc., CN=thawte SHA256 Code Signing CA",
"TBS": {
"MD5": "8314595952398203ab24badbbc927d39",
"SHA1": "b07dcf73133408eee2786a208ce4b2543bf6c583",
"SHA256": "c734685d985b8ea13db4fc1a6dcd26aa0dde78b4c3b651ea5d58e32e081b2a41",
"SHA384": "874ded773c743b4e18744d7978b41cfe2e55529c61d45a0e34b3950aaad56b6c7a3780880133bcd1df3b1f86d468d46d"
},
"ValidFrom": "2013-12-10 00:00:00",
"ValidTo": "2023-12-09 23:59:59",
"Version": 3
},
{
"CertificateType": "Leaf (Code Signing)",
"IsCA": false,
"IsCertificateAuthority": false,
"IsCodeSigning": true,
"SerialNumber": "0dbdf488aeaa9795e332a1ca2747af0d",
"Signature": "3ebdf2009f802c1033d2a14df88ed84c6282db1e8d19d6324b21ffb8e69fbc0752d101bd22ab4fae6c8c45bb82b7ba0d9a7213d7a29a2f587bdf68c7ae3ab6f9ed7cc23e27d6f44a0a5311124381f6f9bdeec2e19c59fc7362d5d59f09951b8ffa03215e5679ae4bcffe45b7059426a96c2897107c07b2b3e6cbcbee46527908db76f7a1bf2af19c986eba31504c9c5c3cb34e81ba2a1eb55965a2d192820cac79f640a3e9672bb507dc3a561de5d94f9a0105a355f42bea235ea5349d7d2b104a71c56640e0170433fe1ef075d9f865f17be8989b590765917215c0f7b709e9820f7106dff8cec57d59ee2777cec96f8b1de8e3a93bc7e7b757d87c9888b9a2",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=CN, L=, O=, OU=, CN=",
"TBS": {
"MD5": "5037c865c427f7d514ac954ef7e66ccf",
"SHA1": "cfcc3ebb5c9003e88373beb66781dbdf9e1904d2",
"SHA256": "cd684ad96d510b669c0767e4b845fb7a04fba27c1f3a0935b09a988d94938f6e",
"SHA384": "30bf56d04a2a54ae834ea9b111da02fe53c0c13ddd66f815aed8100bb887c6d5b299e518ba1f4abc0f2c3bb02029141b"
},
"ValidFrom": "2018-08-15 00:00:00",
"ValidTo": "2019-08-15 23:59:59",
"Version": 3
},
{
"CertificateType": "CA",
"IsCA": true,
"IsCertificateAuthority": true,
"IsCodeSigning": false,
"SerialNumber": "611fb0a400000000001d",
"Signature": "2dcc71b5e8ba94ff5ee64467007b6afc412c3ee70e41855ab12a932ba95b89f2f72b499c8003f297b8e760a80ed7fd5de545467594f4ed1c9de166228b61fb29f2c6a8bdf387c98f7f47e1c058b64a1aa2e7f718606969e083069e26c775c40c0d79da746b52b9fae8ea3359b9bb18dd291a14dfd36a37277a9da0dacffffc22c4faf009ff33e93e17ba1cc742cfce2743d30c0c5581303db96060ce02ece19ee81ddc852ce0a18d966d95ac17a4713ea16741b6281d2ce3b615e5b7e5a2f6256d86e320acf9f8314f8e629b9833376d6af735523e90feb03b5fc5b852a9e06ea0479a279e97aea24a9e531939ec357ec659de3ae0aaf533f06abda0821812dea18c4570ca2bd62e959145995a5c240049bd23b30ceca43df5b9e1d1b1825a38eea3fba1ab483a8c5dffa065223fd3d3fe4990db1446a3852e8a554b09ab38b2ab63a008d1fdad48e273d812bcc26ca516fad09ac05e38383a2b718e553aac42197a1f0d4220e7ab5d8c6880524ca1c0d488d02321fb901309007b4937afa9df486022abf4f6c2363bf8513c34bbc586e43ae19f4b90fe5461024b159c34176aa94b8d4cb69d2326c83af1d6b805cdda1d6240183a2f1b41cd3a993a0aa9d1d77eb8c4aff7b8c980105ed55df6ce7a9a02c50f6381efb564e9fc5bd8d2619a68c37cf9c78df91e87d5fa2cf816ae9dab068fc86dc741cda14e84e3dac26ebcfb",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. , For authorized use only, CN=thawte Primary Root CA",
"TBS": {
"MD5": "a3f222107d4e1085e73b5b589c2f480b",
"SHA1": "b94aa26cd77c48d91a53ac44506cbd255e1d362c",
"SHA256": "a39ed0d6fd4eb1a6f7fed60f726e23eae668b7591bc004644625d22c701213fa",
"SHA384": "64b7643e4146016cbf83c911eb67e4601b6bb8d66f8ee8dcee67b815f91770d86ab23678b984430f22a963e5484881b7"
},
"ValidFrom": "2011-02-22 19:31:57",
"ValidTo": "2021-02-22 19:41:57",
"Version": 3
}
],
"CertificatesInfo": "",
"Signer": [
{
"Issuer": "C=US, O=thawte, Inc., CN=thawte SHA256 Code Signing CA",
"SerialNumber": "0dbdf488aeaa9795e332a1ca2747af0d",
"Version": 1
}
],
"SignerInfo": ""
}
Download
Certificates Expand Certificate 2ac01de88063badb080008853fdd8c6c Field Value ToBeSigned (TBS) MD5 bac0d95b77a36eed50d84415420e56bd ToBeSigned (TBS) SHA1 c107a2a8939e3ff203847e4ba576c7e3767c063a ToBeSigned (TBS) SHA256 7f648cc593ad1a699a8d5a5c972bf1cce89bf3dfd83a67f46de3230c61429fe2 Subject C=CN, ST=湖南省, L=长沙市, O=湖南蓝途方鼎科技有限公司, CN=湖南蓝途方鼎科技有限公司 ValidFrom 2015-04-02 00:00:00 ValidTo 2016-05-01 23:59:59 Signature 9331a576a43dc4e3a4132367b220e74c25851759c04d2db3b42beadbbd370c57aa3990faf580df88d99f8a5ac7836940ebce2b68b7b6b4e804e51b663a10d705b1dc5bc621a7b36ce633ae37e603fb0ae46d0fdaa1bf5ceb7d3262de99aaddeacd2672567bf55dda8e4b839cc1bc772574f0c6808763418a3cf63f596ef1ec038f05a2eab3c476b167fff75d6320069352409f4768f73c3af2b6438ab5279f511e1f8ebd3bed90a81c87338af839a538cb15f4b49de377c039847517a334f72130a8e4b7085a65ebe32cbdda528524dbdd27f74f4e75ff427d7bf40807faff55adcf287fc6aa06d10863511de08a00a546367efa0faeed0c587582d566f798db SignatureAlgorithmOID 1.2.840.113549.1.1.5 IsCertificateAuthority False SerialNumber 2ac01de88063badb080008853fdd8c6c Version 3
Certificate 611993e400000000001c Field Value ToBeSigned (TBS) MD5 78a717e082dcc1cda3458d917e677d14 ToBeSigned (TBS) SHA1 4a872e0e51f9b304469cd1dedb496ee9b8b983a4 ToBeSigned (TBS) SHA256 317fa1d234ebc49040ebc5e8746f8997471496051b185a91bdd9dfbb23fab5f8 Subject C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5 ValidFrom 2011-02-22 19:25:17 ValidTo 2021-02-22 19:35:17 Signature 812a82168c34672be503eb347b8ca2a3508af45586f11e8c8eae7dee0319ce72951848ad6211fd20fd3f4706015ae2e06f8c152c4e3c6a506c0b36a3cf7a0d9c42bc5cf819d560e369e6e22341678c6883762b8f93a32ab57fbe59fba9c9b2268fcaa2f3821b983e919527978661ee5b5d076bcd86a8e26580a8e215e2b2be23056aba0cf347934daca48c077939c061123a050d89a3ec9f578984fbecca7c47661491d8b60f195de6b84aacbc47c8714396e63220a5dc7786fd3ce38b71db7b9b03fcb71d3264eb1652a043a3fa2ead59924e7cc7f233424838513a7c38c71b242228401e1a461f17db18f7f027356cb863d9cdb9645d2ba55eefc629b4f2c7f821cc04ba57fd01b6abc667f9e7d3997ff4f522fa72f5fdff3a1c423aa1f98018a5ee8d1cd4669e4501feaaeefffb178f30f7f1cd29c59decb5d549003d85b8cbbb933a276a49c030ae66c9f723283276f9a48356c848ce5a96aaa0cc0cc47fb48e97af6de35427c39f86c0d6e473089705dbd054625e0348c2d59f7fa7668cd09db04fd4d3985f4b7ac97fb22952d01280c70f54b61e67cdc6a06c110384d34875e72afeb03b6e0a3aa66b769905a3f177686133144706fc537f52bd92145c4a246a678caf8d90aad0f679211b93267cc3ce1ebd883892ae45c6196a4950b305f8ae59378a6a250394b1598150e8ba8380b72335f476b9671d5918ad208d94 SignatureAlgorithmOID 1.2.840.113549.1.1.5 IsCertificateAuthority True SerialNumber 611993e400000000001c Version 3
Certificate 5200e5aa2556fc1a86ed96c9d44b33c7 Field Value ToBeSigned (TBS) MD5 b30c31a572b0409383ed3fbe17e56e81 ToBeSigned (TBS) SHA1 4843a82ed3b1f2bfbee9671960e1940c942f688d ToBeSigned (TBS) SHA256 03cda47a6e654ed85d932714fc09ce4874600eda29ec6628cfbaeb155cab78c9 Subject C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA ValidFrom 2010-02-08 00:00:00 ValidTo 2020-02-07 23:59:59 Signature 5622e634a4c461cb48b901ad56a8640fd98c91c4bbcc0ce5ad7aa0227fdf47384a2d6cd17f711a7cec70a9b1f04fe40f0c53fa155efe749849248581261c911447b04c638cbba134d4c645e80d85267303d0a98c646ddc7192e645056015595139fc58146bfed4a4ed796b080c4172e737220609be23e93f449a1ee9619dccb1905cfc3dd28dac423d6536d4b43d40288f9b10cf2326cc4b20cb901f5d8c4c34ca3cd8e537d66fa520bd34eb26d9ae0de7c59af7a1b42191336f86e858bb257c740e58fe751b633fce317c9b8f1b969ec55376845b9cad91faaced93ba5dc82153c2825363af120d5087111b3d5452968a2c9c3d921a089a052ec793a54891d3 SignatureAlgorithmOID 1.2.840.113549.1.1.5 IsCertificateAuthority True SerialNumber 5200e5aa2556fc1a86ed96c9d44b33c7 Version 3
Imports Expand ntoskrnl.exe fwpkclnt.sys WDFLDR.SYS Imported Functions Expand PsCreateSystemThread ZwClose ZwOpenProcess ZwWaitForSingleObject RtlIpv4AddressToStringA ZwCreateFile ZwWriteFile ZwDeleteFile ZwOpenSymbolicLinkObject ZwQuerySymbolicLinkObject RtlUnicodeStringToAnsiString ExFreePoolWithTag _vsnprintf _vsnwprintf KeInitializeEvent KeWaitForSingleObject RtlRandomEx RtlCopyUnicodeString KeEnterCriticalRegion KeLeaveCriticalRegion ExInitializeResourceLite ExAcquireResourceExclusiveLite ExReleaseResourceLite KeBugCheckEx ExAllocatePoolWithTag ExAllocatePool KeReleaseInStackQueuedSpinLock KeAcquireInStackQueuedSpinLock KeInitializeSpinLock _strlwr IoWMIRegistrationControl ExSystemTimeToLocalTime RtlTimeToTimeFields RtlCompareMemory RtlAppendUnicodeToString RtlAppendUnicodeStringToString MmGetSystemRoutineAddress RtlFreeAnsiString RtlInitUnicodeString FwpsRedirectHandleCreate0 FwpsApplyModifiedLayerData0 FwpsAcquireWritableLayerDataPointer0 FwpsReleaseClassifyHandle0 FwpsAcquireClassifyHandle0 FwpsCalloutRegister2 FwpsQueryConnectionRedirectState0 WdfVersionBindClass WdfVersionUnbind WdfVersionBind WdfVersionUnbindClass Exported Functions Expand Sections Expand .text .rdata .data .pdata .gfids PAGE INIT .rsrc .reloc Signature Expand {
"Certificates": [
{
"CertificateType": "CA",
"IsCA": true,
"IsCertificateAuthority": true,
"IsCodeSigning": true,
"SerialNumber": "71a0b73695ddb1afc23b2b9a18ee54cb",
"Signature": "243bf5d7a03613c743fef0098768d198316e12e43f1e1f967b6b4c1e879e8bc56ca3b10c7b5092d5819cb18f2c29b7eef99105b98e41f12cf6d0592d98e0b9ea8001474095b83d9d03bd79bb35b6ad9c4c27f6674510c9c5bc874e557bd287bbdddc30efc6d46ccc99356d1ce060d3cd688f29594b89960846c98efc754fc5dc09cc4e278b44cd07bcac04e0b533a5879ff4dd730c91ea12816fe375f01eb5936c4417d53e97c9bd072c56771f85dd46e8bfde2c8194a3f7e5b7a7c1379f75ca55774d5e3629ca85d84541725775c0795bfa3410066d642042b73ac81f1d4664025fc647bef0c43a2854daf61e4f9aa21943a46f49f8fc5e422028848b47206e",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, O=thawte, Inc., CN=thawte SHA256 Code Signing CA",
"TBS": {
"MD5": "8314595952398203ab24badbbc927d39",
"SHA1": "b07dcf73133408eee2786a208ce4b2543bf6c583",
"SHA256": "c734685d985b8ea13db4fc1a6dcd26aa0dde78b4c3b651ea5d58e32e081b2a41",
"SHA384": "874ded773c743b4e18744d7978b41cfe2e55529c61d45a0e34b3950aaad56b6c7a3780880133bcd1df3b1f86d468d46d"
},
"ValidFrom": "2013-12-10 00:00:00",
"ValidTo": "2023-12-09 23:59:59",
"Version": 3
},
{
"CertificateType": "Leaf (Code Signing)",
"IsCA": false,
"IsCertificateAuthority": false,
"IsCodeSigning": true,
"SerialNumber": "0dbdf488aeaa9795e332a1ca2747af0d",
"Signature": "3ebdf2009f802c1033d2a14df88ed84c6282db1e8d19d6324b21ffb8e69fbc0752d101bd22ab4fae6c8c45bb82b7ba0d9a7213d7a29a2f587bdf68c7ae3ab6f9ed7cc23e27d6f44a0a5311124381f6f9bdeec2e19c59fc7362d5d59f09951b8ffa03215e5679ae4bcffe45b7059426a96c2897107c07b2b3e6cbcbee46527908db76f7a1bf2af19c986eba31504c9c5c3cb34e81ba2a1eb55965a2d192820cac79f640a3e9672bb507dc3a561de5d94f9a0105a355f42bea235ea5349d7d2b104a71c56640e0170433fe1ef075d9f865f17be8989b590765917215c0f7b709e9820f7106dff8cec57d59ee2777cec96f8b1de8e3a93bc7e7b757d87c9888b9a2",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=CN, L=, O=, OU=, CN=",
"TBS": {
"MD5": "5037c865c427f7d514ac954ef7e66ccf",
"SHA1": "cfcc3ebb5c9003e88373beb66781dbdf9e1904d2",
"SHA256": "cd684ad96d510b669c0767e4b845fb7a04fba27c1f3a0935b09a988d94938f6e",
"SHA384": "30bf56d04a2a54ae834ea9b111da02fe53c0c13ddd66f815aed8100bb887c6d5b299e518ba1f4abc0f2c3bb02029141b"
},
"ValidFrom": "2018-08-15 00:00:00",
"ValidTo": "2019-08-15 23:59:59",
"Version": 3
},
{
"CertificateType": "CA",
"IsCA": true,
"IsCertificateAuthority": true,
"IsCodeSigning": false,
"SerialNumber": "611fb0a400000000001d",
"Signature": "2dcc71b5e8ba94ff5ee64467007b6afc412c3ee70e41855ab12a932ba95b89f2f72b499c8003f297b8e760a80ed7fd5de545467594f4ed1c9de166228b61fb29f2c6a8bdf387c98f7f47e1c058b64a1aa2e7f718606969e083069e26c775c40c0d79da746b52b9fae8ea3359b9bb18dd291a14dfd36a37277a9da0dacffffc22c4faf009ff33e93e17ba1cc742cfce2743d30c0c5581303db96060ce02ece19ee81ddc852ce0a18d966d95ac17a4713ea16741b6281d2ce3b615e5b7e5a2f6256d86e320acf9f8314f8e629b9833376d6af735523e90feb03b5fc5b852a9e06ea0479a279e97aea24a9e531939ec357ec659de3ae0aaf533f06abda0821812dea18c4570ca2bd62e959145995a5c240049bd23b30ceca43df5b9e1d1b1825a38eea3fba1ab483a8c5dffa065223fd3d3fe4990db1446a3852e8a554b09ab38b2ab63a008d1fdad48e273d812bcc26ca516fad09ac05e38383a2b718e553aac42197a1f0d4220e7ab5d8c6880524ca1c0d488d02321fb901309007b4937afa9df486022abf4f6c2363bf8513c34bbc586e43ae19f4b90fe5461024b159c34176aa94b8d4cb69d2326c83af1d6b805cdda1d6240183a2f1b41cd3a993a0aa9d1d77eb8c4aff7b8c980105ed55df6ce7a9a02c50f6381efb564e9fc5bd8d2619a68c37cf9c78df91e87d5fa2cf816ae9dab068fc86dc741cda14e84e3dac26ebcfb",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
"Subject": "C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. , For authorized use only, CN=thawte Primary Root CA",
"TBS": {
"MD5": "a3f222107d4e1085e73b5b589c2f480b",
"SHA1": "b94aa26cd77c48d91a53ac44506cbd255e1d362c",
"SHA256": "a39ed0d6fd4eb1a6f7fed60f726e23eae668b7591bc004644625d22c701213fa",
"SHA384": "64b7643e4146016cbf83c911eb67e4601b6bb8d66f8ee8dcee67b815f91770d86ab23678b984430f22a963e5484881b7"
},
"ValidFrom": "2011-02-22 19:31:57",
"ValidTo": "2021-02-22 19:41:57",
"Version": 3
}
],
"CertificatesInfo": "",
"Signer": [
{
"Issuer": "C=US, O=thawte, Inc., CN=thawte SHA256 Code Signing CA",
"SerialNumber": "0dbdf488aeaa9795e332a1ca2747af0d",
"Version": 1
}
],
"SignerInfo": ""
}
source
last_updated: 2026-06-17