57fc510a-e649-4599-b83e-8f3605e3d1d9

aswArPot.sys :inline

Description

Avast’s “Anti Rootkit” driver (also used by AVG) has been found to be vulnerable to two high severity attacks that could potentially lead to privilege escalation by running code in the kernel from a non-administrator user.

  • UUID: 57fc510a-e649-4599-b83e-8f3605e3d1d9
  • Created: 2023-01-09
  • Author: Michael Haag
  • Acknowledgement: | @mattnotmax

Download

This download link contains the vulnerable driver!

Commands

sc.exe create aswArPot.sys binPath=C:\windows\temp\aswArPot.sys type=kernel && sc.exe start aswArPot.sys
Use CasePrivilegesOperating System
Elevate privilegeskernelWindows 10

Detections

YARA 🏹

Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed driver files

Sigma 🛡️

Expand

Names

detects loading using name only

Hashes

detects loading using hashes only

Sysmon 🔎

Expand

Block

on hashes

Alert

on hashes

Resources


  • https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules
  • CVE-2022-26522, CVE-2022-26523: Both of these vulnerabilities were fixed in version 22.1.

  • CVE

  • CVE-2022-26522
  • CVE-2022-26523
  • Known Vulnerable Samples

    PropertyValue
    FilenameaswArPot.sys
    Creation Timestamp2021-02-01 02:08:43
    MD5a179c4093d05a3e1ee73f6ff07f994aa
    SHA15d6b9e80e12bfc595d4d26f6afb099b3cb471dd4
    SHA2564b5229b3250c8c08b98cb710d6c056144271de099a57ae09f5d2097fc41bd4f1
    Authentihash MD566d55dcf5fe5e1b60f32880d48207105
    Authentihash SHA1b8b5e5951f1c4148537e9850f2b577a453e4c045
    Authentihash SHA256c0c131bc8d6c8b5a2be32474474b1221bce1289c174c87e743ed4a512f5571d4
    RichPEHeaderHash MD5edc05997bbdab8acd04f275b386ffdab
    RichPEHeaderHash SHA1b47a65e11021476840629d33996069e4638e241c
    RichPEHeaderHash SHA256fe13709d1d6fd5734b2d61d1661e6ac2540c5ee2f4f96e56418d1db86c0bdb20
    CompanyAVAST Software
    DescriptionAvast Anti Rootkit
    ProductAvast Antivirus
    OriginalFilenameaswArPot.sys

    Download

    Certificates

    Expand
    Certificate 0d424ae0be3a88ff604021ce1400f0dd
    FieldValue
    ToBeSigned (TBS) MD5c0189c338449a42fe8358c2c1fbecc60
    ToBeSigned (TBS) SHA1b8ac0ee6875594b80ad86a6df6dd1fa3048c187c
    ToBeSigned (TBS) SHA256a43de6baf968a942da017b70769fdb65b3cfb1bbca1f9174da26a7d8aae78ec5
    SubjectC=US, O=DigiCert, Inc., CN=DigiCert Timestamp 2021
    ValidFrom2021-01-01 00:00:00
    ValidTo2031-01-06 00:00:00
    Signature481cdcb5e99a23bce71ae7200e8e6746fd427251740a2347a3ab92d225c47059be14a0e52781a54d1415190779f0d104c386d93bbdfe4402664ded69a40ff6b870cf62e8f5514a7879367a27b7f3e7529f93a7ed439e7be7b4dd412289fb87a246034efcf4feb76477635f2352698382fa1a53ed90cc8da117730df4f36539704bf39cd67a7bda0cbc3d32d01bcbf561fc75080076bc810ef8c0e15ccfc41172e71b6449d8229a751542f52d323881daf460a2bab452fb5ce06124254fb2dfc929a8734351dabd63d61f5b9bf72e1b4f131df74a0d717e97b7f43f84ebc1e3a349a1facea7bf56cfba597661895f7ea7b48e6778f93698e1cb28da5b87a68a2f
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityFalse
    SerialNumber0d424ae0be3a88ff604021ce1400f0dd
    Version3
    Certificate 03f02aca051d1c9330eeabd3706e836f
    FieldValue
    ToBeSigned (TBS) MD5f251d9cde0901fb67831855b4a592b51
    ToBeSigned (TBS) SHA1cd0ac068faea4b875ded287512f20b6ba8dcb457
    ToBeSigned (TBS) SHA256247e040822854e1a4cbc3488782a9e96db6bffa9bdfe36406a46e3f88695d423
    SubjectC=CZ, L=Praha, O=Avast Software s.r.o., OU=RE 999, CN=Avast Software s.r.o.
    ValidFrom2019-12-02 00:00:00
    ValidTo2022-10-19 12:00:00
    Signature874d04f17ffc50e66100207e56ecc8ae7e81c1957a7600295ead9db28842c7c05e06e8e28ccfc1e9d45d7a55d6d4a2fb74d72600a79ef5bfa53acaa4f3a4fcaf90a2554fc37742dd44c83a90880f948f5538637c0d999b03ebbf20cc001293a5639d44ad950cacfce2a337f7a24b817a5b85df89f6acf49974adee1d867373e6534a3f3558e59f87d06afe5744ec575b66c76110a595471007b209c591984f0ff20ea4c87ac405c85f42f0b105b04ec2ced11ca9cfb6aef21a3c6ae9ccd2a9cb4a9f78244751b15bfccb32ec3a52d44258bad6fc6d9f24c24700e9e1c4c0c29b9db4683c526a92934d72367620c6a89119e7a678597d7603c62b1c22f54edfad
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber03f02aca051d1c9330eeabd3706e836f
    Version3
    Certificate 0aa125d6d6321b7e41e405da3697c215
    FieldValue
    ToBeSigned (TBS) MD58d26184fc613f89aba1cefb30fce1b53
    ToBeSigned (TBS) SHA163a7e376bad5ec2e419d514a403bcf46c8d31d95
    ToBeSigned (TBS) SHA25656b5f0d9db578e3f142921daa387902722a76700375c7e1c4ae0ba004bacaa0c
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Assured ID Timestamping CA
    ValidFrom2016-01-07 12:00:00
    ValidTo2031-01-07 12:00:00
    Signature719512e951875669cdefddda7caa637ab378cf06374084ef4b84bfcacf0302fdc5a7c30e20422caf77f32b1f0c215a2ab705341d6aae99f827a266bf09aa60df76a43a930ff8b2d1d87c1962e85e82251ec4ba1c7b2c21e2d65b2c1435430468b2db7502e072c798d63c64e51f4810185f8938614d62462487638c91522caf2989e5781fd60b14a580d7124770b375d59385937eb69267fb536189a8f56b96c0f458690d7cc801b1b92875b7996385228c61ca79947e59fc8c0fe36fb50126b66ca5ee875121e458609bba0c2d2b6da2c47ebbc4252b4702087c49ae13b6e17c424228c61856cf4134b6665db6747bf55633222f2236b24ba24a95d8f5a68e52
    SignatureAlgorithmOID1.2.840.113549.1.1.11
    IsCertificateAuthorityTrue
    SerialNumber0aa125d6d6321b7e41e405da3697c215
    Version3
    Certificate 61204db4000000000027
    FieldValue
    ToBeSigned (TBS) MD58e3ffc222fbcebdbb8b23115ab259be7
    ToBeSigned (TBS) SHA1ee20bff28ffe13be731c294c90d6ded5aae0ec0e
    ToBeSigned (TBS) SHA25659826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
    ValidFrom2011-04-15 19:45:33
    ValidTo2021-04-15 19:55:33
    Signature208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber61204db4000000000027
    Version3
    Certificate 02c4d1e58a4a680c568da3047e7e4d5f
    FieldValue
    ToBeSigned (TBS) MD5829995f702421dea833a24fb2c7f4442
    ToBeSigned (TBS) SHA11d7e838accd498c2e5ba9373af819ec097bb955c
    ToBeSigned (TBS) SHA25692914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db
    SubjectC=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1
    ValidFrom2011-02-11 12:00:00
    ValidTo2026-02-10 12:00:00
    Signature49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber02c4d1e58a4a680c568da3047e7e4d5f
    Version3

    Imports

    Expand
    • ntoskrnl.exe

    Imported Functions

    Expand
    • __C_specific_handler
    • KeDelayExecutionThread
    • IoAllocateWorkItem
    • MmIsAddressValid
    • MmUnlockPages
    • ExAllocatePool
    • RtlAnsiStringToUnicodeString
    • KeAcquireSpinLockRaiseToDpc
    • ZwQuerySystemInformation
    • PsRemoveLoadImageNotifyRoutine
    • ZwUnmapViewOfSection
    • ZwQuerySymbolicLinkObject
    • MmProbeAndLockPages
    • RtlVolumeDeviceToDosName
    • PsSetLoadImageNotifyRoutine
    • IoGetRequestorProcessId
    • ZwReadFile
    • ObQueryNameString
    • IoDetachDevice
    • ZwOpenThreadTokenEx
    • ZwOpenProcessTokenEx
    • towlower
    • NtBuildNumber
    • ExReleaseFastMutex
    • _wcsicmp
    • _snwprintf
    • RtlConvertSidToUnicodeString
    • ObfDereferenceObject
    • IoAllocateMdl
    • ZwCreateSection
    • ZwQueryInformationProcess
    • IoAttachDeviceToDeviceStackSafe
    • PsGetProcessId
    • PsCreateSystemThread
    • ZwQueryInformationThread
    • RtlInitUnicodeString
    • ZwOpenSymbolicLinkObject
    • tolower
    • PsRemoveCreateThreadNotifyRoutine
    • IoDeleteDevice
    • IoBuildDeviceIoControlRequest
    • wcsncpy
    • IoGetDeviceObjectPointer
    • IoGetCurrentProcess
    • ObOpenObjectByPointer
    • strncpy
    • KeReleaseSpinLock
    • _strnicmp
    • IoFileObjectType
    • KeStackAttachProcess
    • PsLookupProcessByProcessId
    • PsGetCurrentProcessId
    • KeSetEvent
    • PsThreadType
    • RtlUnicodeStringToAnsiString
    • ZwQueryInformationToken
    • ZwMapViewOfSection
    • strncmp
    • ObReferenceObjectByHandle
    • RtlGetVersion
    • PsGetThreadId
    • PsGetVersion
    • KeClearEvent
    • IoGetBaseFileSystemDeviceObject
    • wcschr
    • ZwSetInformationFile
    • ZwEnumerateKey
    • IoFreeMdl
    • wcsstr
    • ExAcquireFastMutex
    • MmGetSystemRoutineAddress
    • IoFreeWorkItem
    • _stricmp
    • ExAllocatePoolWithTag
    • RtlInitString
    • IoCreateDevice
    • IofCallDriver
    • IoDeviceObjectType
    • _snprintf
    • ExFreePoolWithTag
    • ZwOpenFile
    • KeSetSystemAffinityThread
    • strstr
    • KeInitializeEvent
    • ObReferenceObjectByName
    • strchr
    • _wcsnicmp
    • KeQueryActiveProcessors
    • RtlEqualSid
    • IoQueueWorkItem
    • MmUnmapLockedPages
    • MmMapLockedPagesSpecifyCache
    • PsSetCreateThreadNotifyRoutine
    • PsGetCurrentThreadId
    • IofCompleteRequest
    • PsGetProcessWin32Process
    • ExEventObjectType
    • ZwQueryInformationFile
    • KeWaitForSingleObject
    • IoCreateSymbolicLink
    • PsSetCreateProcessNotifyRoutine
    • IoDriverObjectType
    • PsLookupThreadByThreadId
    • IoGetDeviceInterfaces
    • ZwClose
    • PsTerminateSystemThread
    • wcsrchr
    • strrchr
    • SeExports
    • KeUnstackDetachProcess
    • KeResetEvent
    • KeRevertToUserAffinityThread
    • ZwOpenProcess
    • wcsncmp
    • ZwOpenKey
    • PsGetThreadProcess
    • IoThreadToProcess
    • PsInitialSystemProcess
    • KeInsertQueueDpc
    • KeNumberProcessors
    • KeInitializeDpc
    • KeSetTargetProcessorDpc
    • PsProcessType
    • MmMapIoSpace
    • MmUnmapIoSpace
    • ZwDeleteFile
    • KeAttachProcess
    • KeDetachProcess
    • RtlCompareUnicodeString
    • ZwWriteFile
    • NtClose
    • ObfReferenceObject
    • IoBuildSynchronousFsdRequest
    • ZwOpenThread
    • ZwTerminateProcess
    • RtlEqualUnicodeString
    • IoFreeIrp
    • ZwQueryDirectoryObject
    • KeBugCheck
    • ZwOpenDirectoryObject
    • IoAllocateIrp
    • KdDebuggerNotPresent
    • ZwSetSecurityObject
    • RtlGetDaclSecurityDescriptor
    • RtlGetGroupSecurityDescriptor
    • RtlGetOwnerSecurityDescriptor
    • RtlGetSaclSecurityDescriptor
    • SeCaptureSecurityDescriptor
    • RtlLengthSecurityDescriptor
    • RtlCreateSecurityDescriptor
    • RtlAbsoluteToSelfRelativeSD
    • RtlAddAccessAllowedAce
    • RtlLengthSid
    • IoIsWdmVersionAvailable
    • RtlSetDaclSecurityDescriptor
    • ZwSetValueKey
    • ZwQueryValueKey
    • ZwCreateKey
    • RtlFreeUnicodeString
    • KeBugCheckEx
    • RtlQueryRegistryValues
    • RtlPrefixUnicodeString
    • ExRegisterCallback
    • ExCreateCallback
    • ExUnregisterCallback
    • strcmp

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • PAGE
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "0d424ae0be3a88ff604021ce1400f0dd",
          "Signature": "481cdcb5e99a23bce71ae7200e8e6746fd427251740a2347a3ab92d225c47059be14a0e52781a54d1415190779f0d104c386d93bbdfe4402664ded69a40ff6b870cf62e8f5514a7879367a27b7f3e7529f93a7ed439e7be7b4dd412289fb87a246034efcf4feb76477635f2352698382fa1a53ed90cc8da117730df4f36539704bf39cd67a7bda0cbc3d32d01bcbf561fc75080076bc810ef8c0e15ccfc41172e71b6449d8229a751542f52d323881daf460a2bab452fb5ce06124254fb2dfc929a8734351dabd63d61f5b9bf72e1b4f131df74a0d717e97b7f43f84ebc1e3a349a1facea7bf56cfba597661895f7ea7b48e6778f93698e1cb28da5b87a68a2f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, O=DigiCert, Inc., CN=DigiCert Timestamp 2021",
          "TBS": {
            "MD5": "c0189c338449a42fe8358c2c1fbecc60",
            "SHA1": "b8ac0ee6875594b80ad86a6df6dd1fa3048c187c",
            "SHA256": "a43de6baf968a942da017b70769fdb65b3cfb1bbca1f9174da26a7d8aae78ec5",
            "SHA384": "76d3a316a5a106050298418cce3beea16100524723d9e3220b0de51bfb6f1c35a5d4c7cd10b358fef7bf94c3e3562150"
          },
          "ValidFrom": "2021-01-01 00:00:00",
          "ValidTo": "2031-01-06 00:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": false,
          "SerialNumber": "03f02aca051d1c9330eeabd3706e836f",
          "Signature": "874d04f17ffc50e66100207e56ecc8ae7e81c1957a7600295ead9db28842c7c05e06e8e28ccfc1e9d45d7a55d6d4a2fb74d72600a79ef5bfa53acaa4f3a4fcaf90a2554fc37742dd44c83a90880f948f5538637c0d999b03ebbf20cc001293a5639d44ad950cacfce2a337f7a24b817a5b85df89f6acf49974adee1d867373e6534a3f3558e59f87d06afe5744ec575b66c76110a595471007b209c591984f0ff20ea4c87ac405c85f42f0b105b04ec2ced11ca9cfb6aef21a3c6ae9ccd2a9cb4a9f78244751b15bfccb32ec3a52d44258bad6fc6d9f24c24700e9e1c4c0c29b9db4683c526a92934d72367620c6a89119e7a678597d7603c62b1c22f54edfad",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CZ, L=Praha, O=Avast Software s.r.o., OU=RE 999, CN=Avast Software s.r.o.",
          "TBS": {
            "MD5": "f251d9cde0901fb67831855b4a592b51",
            "SHA1": "cd0ac068faea4b875ded287512f20b6ba8dcb457",
            "SHA256": "247e040822854e1a4cbc3488782a9e96db6bffa9bdfe36406a46e3f88695d423",
            "SHA384": "c6a765c300f3ee36604e9c51a9fcd18071b0cd0bd15b3ad69350f04a0b1b5ef7b71556af698a1e8988bf91cd8b2a6104"
          },
          "ValidFrom": "2019-12-02 00:00:00",
          "ValidTo": "2022-10-19 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "0aa125d6d6321b7e41e405da3697c215",
          "Signature": "719512e951875669cdefddda7caa637ab378cf06374084ef4b84bfcacf0302fdc5a7c30e20422caf77f32b1f0c215a2ab705341d6aae99f827a266bf09aa60df76a43a930ff8b2d1d87c1962e85e82251ec4ba1c7b2c21e2d65b2c1435430468b2db7502e072c798d63c64e51f4810185f8938614d62462487638c91522caf2989e5781fd60b14a580d7124770b375d59385937eb69267fb536189a8f56b96c0f458690d7cc801b1b92875b7996385228c61ca79947e59fc8c0fe36fb50126b66ca5ee875121e458609bba0c2d2b6da2c47ebbc4252b4702087c49ae13b6e17c424228c61856cf4134b6665db6747bf55633222f2236b24ba24a95d8f5a68e52",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Assured ID Timestamping CA",
          "TBS": {
            "MD5": "8d26184fc613f89aba1cefb30fce1b53",
            "SHA1": "63a7e376bad5ec2e419d514a403bcf46c8d31d95",
            "SHA256": "56b5f0d9db578e3f142921daa387902722a76700375c7e1c4ae0ba004bacaa0c",
            "SHA384": "d8c9691fe9dbe182f07b49b07fbb4f589fa7b38b5c4d21f265d3a2e818f4b1bfb39e03faab2ec05bb10333a99914fb8a"
          },
          "ValidFrom": "2016-01-07 12:00:00",
          "ValidTo": "2031-01-07 12:00:00",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "61204db4000000000027",
          "Signature": "208cc159ed6f9c6b2dc14a3e751d454c41501cbd80ead9b0928b062a133f53169e56396a8a63b6782479f57db8b947a10a96c2f6cbbda2669f06e1acd279090efd3cdcac020c70af3f1bec787ed4eb4b056026d973619121edb06863e09712ab6fa012edd99fd2da273cb3e456f9d1d4810f71bd427ca689dccdd5bd95a2abf193117de8ac3129a85d6670419dfc75c9d5b31a392ad08505508bac91cac493cb71a59da4946f580cfa6e20c40831b5859d7e81f9d23dca5b18856c0a86ec22091ba574344f7f28bc954aab1db698b05d09a477767eefa78e5d84f61824cbd16da6c3a19cc2107580ff9d32fde6cf433a82f7ce8fe1722a9b62b75fed951a395c2f946d48b7015f332fbbdc2d73348904420a1c8b79f9a3fa17effaa11a10dfe0b2c195eb5c0c05973b353e18884ddb6cbf24898dc8bdd89f7b393a24a0d5dfd1f34a1a97f6a66f7a1fb090a9b3ac013991d361b764f13e573803afce7ad2b590f5aedc3999d5b63c97eda6cb16c77d6b2a4c9094e64c54fd1ecd20ecce689c8758e96160beeb0ec9d5197d9fe978bd0eac2175078fa96ee08c6a2a6b9ce3e765bcbc2d3c6ddc04dc67453632af0481bca8006e614c95c55cd48e8e9f2fc13274bdbd11650307cdefb75e0257da86d41a2834af8849b2cfa5dd82566f68aa14e25954feffeaeeefea9270226081e32523c09fcc0f49b235aa58c33ac3d9169410",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA",
          "TBS": {
            "MD5": "8e3ffc222fbcebdbb8b23115ab259be7",
            "SHA1": "ee20bff28ffe13be731c294c90d6ded5aae0ec0e",
            "SHA256": "59826b69bc8c28118c96323b627da59aaca0b142cc5d8bad25a8fcfd399aa821",
            "SHA384": "f2dab7e56a33298654924501499487f6ba72c7d9477476a186e1ed7a9be031fade0e35ac09eff5e56bbbab95ae5374e7"
          },
          "ValidFrom": "2011-04-15 19:45:33",
          "ValidTo": "2021-04-15 19:55:33",
          "Version": 3
        },
        {
          "IsCertificateAuthority": true,
          "SerialNumber": "02c4d1e58a4a680c568da3047e7e4d5f",
          "Signature": "49eb7c60beaeefc97cb3c5ba4b64df1669e286fa29d9de98857d406626332f4455aaaa90e935700a34bed3ae542e8e6500d67a32203e6c26b898a939b1bc95c7aae9f5ee4666c6b3e812f8b3979dff74588234997550ac448fe892ce7d8b0f3196c7dcd31130987416c6e56b4576a39401cd33007a48f66f8631c9562b3322d5f801b644ce8cb4ca88d2e416e3e7f6e23ee109c09d7943437f555c05ad9310c62c0d6bc09eea78e5d277d6b8da9a987fba4c922b9dbda488b1ddafc34cd2979b03c6ae5f1b440f333715e3cbff2f56d316a45b55679da2cadb346c0c734ab57ba4b6b3e935027870ec007acbfc4b4f2236bb1484c98f91dd0f3c758cca0b88e7",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "TBS": {
            "MD5": "829995f702421dea833a24fb2c7f4442",
            "SHA1": "1d7e838accd498c2e5ba9373af819ec097bb955c",
            "SHA256": "92914d016cc46e125e50c4bd0bd7f72db87eed4ba68f3c589b4e86aa563108db",
            "SHA384": "dbb72e38c3bc17b08aa00535ebd48502058ce6ecfd24bd4dd45c7b33e3d523510a4a649d86dfc77436c58754bd0754ea"
          },
          "ValidFrom": "2011-02-11 12:00:00",
          "ValidTo": "2026-02-10 12:00:00",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance Code Signing CA,1",
          "SerialNumber": "03f02aca051d1c9330eeabd3706e836f",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    source

    last_updated: 2024-03-28