708650ed-c497-48be-97bc-9edd48cf2a1a

BdApiUtil.sys :inline

Description

Driver can be used to load unsigned drivers. IOCTL code which takes a PID and terminates it (arbitrary process termination). Admin privileges required to install the driver, but if it's already installed, can be called by any user (non admin).

  • UUID: 708650ed-c497-48be-97bc-9edd48cf2a1a
  • Created: 2025-12-09
  • Author: christopher-ellis-workday, plisskien, Julian Pena

DownloadBlock

This download link contains the vulnerable driver!

Commands

sc.exe create BdApiUtil.sys binPath=C:\windows\temp\BdApiUtil.sys type=kernel && sc.exe start BdApiUtil.sys
Use CasePrivilegesOperating System
Elevate privilegeskernelWindows 10

Detections

YARA 🏹

Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed driver files

Sigma 🛡️

Expand

Names

detects loading using name only

Hashes

detects loading using hashes only

Sysmon 🔎

Expand

Block

on hashes

Alert

on hashes

Resources


  • https://github.com/magicsword-io/LOLDrivers/issues/204
  • https://github.com/magicsword-io/LOLDrivers/issues/231
  • https://github.com/RainbowDynamix/GoodBaiii
  • https://blog.talosintelligence.com/byovd-loader-deadlock-ransomware/

  • Known Vulnerable Samples

    PropertyValue
    FilenameBdApiUtil.sys
    Creation Timestamp2015-03-18 20:58:13
    MD529e1264dd642b646fbef9bd347b1b860
    SHA12d0a8394180e728755e8e13547d572c9e89b7262
    SHA25632198295d2a2700b9895fff999c2b233f9befb0bc175815ec4b71ee926b6edfc
    Authentihash MD555759e7cd4e7816f800aac30081ba5c0
    Authentihash SHA19f7ba541a3dc52e1cb765cd9a4157788eea7797a
    Authentihash SHA256b3811667f28da08859380173611954b5ed3cd8deb972a26caeba8f53d64a103d
    RichPEHeaderHash MD5e734ef5ee4a0a713d8eeaba51a26b111
    RichPEHeaderHash SHA1d0eb1c9935763928f36127634ee7aa6316b53a55
    RichPEHeaderHash SHA256c36513f9cad1ffd1daa6febe5d0c7a9baead7427cd1b1e3ab6a9ef004cd5cc60
    CompanyBaidu, Inc.
    DescriptionBaidu Antivirus BdApi Driver
    ProductBaidu Antivirus

    Download

    Certificates

    Expand
    Certificate 0400000000012f4ee152d7
    FieldValue
    ToBeSigned (TBS) MD5e140543fe3256027cfa79fc3c19c1776
    ToBeSigned (TBS) SHA1c655f94eb1ecc93de319fc0c9a2dc6c5ec063728
    ToBeSigned (TBS) SHA2563ca71e85908ff67368e4dc00253f5691b9e6d50c966e7784143d75fb92aa3448
    SubjectCN=GlobalSign Timestamping CA , G2,O=GlobalSign nv,sa,C=BE
    ValidFrom2011-04-13 10:00:00
    ValidTo2028-01-28 12:00:00
    Signature4e5e56901e46b4d94931f3bb1739281bc216ddfd41dc0905049b6fb2a29ad6992e40990055b5ea3fa52076d38634d417cc553ac782eeefa8babcd8069f1550dfcd167b523a02d7191afdaff0785ce04bc518df3a241edaacb8a95804020730dbb0125efe31bef00448f4f070f83a5e5683cf3dfb0dbcf4c5ed979db9d4dba52784e3389b8ba735864420a43b6da46a0ba183fd28ebdaef28f6cc885dfb0a3b00abe021ebe22f356c0f8e344597eba2f79933357ecb9a8abb454de73f9fc2d98afa65b26ec77e65ffe892e12c31a2f7b02736488f266f3bee4d761f79c3e57f9635bc2d0ecc01b08e7fff518080a792d4b34446648c874f166307314b63b0dff3
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber0400000000012f4ee152d7
    Version3
    Certificate 112106a081d33fd87ae5824cc16b52094e03
    FieldValue
    ToBeSigned (TBS) MD5a0ac4d48fe852f7b3ed4e623d59a825f
    ToBeSigned (TBS) SHA1d4db9846bc4d7db142eeb364286f6de7c102420c
    ToBeSigned (TBS) SHA25678d2e41a13eb4e9171bae2d2adb192cf39210b5231f77cda936bcfbe8c003bdf
    SubjectCN=GlobalSign TSA for MS Authenticode , G2,O=GMO GlobalSign Pte Ltd,C=SG
    ValidFrom2015-02-03 00:00:00
    ValidTo2026-03-03 00:00:00
    Signature8032dc078d1ca09c9d3c2ae83d218b59a14d7ecc44ce03be7eaabcc4e67b73bb4bf188da904e7537283863b9d72b0f54a956ce7739973073cd9bd9d905451c8da4b8035d4fd91c2e98e0e988e6ecd7057e562a7bf7165ba3ad8f972512841bb25c634a0ad2ef10544782843569289c0ce41f141624fa75dc74726e4ecae36a43afcf7d3648d1bde906912c2fa6c871fdcfbdd89d2198fcafdbde228cafa7f377ef9ddca3704b441af078851ef2a58c39b5dc881c37edad14f5070b26bdbe6d025eb1b8b0586c853a0df6ff5a270cc5de53e7543c564cc94e4c30f6f25cfb1a8cc282bead5991f61b4d557bcf5b01dcfd7ad36f235c32479b01f3c15114468a9b
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber112106a081d33fd87ae5824cc16b52094e03
    Version3
    Certificate 250ce8e030612e9f2b89f7054d7cf8fd
    FieldValue
    ToBeSigned (TBS) MD5918d9eb6a6cd36c531eceb926170a7e1
    ToBeSigned (TBS) SHA10ae95700d65e6f59715aa47048993ca7858e676a
    ToBeSigned (TBS) SHA25647c46e6eaa3780eace3d0d891346cd373359d246b21a957219dbab4c8f37c166
    SubjectCN=VeriSign Class 3 Public Primary Certification Authority , G5,OU=(c) 2006 VeriSign, Inc. , For authorized use only,OU=VeriSign Trust Network,O=VeriSign, Inc.,C=US
    ValidFrom2006-11-08 00:00:00
    ValidTo2021-11-07 23:59:59
    Signature1302ddf8e88600f25af8f8200c59886207cecef74ef9bb59a198e5e138dd4ebc6618d3adeb18f20dc96d3e4a9420c33cbabd6554c6af44b310ad2c6b3eabd707b6b88163c5f95e2ee52a67cecd330c2ad7895603231fb3bee83a0859b4ec4535f78a5bff66cf50afc66d578d1978b7b9a2d157ea1f9a4bafbac98e127ec6bdff
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber250ce8e030612e9f2b89f7054d7cf8fd
    Version3
    Certificate 610c120600000000001b
    FieldValue
    ToBeSigned (TBS) MD553c41bc1164e09e0cd1617a5bf913efd
    ToBeSigned (TBS) SHA193c03aac8951d494ecd5696b1c08658541b18727
    ToBeSigned (TBS) SHA25640bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b
    SubjectOU=Class 3 Public Primary Certification Authority,O=VeriSign, Inc.,C=US
    ValidFrom2006-05-23 17:01:29
    ValidTo2016-05-23 17:11:29
    Signature01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610c120600000000001b
    Version3
    Certificate 3bdb1994b98bbb19ab55a42337fa4f5c
    FieldValue
    ToBeSigned (TBS) MD59ea2687f1fc2e86224cb68486714762c
    ToBeSigned (TBS) SHA16d36f4a52430aa26965512fc6ba47a6761e041a9
    ToBeSigned (TBS) SHA2568a741d00a587923919f7fef79b7922ecff7a584ba2551715c5187e399366e66e
    SubjectCN=Baidu Online Network Technology (Beijing)Co., Ltd,OU=Digital ID Class 3 , Microsoft Software Validation v2,O=Baidu Online Network Technology (Beijing)Co., Ltd,L=Beijing,ST=Beijing,C=CN
    ValidFrom2012-04-24 00:00:00
    ValidTo2015-04-24 23:59:59
    Signatured4d31733c0a04a890eecbf1af9f227dc09186dcc6625ee8b059ae8e4fbd4e0fd22f86e9d993b3974a60e9fc5905d6322dbaf62759cb40f596c5805b8607ad52a825c4b4da405aa8b8c024d7117e573a36fbb576355d8449afae87238aae1a63a2271d85abae4387066d04a0362ca7ff482752f0f057bdfc36802dc2c1a9aff13d527340edfcfebe04ed920f9996410e23c6afce70d7387dca8fff985b336da6a63ebf48ccfe8b968ae35111dbab3047d929a54321b31869886932912bec609ab7715021211eb409857e25a3f6c4b573a81da6b666541429a87a702a0879153fe04ca809c819598c38cc0a7a32e4489174324828284329ee1b8a97c9609ca7899
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber3bdb1994b98bbb19ab55a42337fa4f5c
    Version3
    Certificate 5200e5aa2556fc1a86ed96c9d44b33c7
    FieldValue
    ToBeSigned (TBS) MD5b30c31a572b0409383ed3fbe17e56e81
    ToBeSigned (TBS) SHA14843a82ed3b1f2bfbee9671960e1940c942f688d
    ToBeSigned (TBS) SHA25603cda47a6e654ed85d932714fc09ce4874600eda29ec6628cfbaeb155cab78c9
    SubjectCN=VeriSign Class 3 Code Signing 2010 CA,OU=Terms of use at https://www.verisign.com/rpa (c)10,OU=VeriSign Trust Network,O=VeriSign, Inc.,C=US
    ValidFrom2010-02-08 00:00:00
    ValidTo2020-02-07 23:59:59
    Signature5622e634a4c461cb48b901ad56a8640fd98c91c4bbcc0ce5ad7aa0227fdf47384a2d6cd17f711a7cec70a9b1f04fe40f0c53fa155efe749849248581261c911447b04c638cbba134d4c645e80d85267303d0a98c646ddc7192e645056015595139fc58146bfed4a4ed796b080c4172e737220609be23e93f449a1ee9619dccb1905cfc3dd28dac423d6536d4b43d40288f9b10cf2326cc4b20cb901f5d8c4c34ca3cd8e537d66fa520bd34eb26d9ae0de7c59af7a1b42191336f86e858bb257c740e58fe751b633fce317c9b8f1b969ec55376845b9cad91faaced93ba5dc82153c2825363af120d5087111b3d5452968a2c9c3d921a089a052ec793a54891d3
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber5200e5aa2556fc1a86ed96c9d44b33c7
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • FLTMGR.SYS

    Imported Functions

    Expand
    • RtlInitUnicodeString
    • IoDeleteDevice
    • MmGetSystemRoutineAddress
    • IoDetachDevice
    • PsSetCreateProcessNotifyRoutine
    • wcsrchr
    • ZwQueryValueKey
    • ZwClose
    • IofCompleteRequest
    • PsGetVersion
    • IoCreateSymbolicLink
    • PsGetCurrentProcessId
    • IoCreateDevice
    • ExCreateCallback
    • ZwOpenKey
    • RtlCompareMemory
    • MmIsAddressValid
    • _stricmp
    • ExGetPreviousMode
    • ZwQuerySystemInformation
    • IoFreeMdl
    • _vsnprintf
    • NtClose
    • ObReferenceObjectByHandle
    • strrchr
    • ObfDereferenceObject
    • ExQueueWorkItem
    • RtlVolumeDeviceToDosName
    • PsLookupProcessByProcessId
    • ZwQuerySymbolicLinkObject
    • _wcsnicmp
    • ZwReadFile
    • IoGetRelatedDeviceObject
    • KeSetEvent
    • RtlAppendUnicodeToString
    • IoCreateFile
    • KeInitializeEvent
    • ZwQueryObject
    • ZwOpenSymbolicLinkObject
    • ZwSetInformationFile
    • ObQueryNameString
    • IoFileObjectType
    • ZwCreateFile
    • IoGetCurrentProcess
    • ExFreePoolWithTag
    • KeWaitForSingleObject
    • IoFreeIrp
    • IoAllocateIrp
    • ZwQueryInformationProcess
    • ObfReferenceObject
    • ZwTerminateProcess
    • ZwQueryInformationFile
    • ObOpenObjectByPointer
    • IofCallDriver
    • _vsnwprintf
    • ZwCreateKey
    • ZwDeleteValueKey
    • ZwSetValueKey
    • CmRegisterCallback
    • CmUnRegisterCallback
    • ZwDeleteKey
    • DbgPrintEx
    • NtBuildNumber
    • wcschr
    • IoAcquireVpbSpinLock
    • SeCreateAccessState
    • IoGetFileObjectGenericMapping
    • ObCreateObject
    • ObInsertObject
    • IoGetDeviceObjectPointer
    • RtlUpperChar
    • RtlPrefixUnicodeString
    • IoReleaseVpbSpinLock
    • RtlEqualUnicodeString
    • IoDeleteSymbolicLink
    • ExAllocatePoolWithTag
    • mbstowcs
    • RtlAppendUnicodeStringToString
    • _wcsicmp
    • __C_specific_handler
    • FltEnumerateInstances
    • FltEnumerateFilters
    • FltObjectDereference
    • FltGetFilterInformation

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • PAGE
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": false,
          "SerialNumber": "0400000000012f4ee152d7",
          "Signature": "4e5e56901e46b4d94931f3bb1739281bc216ddfd41dc0905049b6fb2a29ad6992e40990055b5ea3fa52076d38634d417cc553ac782eeefa8babcd8069f1550dfcd167b523a02d7191afdaff0785ce04bc518df3a241edaacb8a95804020730dbb0125efe31bef00448f4f070f83a5e5683cf3dfb0dbcf4c5ed979db9d4dba52784e3389b8ba735864420a43b6da46a0ba183fd28ebdaef28f6cc885dfb0a3b00abe021ebe22f356c0f8e344597eba2f79933357ecb9a8abb454de73f9fc2d98afa65b26ec77e65ffe892e12c31a2f7b02736488f266f3bee4d761f79c3e57f9635bc2d0ecc01b08e7fff518080a792d4b34446648c874f166307314b63b0dff3",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "CN=GlobalSign Timestamping CA , G2,O=GlobalSign nv,sa,C=BE",
          "TBS": {
            "MD5": "e140543fe3256027cfa79fc3c19c1776",
            "SHA1": "c655f94eb1ecc93de319fc0c9a2dc6c5ec063728",
            "SHA256": "3ca71e85908ff67368e4dc00253f5691b9e6d50c966e7784143d75fb92aa3448",
            "SHA384": "d9d366f9328f2b55ee19a32cc5fd5148b81d764282fe5dc196c872ae249caa51d2c212ef39f33945dfe0cda81925e326"
          },
          "ValidFrom": "2011-04-13 10:00:00",
          "ValidTo": "2028-01-28 12:00:00",
          "Version": 3
        },
        {
          "CertificateType": "Intermediate",
          "IsCA": false,
          "IsCertificateAuthority": false,
          "IsCodeSigning": false,
          "SerialNumber": "112106a081d33fd87ae5824cc16b52094e03",
          "Signature": "8032dc078d1ca09c9d3c2ae83d218b59a14d7ecc44ce03be7eaabcc4e67b73bb4bf188da904e7537283863b9d72b0f54a956ce7739973073cd9bd9d905451c8da4b8035d4fd91c2e98e0e988e6ecd7057e562a7bf7165ba3ad8f972512841bb25c634a0ad2ef10544782843569289c0ce41f141624fa75dc74726e4ecae36a43afcf7d3648d1bde906912c2fa6c871fdcfbdd89d2198fcafdbde228cafa7f377ef9ddca3704b441af078851ef2a58c39b5dc881c37edad14f5070b26bdbe6d025eb1b8b0586c853a0df6ff5a270cc5de53e7543c564cc94e4c30f6f25cfb1a8cc282bead5991f61b4d557bcf5b01dcfd7ad36f235c32479b01f3c15114468a9b",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "CN=GlobalSign TSA for MS Authenticode , G2,O=GMO GlobalSign Pte Ltd,C=SG",
          "TBS": {
            "MD5": "a0ac4d48fe852f7b3ed4e623d59a825f",
            "SHA1": "d4db9846bc4d7db142eeb364286f6de7c102420c",
            "SHA256": "78d2e41a13eb4e9171bae2d2adb192cf39210b5231f77cda936bcfbe8c003bdf",
            "SHA384": "990ed96dca5979deeedc98a012279f04efb5559d7e7f5084a12f3802ee9439326557aecefd081cff739b78515b5d7f50"
          },
          "ValidFrom": "2015-02-03 00:00:00",
          "ValidTo": "2026-03-03 00:00:00",
          "Version": 3
        },
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": true,
          "SerialNumber": "250ce8e030612e9f2b89f7054d7cf8fd",
          "Signature": "1302ddf8e88600f25af8f8200c59886207cecef74ef9bb59a198e5e138dd4ebc6618d3adeb18f20dc96d3e4a9420c33cbabd6554c6af44b310ad2c6b3eabd707b6b88163c5f95e2ee52a67cecd330c2ad7895603231fb3bee83a0859b4ec4535f78a5bff66cf50afc66d578d1978b7b9a2d157ea1f9a4bafbac98e127ec6bdff",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "CN=VeriSign Class 3 Public Primary Certification Authority , G5,OU=(c) 2006 VeriSign, Inc. , For authorized use only,OU=VeriSign Trust Network,O=VeriSign, Inc.,C=US",
          "TBS": {
            "MD5": "918d9eb6a6cd36c531eceb926170a7e1",
            "SHA1": "0ae95700d65e6f59715aa47048993ca7858e676a",
            "SHA256": "47c46e6eaa3780eace3d0d891346cd373359d246b21a957219dbab4c8f37c166",
            "SHA384": "e54017c93ba52f012cc15aeb3bcbce1e90a0006ff8dca231a24fc572926770f63213343f538003407bed3463fa9c4a85"
          },
          "ValidFrom": "2006-11-08 00:00:00",
          "ValidTo": "2021-11-07 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": false,
          "SerialNumber": "610c120600000000001b",
          "Signature": "01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "OU=Class 3 Public Primary Certification Authority,O=VeriSign, Inc.,C=US",
          "TBS": {
            "MD5": "53c41bc1164e09e0cd1617a5bf913efd",
            "SHA1": "93c03aac8951d494ecd5696b1c08658541b18727",
            "SHA256": "40bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b",
            "SHA384": "f51d4e75ba638f7314cd59b8d6d45f3b34d35ce6986e9d205cd6f333e8e8d8e9c91f636e6bc84731b6661673f40963d8"
          },
          "ValidFrom": "2006-05-23 17:01:29",
          "ValidTo": "2016-05-23 17:11:29",
          "Version": 3
        },
        {
          "CertificateType": "Leaf (Code Signing)",
          "IsCA": false,
          "IsCertificateAuthority": false,
          "IsCodeSigning": true,
          "SerialNumber": "3bdb1994b98bbb19ab55a42337fa4f5c",
          "Signature": "d4d31733c0a04a890eecbf1af9f227dc09186dcc6625ee8b059ae8e4fbd4e0fd22f86e9d993b3974a60e9fc5905d6322dbaf62759cb40f596c5805b8607ad52a825c4b4da405aa8b8c024d7117e573a36fbb576355d8449afae87238aae1a63a2271d85abae4387066d04a0362ca7ff482752f0f057bdfc36802dc2c1a9aff13d527340edfcfebe04ed920f9996410e23c6afce70d7387dca8fff985b336da6a63ebf48ccfe8b968ae35111dbab3047d929a54321b31869886932912bec609ab7715021211eb409857e25a3f6c4b573a81da6b666541429a87a702a0879153fe04ca809c819598c38cc0a7a32e4489174324828284329ee1b8a97c9609ca7899",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "CN=Baidu Online Network Technology (Beijing)Co., Ltd,OU=Digital ID Class 3 , Microsoft Software Validation v2,O=Baidu Online Network Technology (Beijing)Co., Ltd,L=Beijing,ST=Beijing,C=CN",
          "TBS": {
            "MD5": "9ea2687f1fc2e86224cb68486714762c",
            "SHA1": "6d36f4a52430aa26965512fc6ba47a6761e041a9",
            "SHA256": "8a741d00a587923919f7fef79b7922ecff7a584ba2551715c5187e399366e66e",
            "SHA384": "d815eaf2f1988000cd6bebf1199c9ad957b044a5adb9966978eb3459f3ee564f441c37d4c03cd2529d10418bed2c90d9"
          },
          "ValidFrom": "2012-04-24 00:00:00",
          "ValidTo": "2015-04-24 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": true,
          "SerialNumber": "5200e5aa2556fc1a86ed96c9d44b33c7",
          "Signature": "5622e634a4c461cb48b901ad56a8640fd98c91c4bbcc0ce5ad7aa0227fdf47384a2d6cd17f711a7cec70a9b1f04fe40f0c53fa155efe749849248581261c911447b04c638cbba134d4c645e80d85267303d0a98c646ddc7192e645056015595139fc58146bfed4a4ed796b080c4172e737220609be23e93f449a1ee9619dccb1905cfc3dd28dac423d6536d4b43d40288f9b10cf2326cc4b20cb901f5d8c4c34ca3cd8e537d66fa520bd34eb26d9ae0de7c59af7a1b42191336f86e858bb257c740e58fe751b633fce317c9b8f1b969ec55376845b9cad91faaced93ba5dc82153c2825363af120d5087111b3d5452968a2c9c3d921a089a052ec793a54891d3",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "CN=VeriSign Class 3 Code Signing 2010 CA,OU=Terms of use at https://www.verisign.com/rpa (c)10,OU=VeriSign Trust Network,O=VeriSign, Inc.,C=US",
          "TBS": {
            "MD5": "b30c31a572b0409383ed3fbe17e56e81",
            "SHA1": "4843a82ed3b1f2bfbee9671960e1940c942f688d",
            "SHA256": "03cda47a6e654ed85d932714fc09ce4874600eda29ec6628cfbaeb155cab78c9",
            "SHA384": "bbda8407c4f9fc4e54d772f1c7fb9d30bc97e1f97ecd51c443063d1fa0644e266328781776cd5c44896c457c75f4d7da"
          },
          "ValidFrom": "2010-02-08 00:00:00",
          "ValidTo": "2020-02-07 23:59:59",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv,sa,C=BE",
          "SerialNumber": "3bdb1994b98bbb19ab55a42337fa4f5c",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    source

    last_updated: 2026-01-07