741677e9-20d5-40e5-9cd2-3bf2beb76322

dpmemio.sys :inline

Description

ET&T Technology Co., Ltd. dpmemio.sys (ClevoECView) is a 12KB driver with only 9 imports that provides completely unrestricted arbitrary physical memory read/write and I/O port access with no authentication, no ACL, no address validation, and no size validation. MmUnmapIoSpace is not even imported, meaning every MmMapIoSpace call permanently leaks a system PTE mapping. An additional bug exists where MOVSXD sign-extension on a 32-bit UserBufferPtr provides a write-to-kernel-VA primitive. IOCTLs exposed via \.\dpMemIO include 0xC80A2420 (arbitrary physical memory READ via MmMapIoSpace), 0xC80A2424 (arbitrary physical memory WRITE via MmMapIoSpace), 0xC80A2410/0xC80A2414 (I/O port read/write byte), 0xC80A2418/0xC80A241C (I/O port read/write variable size), and 0xC80A2428 (version/ping). VeriSign signed with a revoked certificate.

  • UUID: 741677e9-20d5-40e5-9cd2-3bf2beb76322
  • Created: 2026-04-06
  • Author: Michael Haag
  • Acknowledgement: weezerOSINT | @weezerOSINT

Download

This download link contains the vulnerable driver!

Block dpmemio.sys across your endpoints

Add this driver to your block policy in minutes with MagicSword, threat-driven application control. Free for up to 100 endpoints.

Start Blocking for Free

Commands

sc.exe create dpMemIO binPath=C:\windows\temp\dpmemio.sys type=kernel && sc.exe start dpMemIO
Use CasePrivilegesOperating System
Elevate privilegeskernelWindows 10

Detections

YARA 🏹

Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed driver files

Sigma 🛡️

Expand

Names

detects loading using name only

Hashes

detects loading using hashes only

Sysmon 🔎

Expand

Block

on hashes

Alert

on hashes

Resources


  • https://github.com/magicsword-io/LOLDrivers/issues/288
  • https://www.virustotal.com/gui/file/7cf6881e43337c288b1883fafb234146a450ff94388aee395e05e36202c5afbb
  • https://www.virustotal.com/gui/file/cd631c54fe1375e4bdd2f63b58bd106066eeee267fc77b3161ceb023ab5fddda

  • Known Vulnerable Samples

    PropertyValue
    Filenamedpmemio.sys
    Creation Timestamp2007-06-06 09:54:21
    MD51176d570c2c1af00f92feef45cea1614
    SHA16f6c0176e75b2aea004c54a963fc4cee0f67bc2e
    SHA2567cf6881e43337c288b1883fafb234146a450ff94388aee395e05e36202c5afbb
    Authentihash MD50def4c412000a7bef2a2cafd00f50126
    Authentihash SHA146be73d4bca95080185b99576671b51de9edc847
    Authentihash SHA2569dd70d3c1262b36468cb79ad26580a9d8b90e557d148ea36034b9c1195af6815
    RichPEHeaderHash MD59f434cf4ef4cf02a1c04edd1db2f1b54
    RichPEHeaderHash SHA1a5e1939b262f610f3428ee71eaa4e6d3bddda4b3
    RichPEHeaderHash SHA2567ddcfd965cd2cc3065b0b333db796e294a4e63fcdbb29a2cde54de053952e274
    PublisherET&T Technology Co.,Ltd.
    Date2007-02-06 00:00:00
    DescriptionDirect Physical Memory and Port access driver
    ProductDirect Physical Memory and Port access driver
    OriginalFilenamedpmemio.sys

    Download

    Certificates

    Expand
    Certificate 47bf1995df8d524643f7db6d480d31a4
    FieldValue
    ToBeSigned (TBS) MD5518d2ea8a21e879c942d504824ac211c
    ToBeSigned (TBS) SHA121ce87d827077e61abddf2beba69fde5432ea031
    ToBeSigned (TBS) SHA2561ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA
    ValidFrom2003-12-04 00:00:00
    ValidTo2013-12-03 23:59:59
    Signature4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber47bf1995df8d524643f7db6d480d31a4
    Version3
    Certificate 0de92bf0d4d82988183205095e9a7688
    FieldValue
    ToBeSigned (TBS) MD545c204b8a20f6abb0188d2d38a3fb0c9
    ToBeSigned (TBS) SHA1cdf3a3c5c2eda4c29621f30fd3154f9f8c765739
    ToBeSigned (TBS) SHA256e32839dddc0f4ed2474efaf37f59d46db400c700fd19533cb0895a111124bc77
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services Signer
    ValidFrom2003-12-04 00:00:00
    ValidTo2008-12-03 23:59:59
    Signature877870da4e5201205be079c98230c4fdb91996bd9100c3bdcdcdc6f40ed8fff94dc033623011c5f5741bd492de5f9c2013b17c45be50cd83e7801783a72793671346fbcab8984103cc9b515b058b7fa86ff31b501b242ef2698d6c22f7bbca1695ed0c74c06877d9eb996287c17390f889747a23aba3987b97b1f78f29714d2e751b4841daf0b50d2054d677a097826369fd09cf8af075bb099bd9f91155269a6132be7a02b07b86bea2c38b222c78d13576bc92735cf9b9e64c150a23cce4d2d4342e4940153c0f607a24c6a566ef96cf70eb3ee7f40d7edcd17ca3767169c19c4f47303521b1a2af1a623c2bd98eaa2a077bd818b35c7be29da56ffe3c89ad
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber0de92bf0d4d82988183205095e9a7688
    Version3
    Certificate 4191a15a3978dfcf496566381d4c75c2
    FieldValue
    ToBeSigned (TBS) MD541011f8d0e7c7a6408334ca387914c61
    ToBeSigned (TBS) SHA1c7fc1727f5b75a6421a1f95c73bbdb23580c48e5
    ToBeSigned (TBS) SHA25688dd3952638ee82738c03168e6fd863fe4eab1059ee5e2926ad8cb587c255dc0
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)04, CN=VeriSign Class 3 Code Signing 2004 CA
    ValidFrom2004-07-16 00:00:00
    ValidTo2014-07-15 23:59:59
    Signatureae3a17b84a7b55fa6455ec40a4ed494190999c89bcaf2e1dca7823f91c190f7feb68bc32d98838dedc3fd389b43fb18296f1a45abaed2e26d3de7c016e000a00a4069211480940f91c1879672324e0bbd5e150ae1bf50edde02e81cd80a36c524f9175558aba22f2d2ea4175882f63557d1e545a9559cad93481c05f5ef67ab5
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber4191a15a3978dfcf496566381d4c75c2
    Version3
    Certificate 7817f8d95c5c37dd0a668e5aa1ba5743
    FieldValue
    ToBeSigned (TBS) MD547adac8510894e82c819d424e46f64bb
    ToBeSigned (TBS) SHA1fa98632eaca04b46b42ac3436570ffbd63607889
    ToBeSigned (TBS) SHA256c66eec79e3b771ad59d4a2498254282bd2f8ee5f61abc5bb66aa9fc6d3f5defc
    SubjectC=TW, ST=Taiwan, L=Taipei, O=ET&T Technology Co.,Ltd., OU=Digital ID Class 3 , Microsoft Software Validation v2, OU=R&D, CN=ET&T Technology Co.,Ltd.
    ValidFrom2007-02-06 00:00:00
    ValidTo2008-02-06 23:59:59
    Signature53ef10c58d128ceb55e458b48729529d67026d2c73ba0996b17df9b1db8fbdb1ddeb9c7e3b541fb10d5813a792a2abdc631b133aae44e364c948cffa15650dc980da2b984eabdc4dc76a47d4ef26966ea42d9124d7a13774fd6b1c9ae5c84bd9c58197d95a787a2b3830b6c0f595b99b60424d059ade8bce5d73541c60fbe294b7bf5ab017c13960c57694ccf0bf1790fa6a156b21b133ed9812e3b593409b6039628db453979a8403cf01160e64cd213aa7f1593d3b59436e33972c602d0a23f88c463fc9c4834cce6ca6057764ac5cbc377f455ca150f99fb8e8209848200d1d03825eeec09cc9f9de346d526b3bd1bde5a9682e59210a3e6fcdee2801d169
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber7817f8d95c5c37dd0a668e5aa1ba5743
    Version3
    Certificate 610c120600000000001b
    FieldValue
    ToBeSigned (TBS) MD553c41bc1164e09e0cd1617a5bf913efd
    ToBeSigned (TBS) SHA193c03aac8951d494ecd5696b1c08658541b18727
    ToBeSigned (TBS) SHA25640bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b
    SubjectC=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
    ValidFrom2006-05-23 17:01:29
    ValidTo2016-05-23 17:11:29
    Signature01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610c120600000000001b
    Version3

    Imports

    Expand
    • ntoskrnl.exe

    Imported Functions

    Expand
    • IofCompleteRequest
    • RtlCopyMemory
    • MmMapIoSpace
    • IoDeleteDevice
    • IoDeleteSymbolicLink
    • RtlInitUnicodeString
    • IoCreateSymbolicLink
    • IoCreateDevice
    • KeBugCheckEx

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • INIT
    • .rsrc

    Signature

    Expand
    {
      "Certificates": [
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": false,
          "SerialNumber": "47bf1995df8d524643f7db6d480d31a4",
          "Signature": "4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA",
          "TBS": {
            "MD5": "518d2ea8a21e879c942d504824ac211c",
            "SHA1": "21ce87d827077e61abddf2beba69fde5432ea031",
            "SHA256": "1ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7",
            "SHA384": "53e346bbde23779a5d116cc9d86fdd71c97b1f1b343439f8a11aa1d3c87af63864bb8488a5aeb2d0c26a6a1e0b15f03f"
          },
          "ValidFrom": "2003-12-04 00:00:00",
          "ValidTo": "2013-12-03 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "Intermediate",
          "IsCA": false,
          "IsCertificateAuthority": false,
          "IsCodeSigning": false,
          "SerialNumber": "0de92bf0d4d82988183205095e9a7688",
          "Signature": "877870da4e5201205be079c98230c4fdb91996bd9100c3bdcdcdc6f40ed8fff94dc033623011c5f5741bd492de5f9c2013b17c45be50cd83e7801783a72793671346fbcab8984103cc9b515b058b7fa86ff31b501b242ef2698d6c22f7bbca1695ed0c74c06877d9eb996287c17390f889747a23aba3987b97b1f78f29714d2e751b4841daf0b50d2054d677a097826369fd09cf8af075bb099bd9f91155269a6132be7a02b07b86bea2c38b222c78d13576bc92735cf9b9e64c150a23cce4d2d4342e4940153c0f607a24c6a566ef96cf70eb3ee7f40d7edcd17ca3767169c19c4f47303521b1a2af1a623c2bd98eaa2a077bd818b35c7be29da56ffe3c89ad",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services Signer",
          "TBS": {
            "MD5": "45c204b8a20f6abb0188d2d38a3fb0c9",
            "SHA1": "cdf3a3c5c2eda4c29621f30fd3154f9f8c765739",
            "SHA256": "e32839dddc0f4ed2474efaf37f59d46db400c700fd19533cb0895a111124bc77",
            "SHA384": "ee9c75832cb252218b3201619852209df490d2ef7a5f7a28afdb37f1c1dd56f4604898838e558f615b1c798d4a488223"
          },
          "ValidFrom": "2003-12-04 00:00:00",
          "ValidTo": "2008-12-03 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": true,
          "SerialNumber": "4191a15a3978dfcf496566381d4c75c2",
          "Signature": "ae3a17b84a7b55fa6455ec40a4ed494190999c89bcaf2e1dca7823f91c190f7feb68bc32d98838dedc3fd389b43fb18296f1a45abaed2e26d3de7c016e000a00a4069211480940f91c1879672324e0bbd5e150ae1bf50edde02e81cd80a36c524f9175558aba22f2d2ea4175882f63557d1e545a9559cad93481c05f5ef67ab5",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)04, CN=VeriSign Class 3 Code Signing 2004 CA",
          "TBS": {
            "MD5": "41011f8d0e7c7a6408334ca387914c61",
            "SHA1": "c7fc1727f5b75a6421a1f95c73bbdb23580c48e5",
            "SHA256": "88dd3952638ee82738c03168e6fd863fe4eab1059ee5e2926ad8cb587c255dc0",
            "SHA384": "a00aa5ed457c41e37967882644d63366bae014f03a986576d8514164d7027acf7d0b5e03d764db2558f60db148954459"
          },
          "ValidFrom": "2004-07-16 00:00:00",
          "ValidTo": "2014-07-15 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "Leaf (Code Signing)",
          "IsCA": false,
          "IsCertificateAuthority": false,
          "IsCodeSigning": true,
          "SerialNumber": "7817f8d95c5c37dd0a668e5aa1ba5743",
          "Signature": "53ef10c58d128ceb55e458b48729529d67026d2c73ba0996b17df9b1db8fbdb1ddeb9c7e3b541fb10d5813a792a2abdc631b133aae44e364c948cffa15650dc980da2b984eabdc4dc76a47d4ef26966ea42d9124d7a13774fd6b1c9ae5c84bd9c58197d95a787a2b3830b6c0f595b99b60424d059ade8bce5d73541c60fbe294b7bf5ab017c13960c57694ccf0bf1790fa6a156b21b133ed9812e3b593409b6039628db453979a8403cf01160e64cd213aa7f1593d3b59436e33972c602d0a23f88c463fc9c4834cce6ca6057764ac5cbc377f455ca150f99fb8e8209848200d1d03825eeec09cc9f9de346d526b3bd1bde5a9682e59210a3e6fcdee2801d169",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=TW, ST=Taiwan, L=Taipei, O=ET\u0026T Technology Co.,Ltd., OU=Digital ID Class 3 , Microsoft Software Validation v2, OU=R\u0026D, CN=ET\u0026T Technology Co.,Ltd.",
          "TBS": {
            "MD5": "47adac8510894e82c819d424e46f64bb",
            "SHA1": "fa98632eaca04b46b42ac3436570ffbd63607889",
            "SHA256": "c66eec79e3b771ad59d4a2498254282bd2f8ee5f61abc5bb66aa9fc6d3f5defc",
            "SHA384": "03e7ec2bf67423c2398ddeac6e166c6f5cebf3b07d4b5953ed11674415cc0ffa2715b8d57b78e3e25fcb7dc73704851b"
          },
          "ValidFrom": "2007-02-06 00:00:00",
          "ValidTo": "2008-02-06 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": false,
          "SerialNumber": "610c120600000000001b",
          "Signature": "01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority",
          "TBS": {
            "MD5": "53c41bc1164e09e0cd1617a5bf913efd",
            "SHA1": "93c03aac8951d494ecd5696b1c08658541b18727",
            "SHA256": "40bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b",
            "SHA384": "f51d4e75ba638f7314cd59b8d6d45f3b34d35ce6986e9d205cd6f333e8e8d8e9c91f636e6bc84731b6661673f40963d8"
          },
          "ValidFrom": "2006-05-23 17:01:29",
          "ValidTo": "2016-05-23 17:11:29",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)04, CN=VeriSign Class 3 Code Signing 2004 CA",
          "SerialNumber": "7817f8d95c5c37dd0a668e5aa1ba5743",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    PropertyValue
    Filenamedpmemio.sys
    Creation Timestamp
    MD581317f20d85addb0407e5f5c15095a53
    SHA17bb3b01e5cdc6b5b98d75f64667d29e2c151f8cc
    SHA256cd631c54fe1375e4bdd2f63b58bd106066eeee267fc77b3161ceb023ab5fddda
    Authentihash MD52798e1bb95ee53e08c1088fbec65f35a
    Authentihash SHA1bb6e9bc2437bee2d30f739beb054750cd6ca24cc
    Authentihash SHA256c25c71ca670d6d27ced406b8cba8aa92a4b96898ec1506f59f4fef09c1f3bb11
    RichPEHeaderHash MD57a98db6636f7aef4106502e95d88556f
    RichPEHeaderHash SHA1acc2d551ac5a88713e421e45306f1a1b05067d3d
    RichPEHeaderHash SHA256489ab5bcde963db4f2f820a17d16b7b1cdde7d3ebaaa9fc31ac68c9cfbc56399
    PublisherET&T Technology Co.,Ltd.
    Date2007-02-06 00:00:00
    CompanyWindows (R) Codename Longhorn DDK provider
    DescriptionDirect Physical Memory and Port access driver
    ProductWindows (R) Codename Longhorn DDK driver
    OriginalFilenamedpmemio.sys

    Download

    Certificates

    Expand
    Certificate 47bf1995df8d524643f7db6d480d31a4
    FieldValue
    ToBeSigned (TBS) MD5518d2ea8a21e879c942d504824ac211c
    ToBeSigned (TBS) SHA121ce87d827077e61abddf2beba69fde5432ea031
    ToBeSigned (TBS) SHA2561ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA
    ValidFrom2003-12-04 00:00:00
    ValidTo2013-12-03 23:59:59
    Signature
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber47bf1995df8d524643f7db6d480d31a4
    Version3
    Certificate 0de92bf0d4d82988183205095e9a7688
    FieldValue
    ToBeSigned (TBS) MD545c204b8a20f6abb0188d2d38a3fb0c9
    ToBeSigned (TBS) SHA1cdf3a3c5c2eda4c29621f30fd3154f9f8c765739
    ToBeSigned (TBS) SHA256e32839dddc0f4ed2474efaf37f59d46db400c700fd19533cb0895a111124bc77
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services Signer
    ValidFrom2003-12-04 00:00:00
    ValidTo2008-12-03 23:59:59
    Signature
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber0de92bf0d4d82988183205095e9a7688
    Version3
    Certificate 4191a15a3978dfcf496566381d4c75c2
    FieldValue
    ToBeSigned (TBS) MD541011f8d0e7c7a6408334ca387914c61
    ToBeSigned (TBS) SHA1c7fc1727f5b75a6421a1f95c73bbdb23580c48e5
    ToBeSigned (TBS) SHA25688dd3952638ee82738c03168e6fd863fe4eab1059ee5e2926ad8cb587c255dc0
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)04, CN=VeriSign Class 3 Code Signing 2004 CA
    ValidFrom2004-07-16 00:00:00
    ValidTo2014-07-15 23:59:59
    Signature
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber4191a15a3978dfcf496566381d4c75c2
    Version3
    Certificate 7817f8d95c5c37dd0a668e5aa1ba5743
    FieldValue
    ToBeSigned (TBS) MD547adac8510894e82c819d424e46f64bb
    ToBeSigned (TBS) SHA1fa98632eaca04b46b42ac3436570ffbd63607889
    ToBeSigned (TBS) SHA256c66eec79e3b771ad59d4a2498254282bd2f8ee5f61abc5bb66aa9fc6d3f5defc
    SubjectC=TW, ST=Taiwan, L=Taipei, O=ET&T Technology Co.,Ltd., OU=Digital ID Class 3 , Microsoft Software Validation v2, OU=R&D, CN=ET&T Technology Co.,Ltd.
    ValidFrom2007-02-06 00:00:00
    ValidTo2008-02-06 23:59:59
    Signature
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber7817f8d95c5c37dd0a668e5aa1ba5743
    Version3
    Certificate 610c120600000000001b
    FieldValue
    ToBeSigned (TBS) MD553c41bc1164e09e0cd1617a5bf913efd
    ToBeSigned (TBS) SHA193c03aac8951d494ecd5696b1c08658541b18727
    ToBeSigned (TBS) SHA25640bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b
    SubjectC=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
    ValidFrom2006-05-23 17:01:29
    ValidTo2016-05-23 17:11:29
    Signature
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610c120600000000001b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • HAL.dll

    Imported Functions

    Expand
    • IoCreateDevice
    • IoCreateSymbolicLink
    • KeBugCheckEx
    • RtlInitUnicodeString
    • IoDeleteSymbolicLink
    • IoDeleteDevice
    • memcpy
    • MmMapIoSpace
    • KeTickCount
    • IofCompleteRequest
    • WRITE_PORT_USHORT
    • READ_PORT_ULONG
    • READ_PORT_USHORT
    • READ_PORT_UCHAR
    • WRITE_PORT_UCHAR
    • WRITE_PORT_ULONG

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": false,
          "SerialNumber": "47bf1995df8d524643f7db6d480d31a4",
          "Signature": "4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA",
          "TBS": {
            "MD5": "518d2ea8a21e879c942d504824ac211c",
            "SHA1": "21ce87d827077e61abddf2beba69fde5432ea031",
            "SHA256": "1ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7",
            "SHA384": "53e346bbde23779a5d116cc9d86fdd71c97b1f1b343439f8a11aa1d3c87af63864bb8488a5aeb2d0c26a6a1e0b15f03f"
          },
          "ValidFrom": "2003-12-04 00:00:00",
          "ValidTo": "2013-12-03 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "Intermediate",
          "IsCA": false,
          "IsCertificateAuthority": false,
          "IsCodeSigning": false,
          "SerialNumber": "0de92bf0d4d82988183205095e9a7688",
          "Signature": "877870da4e5201205be079c98230c4fdb91996bd9100c3bdcdcdc6f40ed8fff94dc033623011c5f5741bd492de5f9c2013b17c45be50cd83e7801783a72793671346fbcab8984103cc9b515b058b7fa86ff31b501b242ef2698d6c22f7bbca1695ed0c74c06877d9eb996287c17390f889747a23aba3987b97b1f78f29714d2e751b4841daf0b50d2054d677a097826369fd09cf8af075bb099bd9f91155269a6132be7a02b07b86bea2c38b222c78d13576bc92735cf9b9e64c150a23cce4d2d4342e4940153c0f607a24c6a566ef96cf70eb3ee7f40d7edcd17ca3767169c19c4f47303521b1a2af1a623c2bd98eaa2a077bd818b35c7be29da56ffe3c89ad",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services Signer",
          "TBS": {
            "MD5": "45c204b8a20f6abb0188d2d38a3fb0c9",
            "SHA1": "cdf3a3c5c2eda4c29621f30fd3154f9f8c765739",
            "SHA256": "e32839dddc0f4ed2474efaf37f59d46db400c700fd19533cb0895a111124bc77",
            "SHA384": "ee9c75832cb252218b3201619852209df490d2ef7a5f7a28afdb37f1c1dd56f4604898838e558f615b1c798d4a488223"
          },
          "ValidFrom": "2003-12-04 00:00:00",
          "ValidTo": "2008-12-03 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": true,
          "SerialNumber": "4191a15a3978dfcf496566381d4c75c2",
          "Signature": "ae3a17b84a7b55fa6455ec40a4ed494190999c89bcaf2e1dca7823f91c190f7feb68bc32d98838dedc3fd389b43fb18296f1a45abaed2e26d3de7c016e000a00a4069211480940f91c1879672324e0bbd5e150ae1bf50edde02e81cd80a36c524f9175558aba22f2d2ea4175882f63557d1e545a9559cad93481c05f5ef67ab5",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)04, CN=VeriSign Class 3 Code Signing 2004 CA",
          "TBS": {
            "MD5": "41011f8d0e7c7a6408334ca387914c61",
            "SHA1": "c7fc1727f5b75a6421a1f95c73bbdb23580c48e5",
            "SHA256": "88dd3952638ee82738c03168e6fd863fe4eab1059ee5e2926ad8cb587c255dc0",
            "SHA384": "a00aa5ed457c41e37967882644d63366bae014f03a986576d8514164d7027acf7d0b5e03d764db2558f60db148954459"
          },
          "ValidFrom": "2004-07-16 00:00:00",
          "ValidTo": "2014-07-15 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "Leaf (Code Signing)",
          "IsCA": false,
          "IsCertificateAuthority": false,
          "IsCodeSigning": true,
          "SerialNumber": "7817f8d95c5c37dd0a668e5aa1ba5743",
          "Signature": "53ef10c58d128ceb55e458b48729529d67026d2c73ba0996b17df9b1db8fbdb1ddeb9c7e3b541fb10d5813a792a2abdc631b133aae44e364c948cffa15650dc980da2b984eabdc4dc76a47d4ef26966ea42d9124d7a13774fd6b1c9ae5c84bd9c58197d95a787a2b3830b6c0f595b99b60424d059ade8bce5d73541c60fbe294b7bf5ab017c13960c57694ccf0bf1790fa6a156b21b133ed9812e3b593409b6039628db453979a8403cf01160e64cd213aa7f1593d3b59436e33972c602d0a23f88c463fc9c4834cce6ca6057764ac5cbc377f455ca150f99fb8e8209848200d1d03825eeec09cc9f9de346d526b3bd1bde5a9682e59210a3e6fcdee2801d169",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=TW, ST=Taiwan, L=Taipei, O=ET\u0026T Technology Co.,Ltd., OU=Digital ID Class 3 , Microsoft Software Validation v2, OU=R\u0026D, CN=ET\u0026T Technology Co.,Ltd.",
          "TBS": {
            "MD5": "47adac8510894e82c819d424e46f64bb",
            "SHA1": "fa98632eaca04b46b42ac3436570ffbd63607889",
            "SHA256": "c66eec79e3b771ad59d4a2498254282bd2f8ee5f61abc5bb66aa9fc6d3f5defc",
            "SHA384": "03e7ec2bf67423c2398ddeac6e166c6f5cebf3b07d4b5953ed11674415cc0ffa2715b8d57b78e3e25fcb7dc73704851b"
          },
          "ValidFrom": "2007-02-06 00:00:00",
          "ValidTo": "2008-02-06 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": false,
          "SerialNumber": "610c120600000000001b",
          "Signature": "01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority",
          "TBS": {
            "MD5": "53c41bc1164e09e0cd1617a5bf913efd",
            "SHA1": "93c03aac8951d494ecd5696b1c08658541b18727",
            "SHA256": "40bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b",
            "SHA384": "f51d4e75ba638f7314cd59b8d6d45f3b34d35ce6986e9d205cd6f333e8e8d8e9c91f636e6bc84731b6661673f40963d8"
          },
          "ValidFrom": "2006-05-23 17:01:29",
          "ValidTo": "2016-05-23 17:11:29",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)04, CN=VeriSign Class 3 Code Signing 2004 CA",
          "SerialNumber": "7817f8d95c5c37dd0a668e5aa1ba5743",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    source

    last_updated: 2026-05-04