83b78b88-3b43-41cc-a60f-cab1a7b96978

BdApiUtil.sys :inline

Description

BdApiUtil.sys is a kernel driver from Baidu Antivirus that exposes dangerous primitives to usermode with no authentication. The driver provides process termination by PID via PsLookupProcessByProcessId and ZwTerminateProcess (IOCTL 0x800024B4), process suspension via dynamically-resolved NtSuspendProcess (IOCTL 0x800024B8), full kernel registry CRUD including ZwOpenKey (0x80002190), ZwCreateKey (0x80002194), ZwSetValueKey (0x80002198), ZwDeleteKey (0x8000219C), and ZwDeleteValueKey (0x800021A0), and kernel-mode file creation via ObInsertObject/ZwCreateFile (0x80002324). The process termination primitive is exploited by the GoodBaiii EDR killer tool. Registry callback monitoring via CmRegisterCallback and process creation monitoring via PsSetCreateProcessNotifyRoutine are also present.

  • UUID: 83b78b88-3b43-41cc-a60f-cab1a7b96978
  • Created: 2026-04-22
  • Author: Michael Haag
  • Acknowledgement: | @MHaggis

Download

This download link contains the vulnerable driver!

Block BdApiUtil.sys across your endpoints

Add this driver to your block policy in minutes with MagicSword, threat-driven application control. Free for up to 100 endpoints.

Start Blocking for Free

Commands

sc.exe create BdApiUtil binPath=C:\windows\temp\BdApiUtil.sys type=kernel && sc.exe start BdApiUtil
Use CasePrivilegesOperating System
Elevate privilegeskernelWindows 10

Detections

YARA 🏹

Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed driver files

Sigma 🛡️

Expand

Names

detects loading using name only

Hashes

detects loading using hashes only

Sysmon 🔎

Expand

Block

on hashes

Alert

on hashes

Resources


  • https://github.com/magicsword-io/LOLDrivers/issues/231
  • https://github.com/RainbowDynamix/GoodBaiii

  • Known Vulnerable Samples

    PropertyValue
    FilenameBdApiUtil.sys
    Creation Timestamp2014-04-10 01:05:42
    MD56d46f925df569b488e9b63778ab0d91e
    SHA19837e4ce049cf164b7a484d91aad696d5e4f32c4
    SHA256d8ce0a5866178495a66d23c9587822164966111fcd34764011e907951c599711
    Authentihash MD53aecdab75ed6964577a461d869a724c1
    Authentihash SHA163f49a9859b18aa787c2978592ce4110b10e84b9
    Authentihash SHA25624ab8a064b5e3b501914eab88edd1fab75828a9bb4c781e41783283c45d15c71
    RichPEHeaderHash MD594abf4db433f44a7fbd1bba345c26a99
    RichPEHeaderHash SHA1fa20930f9aef107e06d761aed1c8b3b76ee174fe
    RichPEHeaderHash SHA2565cc5e625344124213f75451260e7090a9023b0bb3921d1065f0dbf17702d547a
    CompanyBaidu, Inc.
    DescriptionBaidu Antivirus BdApi Driver
    ProductBaidu Antivirus

    Download

    Certificates

    Expand
    Certificate 7e93ebfb7cc64e59ea4b9a77d406fc3b
    FieldValue
    ToBeSigned (TBS) MD5d0785ad36e427c92b19f6826ab1e8020
    ToBeSigned (TBS) SHA1365b7a9c21bd9373e49052c3e7b3e4646ddd4d43
    ToBeSigned (TBS) SHA256c2abb7484da91a658548de089d52436175fdb760a1387d225611dc0613a1e2ff
    SubjectC=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA , G2
    ValidFrom2012-12-21 00:00:00
    ValidTo2020-12-30 23:59:59
    Signature03099b8f79ef7f5930aaef68b5fae3091dbb4f82065d375fa6529f168dea1c9209446ef56deb587c30e8f9698d23730b126f47a9ae3911f82ab19bb01ac38eeb599600adce0c4db2d031a6085c2a7afce27a1d574ca86518e979406225966ec7c7376a8321088e41eaddd9573f1d7749872a16065ea6386a2212a35119837eb6
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber7e93ebfb7cc64e59ea4b9a77d406fc3b
    Version3
    Certificate 0ecff438c8febf356e04d86a981b1a50
    FieldValue
    ToBeSigned (TBS) MD5e9d38360b914c8863f6cba3ee58764d3
    ToBeSigned (TBS) SHA14cba8eae47b6bf76f20b3504b98b8f062694a89b
    ToBeSigned (TBS) SHA25688901d86a4cc1f1bb193d08e1fb63d27452e63f83e228c657ab1a92e4ade3976
    SubjectC=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G4
    ValidFrom2012-10-18 00:00:00
    ValidTo2020-12-29 23:59:59
    Signature783bb4912a004cf08f62303778a38427076f18b2de25dca0d49403aa864e259f9a40031cddcee379cb216806dab632b46dbff42c266333e449646d0de6c3670ef705a4356c7c8916c6e9b2dfb2e9dd20c6710fcd9574dcb65cdebd371f4378e678b5cd280420a3aaf14bc48829910e80d111fcdd5c766e4f5e0e4546416e0db0ea389ab13ada097110fc1c79b4807bac69f4fd9cb60c162bf17f5b093d9b5be216ca13816d002e380da8298f2ce1b2f45aa901af159c2c2f491bdb22bbc3fe789451c386b182885df03db451a179332b2e7bb9dc20091371eb6a195bcfe8a530572c89493fb9cf7fc9bf3e226863539abd6974acc51d3c7f92e0c3bc1cd80475
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber0ecff438c8febf356e04d86a981b1a50
    Version3
    Certificate 250ce8e030612e9f2b89f7054d7cf8fd
    FieldValue
    ToBeSigned (TBS) MD5918d9eb6a6cd36c531eceb926170a7e1
    ToBeSigned (TBS) SHA10ae95700d65e6f59715aa47048993ca7858e676a
    ToBeSigned (TBS) SHA25647c46e6eaa3780eace3d0d891346cd373359d246b21a957219dbab4c8f37c166
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5
    ValidFrom2006-11-08 00:00:00
    ValidTo2021-11-07 23:59:59
    Signature1302ddf8e88600f25af8f8200c59886207cecef74ef9bb59a198e5e138dd4ebc6618d3adeb18f20dc96d3e4a9420c33cbabd6554c6af44b310ad2c6b3eabd707b6b88163c5f95e2ee52a67cecd330c2ad7895603231fb3bee83a0859b4ec4535f78a5bff66cf50afc66d578d1978b7b9a2d157ea1f9a4bafbac98e127ec6bdff
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber250ce8e030612e9f2b89f7054d7cf8fd
    Version3
    Certificate 610c120600000000001b
    FieldValue
    ToBeSigned (TBS) MD553c41bc1164e09e0cd1617a5bf913efd
    ToBeSigned (TBS) SHA193c03aac8951d494ecd5696b1c08658541b18727
    ToBeSigned (TBS) SHA25640bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b
    SubjectC=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
    ValidFrom2006-05-23 17:01:29
    ValidTo2016-05-23 17:11:29
    Signature01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610c120600000000001b
    Version3
    Certificate 3bdb1994b98bbb19ab55a42337fa4f5c
    FieldValue
    ToBeSigned (TBS) MD59ea2687f1fc2e86224cb68486714762c
    ToBeSigned (TBS) SHA16d36f4a52430aa26965512fc6ba47a6761e041a9
    ToBeSigned (TBS) SHA2568a741d00a587923919f7fef79b7922ecff7a584ba2551715c5187e399366e66e
    SubjectC=CN, ST=Beijing, L=Beijing, O=Baidu Online Network Technology (Beijing)Co., Ltd, OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=Baidu Online Network Technology (Beijing)Co., Ltd
    ValidFrom2012-04-24 00:00:00
    ValidTo2015-04-24 23:59:59
    Signatured4d31733c0a04a890eecbf1af9f227dc09186dcc6625ee8b059ae8e4fbd4e0fd22f86e9d993b3974a60e9fc5905d6322dbaf62759cb40f596c5805b8607ad52a825c4b4da405aa8b8c024d7117e573a36fbb576355d8449afae87238aae1a63a2271d85abae4387066d04a0362ca7ff482752f0f057bdfc36802dc2c1a9aff13d527340edfcfebe04ed920f9996410e23c6afce70d7387dca8fff985b336da6a63ebf48ccfe8b968ae35111dbab3047d929a54321b31869886932912bec609ab7715021211eb409857e25a3f6c4b573a81da6b666541429a87a702a0879153fe04ca809c819598c38cc0a7a32e4489174324828284329ee1b8a97c9609ca7899
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber3bdb1994b98bbb19ab55a42337fa4f5c
    Version3
    Certificate 5200e5aa2556fc1a86ed96c9d44b33c7
    FieldValue
    ToBeSigned (TBS) MD5b30c31a572b0409383ed3fbe17e56e81
    ToBeSigned (TBS) SHA14843a82ed3b1f2bfbee9671960e1940c942f688d
    ToBeSigned (TBS) SHA25603cda47a6e654ed85d932714fc09ce4874600eda29ec6628cfbaeb155cab78c9
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA
    ValidFrom2010-02-08 00:00:00
    ValidTo2020-02-07 23:59:59
    Signature5622e634a4c461cb48b901ad56a8640fd98c91c4bbcc0ce5ad7aa0227fdf47384a2d6cd17f711a7cec70a9b1f04fe40f0c53fa155efe749849248581261c911447b04c638cbba134d4c645e80d85267303d0a98c646ddc7192e645056015595139fc58146bfed4a4ed796b080c4172e737220609be23e93f449a1ee9619dccb1905cfc3dd28dac423d6536d4b43d40288f9b10cf2326cc4b20cb901f5d8c4c34ca3cd8e537d66fa520bd34eb26d9ae0de7c59af7a1b42191336f86e858bb257c740e58fe751b633fce317c9b8f1b969ec55376845b9cad91faaced93ba5dc82153c2825363af120d5087111b3d5452968a2c9c3d921a089a052ec793a54891d3
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber5200e5aa2556fc1a86ed96c9d44b33c7
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • FLTMGR.SYS

    Imported Functions

    Expand
    • RtlInitUnicodeString
    • IoDeleteDevice
    • MmGetSystemRoutineAddress
    • IoDetachDevice
    • PsSetCreateProcessNotifyRoutine
    • wcslen
    • wcsrchr
    • ZwQueryValueKey
    • ZwClose
    • IofCompleteRequest
    • PsGetVersion
    • IoCreateSymbolicLink
    • PsGetCurrentProcessId
    • IoCreateDevice
    • ExCreateCallback
    • DbgPrint
    • ZwOpenKey
    • RtlCompareMemory
    • MmIsAddressValid
    • _stricmp
    • ZwMapViewOfSection
    • ExGetPreviousMode
    • ZwQuerySystemInformation
    • IoFreeMdl
    • MmMapLockedPagesSpecifyCache
    • _vsnprintf
    • NtClose
    • ObReferenceObjectByHandle
    • MmProbeAndLockPages
    • MmUnlockPages
    • strrchr
    • ObfDereferenceObject
    • ZwCreateSection
    • ZwOpenFile
    • IoAllocateMdl
    • ExQueueWorkItem
    • ProbeForRead
    • RtlVolumeDeviceToDosName
    • PsLookupProcessByProcessId
    • ZwQuerySymbolicLinkObject
    • _wcsnicmp
    • ZwReadFile
    • KeSetEvent
    • RtlAppendUnicodeToString
    • IoCreateFile
    • KeInitializeEvent
    • ZwQueryObject
    • ZwOpenSymbolicLinkObject
    • ZwSetInformationFile
    • ObQueryNameString
    • IoFileObjectType
    • ZwCreateFile
    • IoGetCurrentProcess
    • ExFreePoolWithTag
    • RtlAppendUnicodeStringToString
    • KeWaitForSingleObject
    • IoFreeIrp
    • IoAllocateIrp
    • ZwQueryInformationProcess
    • ObfReferenceObject
    • PsGetCurrentThreadId
    • RtlCopyUnicodeString
    • ZwTerminateProcess
    • ZwQueryInformationFile
    • ObOpenObjectByPointer
    • IofCallDriver
    • _vsnwprintf
    • ZwCreateKey
    • ZwDeleteValueKey
    • ZwSetValueKey
    • MmUserProbeAddress
    • ZwUnmapViewOfSection
    • CmRegisterCallback
    • CmUnRegisterCallback
    • ZwDeleteKey
    • DbgPrintEx
    • ObOpenObjectByName
    • ExNotifyCallback
    • NtBuildNumber
    • SeDeleteObjectAuditAlarm
    • wcschr
    • IoAcquireVpbSpinLock
    • SeCreateAccessState
    • IoGetFileObjectGenericMapping
    • ObCreateObject
    • ObInsertObject
    • IoGetDeviceObjectPointer
    • RtlUpperChar
    • RtlPrefixUnicodeString
    • IoReleaseVpbSpinLock
    • RtlEqualUnicodeString
    • KeReleaseInStackQueuedSpinLock
    • KeAcquireInStackQueuedSpinLock
    • PsTerminateSystemThread
    • KeWaitForMultipleObjects
    • IoDeleteSymbolicLink
    • ExAllocatePoolWithTag
    • mbstowcs
    • _wcsicmp
    • __C_specific_handler
    • FltEnumerateInstances
    • FltEnumerateFilters
    • FltObjectDereference
    • FltGetFilterInformation

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • PAGE
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": false,
          "SerialNumber": "7e93ebfb7cc64e59ea4b9a77d406fc3b",
          "Signature": "03099b8f79ef7f5930aaef68b5fae3091dbb4f82065d375fa6529f168dea1c9209446ef56deb587c30e8f9698d23730b126f47a9ae3911f82ab19bb01ac38eeb599600adce0c4db2d031a6085c2a7afce27a1d574ca86518e979406225966ec7c7376a8321088e41eaddd9573f1d7749872a16065ea6386a2212a35119837eb6",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA , G2",
          "TBS": {
            "MD5": "d0785ad36e427c92b19f6826ab1e8020",
            "SHA1": "365b7a9c21bd9373e49052c3e7b3e4646ddd4d43",
            "SHA256": "c2abb7484da91a658548de089d52436175fdb760a1387d225611dc0613a1e2ff",
            "SHA384": "eab4fe5ef90e0de4a6aa3a27769a5e879f588df5e4785aa4104debd1f81e19ea56d33e3a16e5facf99f68b5d8e3d287b"
          },
          "ValidFrom": "2012-12-21 00:00:00",
          "ValidTo": "2020-12-30 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "Intermediate",
          "IsCA": false,
          "IsCertificateAuthority": false,
          "IsCodeSigning": false,
          "SerialNumber": "0ecff438c8febf356e04d86a981b1a50",
          "Signature": "783bb4912a004cf08f62303778a38427076f18b2de25dca0d49403aa864e259f9a40031cddcee379cb216806dab632b46dbff42c266333e449646d0de6c3670ef705a4356c7c8916c6e9b2dfb2e9dd20c6710fcd9574dcb65cdebd371f4378e678b5cd280420a3aaf14bc48829910e80d111fcdd5c766e4f5e0e4546416e0db0ea389ab13ada097110fc1c79b4807bac69f4fd9cb60c162bf17f5b093d9b5be216ca13816d002e380da8298f2ce1b2f45aa901af159c2c2f491bdb22bbc3fe789451c386b182885df03db451a179332b2e7bb9dc20091371eb6a195bcfe8a530572c89493fb9cf7fc9bf3e226863539abd6974acc51d3c7f92e0c3bc1cd80475",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer , G4",
          "TBS": {
            "MD5": "e9d38360b914c8863f6cba3ee58764d3",
            "SHA1": "4cba8eae47b6bf76f20b3504b98b8f062694a89b",
            "SHA256": "88901d86a4cc1f1bb193d08e1fb63d27452e63f83e228c657ab1a92e4ade3976",
            "SHA384": "e9f2a75334a9e336c5a4712eadee88d0374b0fdc273262f4e65c9040ad2793067cc076696db5279a478773485e285652"
          },
          "ValidFrom": "2012-10-18 00:00:00",
          "ValidTo": "2020-12-29 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": true,
          "SerialNumber": "250ce8e030612e9f2b89f7054d7cf8fd",
          "Signature": "1302ddf8e88600f25af8f8200c59886207cecef74ef9bb59a198e5e138dd4ebc6618d3adeb18f20dc96d3e4a9420c33cbabd6554c6af44b310ad2c6b3eabd707b6b88163c5f95e2ee52a67cecd330c2ad7895603231fb3bee83a0859b4ec4535f78a5bff66cf50afc66d578d1978b7b9a2d157ea1f9a4bafbac98e127ec6bdff",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. , For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority , G5",
          "TBS": {
            "MD5": "918d9eb6a6cd36c531eceb926170a7e1",
            "SHA1": "0ae95700d65e6f59715aa47048993ca7858e676a",
            "SHA256": "47c46e6eaa3780eace3d0d891346cd373359d246b21a957219dbab4c8f37c166",
            "SHA384": "e54017c93ba52f012cc15aeb3bcbce1e90a0006ff8dca231a24fc572926770f63213343f538003407bed3463fa9c4a85"
          },
          "ValidFrom": "2006-11-08 00:00:00",
          "ValidTo": "2021-11-07 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": false,
          "SerialNumber": "610c120600000000001b",
          "Signature": "01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority",
          "TBS": {
            "MD5": "53c41bc1164e09e0cd1617a5bf913efd",
            "SHA1": "93c03aac8951d494ecd5696b1c08658541b18727",
            "SHA256": "40bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b",
            "SHA384": "f51d4e75ba638f7314cd59b8d6d45f3b34d35ce6986e9d205cd6f333e8e8d8e9c91f636e6bc84731b6661673f40963d8"
          },
          "ValidFrom": "2006-05-23 17:01:29",
          "ValidTo": "2016-05-23 17:11:29",
          "Version": 3
        },
        {
          "CertificateType": "Leaf (Code Signing)",
          "IsCA": false,
          "IsCertificateAuthority": false,
          "IsCodeSigning": true,
          "SerialNumber": "3bdb1994b98bbb19ab55a42337fa4f5c",
          "Signature": "d4d31733c0a04a890eecbf1af9f227dc09186dcc6625ee8b059ae8e4fbd4e0fd22f86e9d993b3974a60e9fc5905d6322dbaf62759cb40f596c5805b8607ad52a825c4b4da405aa8b8c024d7117e573a36fbb576355d8449afae87238aae1a63a2271d85abae4387066d04a0362ca7ff482752f0f057bdfc36802dc2c1a9aff13d527340edfcfebe04ed920f9996410e23c6afce70d7387dca8fff985b336da6a63ebf48ccfe8b968ae35111dbab3047d929a54321b31869886932912bec609ab7715021211eb409857e25a3f6c4b573a81da6b666541429a87a702a0879153fe04ca809c819598c38cc0a7a32e4489174324828284329ee1b8a97c9609ca7899",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=CN, ST=Beijing, L=Beijing, O=Baidu Online Network Technology (Beijing)Co., Ltd, OU=Digital ID Class 3 , Microsoft Software Validation v2, CN=Baidu Online Network Technology (Beijing)Co., Ltd",
          "TBS": {
            "MD5": "9ea2687f1fc2e86224cb68486714762c",
            "SHA1": "6d36f4a52430aa26965512fc6ba47a6761e041a9",
            "SHA256": "8a741d00a587923919f7fef79b7922ecff7a584ba2551715c5187e399366e66e",
            "SHA384": "d815eaf2f1988000cd6bebf1199c9ad957b044a5adb9966978eb3459f3ee564f441c37d4c03cd2529d10418bed2c90d9"
          },
          "ValidFrom": "2012-04-24 00:00:00",
          "ValidTo": "2015-04-24 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": true,
          "SerialNumber": "5200e5aa2556fc1a86ed96c9d44b33c7",
          "Signature": "5622e634a4c461cb48b901ad56a8640fd98c91c4bbcc0ce5ad7aa0227fdf47384a2d6cd17f711a7cec70a9b1f04fe40f0c53fa155efe749849248581261c911447b04c638cbba134d4c645e80d85267303d0a98c646ddc7192e645056015595139fc58146bfed4a4ed796b080c4172e737220609be23e93f449a1ee9619dccb1905cfc3dd28dac423d6536d4b43d40288f9b10cf2326cc4b20cb901f5d8c4c34ca3cd8e537d66fa520bd34eb26d9ae0de7c59af7a1b42191336f86e858bb257c740e58fe751b633fce317c9b8f1b969ec55376845b9cad91faaced93ba5dc82153c2825363af120d5087111b3d5452968a2c9c3d921a089a052ec793a54891d3",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA",
          "TBS": {
            "MD5": "b30c31a572b0409383ed3fbe17e56e81",
            "SHA1": "4843a82ed3b1f2bfbee9671960e1940c942f688d",
            "SHA256": "03cda47a6e654ed85d932714fc09ce4874600eda29ec6628cfbaeb155cab78c9",
            "SHA384": "bbda8407c4f9fc4e54d772f1c7fb9d30bc97e1f97ecd51c443063d1fa0644e266328781776cd5c44896c457c75f4d7da"
          },
          "ValidFrom": "2010-02-08 00:00:00",
          "ValidTo": "2020-02-07 23:59:59",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA",
          "SerialNumber": "3bdb1994b98bbb19ab55a42337fa4f5c",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    source

    last_updated: 2026-05-04