8f2d3be4-3e25-490f-82bc-0aca16aee101

PCTcore64.sys :inline

Description

PC Tools PCTcore64.sys is documented by BlackSnufkin BYOVD research and CERT/CC as CVE-2026-8501. The driver creates a PCTCore device interface without restrictive access controls and exposes a process-termination IOCTL reachable by local callers.

  • UUID: 8f2d3be4-3e25-490f-82bc-0aca16aee101
  • Created: 2026-06-16
  • Author: Michael Haag
  • Acknowledgement: BlackSnufkin | @BlackSnufkin

Download

This download link contains the vulnerable driver!

Block PCTcore64.sys across your endpoints

Add this driver to your block policy in minutes with MagicSword, threat-driven application control. Free for up to 100 endpoints.

Start Blocking for Free

Commands

sc.exe create PCTcore64 binPath=C:\windows\temp\PCTcore64.sys type=kernel && sc.exe start PCTcore64
Use CasePrivilegesOperating System
Terminate processes through a vulnerable PC Tools kernel driver IOCTL path.kernelWindows 10, Windows 11

Detections

YARA 🏹

Expand

Exact Match

with header and size limitation

Threat Hunting

without header and size limitation

Renamed

for renamed driver files

Sigma 🛡️

Expand

Names

detects loading using name only

Hashes

detects loading using hashes only

Sysmon 🔎

Expand

Block

on hashes

Alert

on hashes

Resources


  • https://github.com/BlackSnufkin/BYOVD/tree/main/PCTcore64-Killer
  • https://kb.cert.org/vuls/id/158530

  • CVE

  • C
  • V
  • E
  • -
  • 2
  • 0
  • 2
  • 6
  • -
  • 8
  • 5
  • 0
  • 1
  • Known Vulnerable Samples

    PropertyValue
    FilenamePCTcore64.sys
    Creation Timestamp2010-03-28 16:55:18
    MD560f19af0a9a26851ad9bc2d981afbac6
    SHA1d5609dc8c5215ebe197aad74ea1459a38f3612dd
    SHA256c76dd87891e3e30db2aed057e7b04c19ca264f434c21f68a7a2d9b17a97aff39
    Authentihash MD57b5b4b739265c7cb20259ab9275bdb96
    Authentihash SHA117d5646942678e9fbfb8fe2835c4eb7b5b6d26db
    Authentihash SHA256f02f7cd930d656cbae0ab9d3c3eafd3d8333f182505c539f4ef4032c4c92e725
    RichPEHeaderHash MD51ae228e6a26fd9454121538aa0e1cd5a
    RichPEHeaderHash SHA1e25b723d0d36deb40db29b33ee95871c75be5080
    RichPEHeaderHash SHA2561b126bebb862d3f07462fd81a61e8d56afba8940f83cb4e8dbbd95e8c70f0b7c
    CompanyPC Tools
    DescriptionPC Tools KDS Core Driver
    ProductKernel Driver Suite
    OriginalFilenamePCTCore.sys

    Download

    Certificates

    Expand
    Certificate 3825d7faf861af9ef490e726b5d65ad5
    FieldValue
    ToBeSigned (TBS) MD5d6c7684e9aaa508cf268335f83afe040
    ToBeSigned (TBS) SHA118066d20ad92409c567cdfde745279ff71c75226
    ToBeSigned (TBS) SHA256a612fb22ce8be6dab75e47c98508f98496583e79c9c97b936a8caee9ea9f3fff
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services Signer , G2
    ValidFrom2007-06-15 00:00:00
    ValidTo2012-06-14 23:59:59
    Signature50c54bc82480dfe40d24c2de1ab1a102a1a6822d0c831581370a820e2cb05a1761b5d805fe88dbf19191b3561a40a6eb92be3839b07536743a984fe437ba9989ca95421db0b9c7a08d57e0fad5640442354e01d133a217c84daa27c7f2e1864c02384d8378c6fc53e0ebe00687dda4969e5e0c98e2a5bebf8285c360e1dfad28d8c7a54b64dac71b5bbdac3908d53822a1338b2f8a9aebbc07213f44410907b5651c24bc48d34480eba1cfc902b414cf54c716a3805cf9793e5d727d88179e2c43a2ca53ce7d3df62a3ab84f9400a56d0a835df95e53f418b3570f70c3fbf5ad95a00e17dec4168060c90f2b6e8604f1ebf47827d105c5ee345b5eb94932f233
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber3825d7faf861af9ef490e726b5d65ad5
    Version3
    Certificate 47bf1995df8d524643f7db6d480d31a4
    FieldValue
    ToBeSigned (TBS) MD5518d2ea8a21e879c942d504824ac211c
    ToBeSigned (TBS) SHA121ce87d827077e61abddf2beba69fde5432ea031
    ToBeSigned (TBS) SHA2561ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7
    SubjectC=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA
    ValidFrom2003-12-04 00:00:00
    ValidTo2013-12-03 23:59:59
    Signature4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber47bf1995df8d524643f7db6d480d31a4
    Version3
    Certificate 42abdc237d1ba31664ba4e7b05f23652
    FieldValue
    ToBeSigned (TBS) MD58b81840a27c0ef49b44038c87f4806c7
    ToBeSigned (TBS) SHA177a76258b935a7b7dc827a7f8f5bad390e7c5410
    ToBeSigned (TBS) SHA256ac9d2e29b9ccdcbdf30d64690d57d29cc45c0e177fb6a9de11a22516e78c06ef
    SubjectC=AU, ST=Victoria, L=Melbourne, O=PC Tools, OU=Digital ID Class 3 , Microsoft Software Validation v2, OU=Software, CN=PC Tools
    ValidFrom2009-07-10 00:00:00
    ValidTo2012-08-15 23:59:59
    Signature7e144513445f7bab97e8d5edd6f5a6a17e52e9cad0d0d80c1ce4c27b16d0a811f01339b5882702ad64068bf54a85e5862fdbbab059d0b887387a56fc006fcc5dc56534012a160465e8429cdbef4cc8a84f9fcc09ae2db685a7e4d3265bfd1887a0052f6187cfacda9c164d09445bcca2d554bdcb1fc9d9a16e5879ad4d64a0d27773c54543ce6f26db43ff1de47b1bc85bd8e810d5f6fd54f416fc414cdded4e042f7030a38e5493bf82580e58c26758818eac84dcd7c1ca6c7c255e1380e726a29f923fd7f5ad38e4738d3eccd9c32eada6d740ebe0aa6e901dbabe0756fd175b0e9eb86f856300e0d00f1676a17297acf54ec4bbb900efb32fda1bd48159bd
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityFalse
    SerialNumber42abdc237d1ba31664ba4e7b05f23652
    Version3
    Certificate 655226e1b22e18e1590f2985ac22e75c
    FieldValue
    ToBeSigned (TBS) MD5650704c342850095f3288eaf791147d4
    ToBeSigned (TBS) SHA14cdc38c800761463749c3cbd94a12f32e49877bf
    ToBeSigned (TBS) SHA25607b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214
    SubjectC=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA
    ValidFrom2009-05-21 00:00:00
    ValidTo2019-05-20 23:59:59
    Signature8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber655226e1b22e18e1590f2985ac22e75c
    Version3
    Certificate 610c120600000000001b
    FieldValue
    ToBeSigned (TBS) MD553c41bc1164e09e0cd1617a5bf913efd
    ToBeSigned (TBS) SHA193c03aac8951d494ecd5696b1c08658541b18727
    ToBeSigned (TBS) SHA25640bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b
    SubjectC=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
    ValidFrom2006-05-23 17:01:29
    ValidTo2016-05-23 17:11:29
    Signature01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665
    SignatureAlgorithmOID1.2.840.113549.1.1.5
    IsCertificateAuthorityTrue
    SerialNumber610c120600000000001b
    Version3

    Imports

    Expand
    • ntoskrnl.exe
    • FLTMGR.SYS

    Imported Functions

    Expand
    • RtlEqualUnicodeString
    • IoGetDeviceAttachmentBaseRef
    • IoCreateFileSpecifyDeviceObjectHint
    • ZwQueryInformationFile
    • ZwSetInformationFile
    • ZwQueryDirectoryFile
    • KeWaitForSingleObject
    • ZwReadFile
    • ZwWriteFile
    • FsRtlDissectName
    • ZwCreateSection
    • ZwMapViewOfSection
    • ZwUnmapViewOfSection
    • RtlCompareMemory
    • RtlIntegerToUnicodeString
    • KeInitializeEvent
    • KeInitializeSemaphore
    • PsCreateSystemThread
    • RtlInitializeGenericTable
    • KeReleaseSemaphore
    • ExAcquireFastMutex
    • KeSetEvent
    • ExReleaseFastMutex
    • RtlEnumerateGenericTableWithoutSplaying
    • RtlDeleteElementGenericTable
    • RtlInsertElementGenericTable
    • RtlLookupElementGenericTable
    • ExInterlockedAddLargeInteger
    • ExSystemTimeToLocalTime
    • PsGetCurrentThreadId
    • KeSetPriorityThread
    • PsTerminateSystemThread
    • IoReleaseCancelSpinLock
    • KeAcquireSpinLockRaiseToDpc
    • KeReleaseSpinLock
    • RtlDelete
    • FsRtlIsNameInExpression
    • RtlDeleteNoSplay
    • FsRtlDoesNameContainWildCards
    • FsRtlAreNamesEqual
    • RtlCompareUnicodeString
    • IoIs32bitProcess
    • ProbeForRead
    • ZwQueryValueKey
    • ZwSetValueKey
    • ZwEnumerateKey
    • PsLookupProcessByProcessId
    • PsLookupThreadByThreadId
    • ZwQuerySystemInformation
    • RtlInitAnsiString
    • RtlVolumeDeviceToDosName
    • ZwQueryInformationProcess
    • KeStackAttachProcess
    • KeUnstackDetachProcess
    • PsSetCreateProcessNotifyRoutine
    • PsSetCreateThreadNotifyRoutine
    • PsSetLoadImageNotifyRoutine
    • IoIsWdmVersionAvailable
    • IoAllocateWorkItem
    • IoQueueWorkItem
    • ExGetPreviousMode
    • ZwTerminateProcess
    • ObQueryNameString
    • RtlIsNameLegalDOS8Dot3
    • ZwOpenFile
    • IoGetRelatedDeviceObject
    • IoGetDiskDeviceObject
    • ZwOpenSymbolicLinkObject
    • ZwQuerySymbolicLinkObject
    • ZwOpenProcess
    • ZwQueryObject
    • ZwDuplicateObject
    • MmGetSystemRoutineAddress
    • ObOpenObjectByPointer
    • ZwQueryKey
    • ZwCreateKey
    • ExInterlockedPushEntryList
    • ZwDeleteKey
    • ZwDeleteValueKey
    • ZwFlushKey
    • ExInterlockedPopEntryList
    • IoAllocateErrorLogEntry
    • IoWriteErrorLogEntry
    • IoAttachDeviceToDeviceStack
    • IoDetachDevice
    • IoGetAttachedDeviceReference
    • IoBuildDeviceIoControlRequest
    • ExInterlockedInsertHeadList
    • ExInterlockedRemoveHeadList
    • KeQueryTimeIncrement
    • IoAllocateIrp
    • IoFreeIrp
    • IoAllocateMdl
    • MmProbeAndLockPages
    • IoFreeMdl
    • MmUnlockPages
    • KeDelayExecutionThread
    • KeBugCheckEx
    • RtlAppendUnicodeStringToString
    • RtlAppendUnicodeToString
    • IoFileObjectType
    • ObReferenceObjectByHandle
    • FsRtlIsPagingFile
    • ExInitializeResourceLite
    • ExDeleteResourceLite
    • ExAcquireResourceExclusiveLite
    • KeLeaveCriticalRegion
    • ExReleaseResourceLite
    • ExAcquireResourceSharedLite
    • KeEnterCriticalRegion
    • RtlFreeUnicodeString
    • RtlUpcaseUnicodeString
    • ObfDereferenceObject
    • IoCreateStreamFileObject
    • ZwEnumerateValueKey
    • ZwClose
    • ZwOpenKey
    • PoCallDriver
    • PoStartNextPowerIrp
    • IoReleaseRemoveLockAndWaitEx
    • IoReleaseRemoveLockEx
    • IofCallDriver
    • IofCompleteRequest
    • IoAcquireRemoveLockEx
    • RtlGUIDFromString
    • IoGetDeviceProperty
    • IoUnregisterPlugPlayNotification
    • IoDeleteSymbolicLink
    • IoRegisterPlugPlayNotification
    • IoRegisterShutdownNotification
    • IoDeleteDevice
    • IoCreateSymbolicLink
    • IoInitializeRemoveLockEx
    • IoCreateDevice
    • RtlInitUnicodeString
    • ExFreePoolWithTag
    • PsGetCurrentProcessId
    • RtlCopyUnicodeString
    • RtlAnsiStringToUnicodeString
    • ExAllocatePoolWithTag
    • RtlAnsiCharToUnicodeChar
    • PsGetVersion
    • __C_specific_handler
    • FltCloseClientPort
    • FltGetVolumeName
    • FltGetVolumeGuidName
    • FltWriteFile
    • FltFreeCallbackData
    • FltPerformSynchronousIo
    • FltAllocateCallbackData
    • FltSetInformationFile
    • FltGetVolumeFromFileObject
    • FltGetDiskDeviceObject
    • FltEnumerateInstances
    • FltClose
    • FltObjectDereference
    • FltReadFile
    • FltCreateFile
    • FltGetBottomInstance
    • FltIsDirectory
    • FltGetFileNameInformation
    • FltSetStreamHandleContext
    • FltGetStreamHandleContext
    • FltSetStreamContext
    • FltGetStreamContext
    • FltGetTunneledName
    • FltQueryInformationFile
    • FltCancelFileOpen
    • FltGetRequestorProcessId
    • FltGetDeviceObject
    • FltSetInstanceContext
    • FltAllocateContext
    • FltReleaseFileNameInformation
    • FltParseFileNameInformation
    • FltGetDestinationFileNameInformation
    • FltReleaseContext
    • FltGetInstanceContext
    • FltStartFiltering
    • FltCloseCommunicationPort
    • FltFreeSecurityDescriptor
    • FltCreateCommunicationPort
    • FltUnregisterFilter
    • FltBuildDefaultSecurityDescriptor
    • FltRegisterFilter
    • FltSendMessage

    Exported Functions

    Expand

    Sections

    Expand
    • .text
    • .rdata
    • .data
    • .pdata
    • PAGE
    • INIT
    • .rsrc
    • .reloc

    Signature

    Expand
    {
      "Certificates": [
        {
          "CertificateType": "Intermediate",
          "IsCA": false,
          "IsCertificateAuthority": false,
          "IsCodeSigning": false,
          "SerialNumber": "3825d7faf861af9ef490e726b5d65ad5",
          "Signature": "50c54bc82480dfe40d24c2de1ab1a102a1a6822d0c831581370a820e2cb05a1761b5d805fe88dbf19191b3561a40a6eb92be3839b07536743a984fe437ba9989ca95421db0b9c7a08d57e0fad5640442354e01d133a217c84daa27c7f2e1864c02384d8378c6fc53e0ebe00687dda4969e5e0c98e2a5bebf8285c360e1dfad28d8c7a54b64dac71b5bbdac3908d53822a1338b2f8a9aebbc07213f44410907b5651c24bc48d34480eba1cfc902b414cf54c716a3805cf9793e5d727d88179e2c43a2ca53ce7d3df62a3ab84f9400a56d0a835df95e53f418b3570f70c3fbf5ad95a00e17dec4168060c90f2b6e8604f1ebf47827d105c5ee345b5eb94932f233",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services Signer , G2",
          "TBS": {
            "MD5": "d6c7684e9aaa508cf268335f83afe040",
            "SHA1": "18066d20ad92409c567cdfde745279ff71c75226",
            "SHA256": "a612fb22ce8be6dab75e47c98508f98496583e79c9c97b936a8caee9ea9f3fff",
            "SHA384": "35c249d6ad0261a6229b2a727067ac6ba32a5d24b30b9249051f748c7735fbe2ec2ef26a702c50df1790fbe32a65aee7"
          },
          "ValidFrom": "2007-06-15 00:00:00",
          "ValidTo": "2012-06-14 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": false,
          "SerialNumber": "47bf1995df8d524643f7db6d480d31a4",
          "Signature": "4a6bf9ea58c2441c318979992b96bf82ac01d61c4ccdb08a586edf0829a35ec8ca9313e704520def47272f0038b0e4c9934e9ad4226215f73f37214f703180f18b3887b3e8e89700fecf55964e24d2a9274e7aaeb76141f32acee7c9d95eddbb2b853eb59db5d9e157ffbeb4c57ef5cf0c9ef097fe2bd33b521b1b3827f73f4a",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., CN=VeriSign Time Stamping Services CA",
          "TBS": {
            "MD5": "518d2ea8a21e879c942d504824ac211c",
            "SHA1": "21ce87d827077e61abddf2beba69fde5432ea031",
            "SHA256": "1ec3b4f02e03930a470020e0e48d24b84678bb558f46182888d870541f5e25c7",
            "SHA384": "53e346bbde23779a5d116cc9d86fdd71c97b1f1b343439f8a11aa1d3c87af63864bb8488a5aeb2d0c26a6a1e0b15f03f"
          },
          "ValidFrom": "2003-12-04 00:00:00",
          "ValidTo": "2013-12-03 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "Leaf (Code Signing)",
          "IsCA": false,
          "IsCertificateAuthority": false,
          "IsCodeSigning": true,
          "SerialNumber": "42abdc237d1ba31664ba4e7b05f23652",
          "Signature": "7e144513445f7bab97e8d5edd6f5a6a17e52e9cad0d0d80c1ce4c27b16d0a811f01339b5882702ad64068bf54a85e5862fdbbab059d0b887387a56fc006fcc5dc56534012a160465e8429cdbef4cc8a84f9fcc09ae2db685a7e4d3265bfd1887a0052f6187cfacda9c164d09445bcca2d554bdcb1fc9d9a16e5879ad4d64a0d27773c54543ce6f26db43ff1de47b1bc85bd8e810d5f6fd54f416fc414cdded4e042f7030a38e5493bf82580e58c26758818eac84dcd7c1ca6c7c255e1380e726a29f923fd7f5ad38e4738d3eccd9c32eada6d740ebe0aa6e901dbabe0756fd175b0e9eb86f856300e0d00f1676a17297acf54ec4bbb900efb32fda1bd48159bd",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=AU, ST=Victoria, L=Melbourne, O=PC Tools, OU=Digital ID Class 3 , Microsoft Software Validation v2, OU=Software, CN=PC Tools",
          "TBS": {
            "MD5": "8b81840a27c0ef49b44038c87f4806c7",
            "SHA1": "77a76258b935a7b7dc827a7f8f5bad390e7c5410",
            "SHA256": "ac9d2e29b9ccdcbdf30d64690d57d29cc45c0e177fb6a9de11a22516e78c06ef",
            "SHA384": "0658ecafc765266284c737f1b6db3ff5c394d0412ab57d8d6f661058ebbdc7e398dcbd2ce6b48d5562809db231f30269"
          },
          "ValidFrom": "2009-07-10 00:00:00",
          "ValidTo": "2012-08-15 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": true,
          "SerialNumber": "655226e1b22e18e1590f2985ac22e75c",
          "Signature": "8b03c0dd94d841a26169b015a878c730c6903c7e42f724b6e4837317047f04109ca1e2fa812febc0ca44e772e050b6551020836e9692e49a516ab43731dca52deb8c00c71d4fe74d32ba85f84ebefa675565f06abe7aca64381a101078457631f3867a030f60c2b35d9df68b6676821b59e183e5bd49a53856e5de41770e580f",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "TBS": {
            "MD5": "650704c342850095f3288eaf791147d4",
            "SHA1": "4cdc38c800761463749c3cbd94a12f32e49877bf",
            "SHA256": "07b8f662558ec85b71b43a79c6e94698144f4ced2308af21e7ba1e5d461da214",
            "SHA384": "2a271d052213438467d09d60eaa4010c8642fff3eb0070e0cf9969428713c8fdc066b90996d594dd3136f5bd0af5a22a"
          },
          "ValidFrom": "2009-05-21 00:00:00",
          "ValidTo": "2019-05-20 23:59:59",
          "Version": 3
        },
        {
          "CertificateType": "CA",
          "IsCA": true,
          "IsCertificateAuthority": true,
          "IsCodeSigning": false,
          "SerialNumber": "610c120600000000001b",
          "Signature": "01e446b33b457f7513877e5f43de468ecb8abdb64741bccccc7491d8ce395195a4a6b547c0efd2da7b8f5711f4328c7ccd3fee42da04214af7c843884a6f5cca14fc4bd19f4cbdd4556ecc02be0da6888f8609baa425bde8b0f0fa8b714e67b0cb82a8d78e55f737ebf03e88efe4e08afd1c6e2e61414875b4b02c1d28d8490fd715f02473253ccc880cde284c6554fe5eae8cea19ad2c51b29b3a47f53c80350117e24987d6544afb4bab07bcbf7d79cfbf35005cbb9ecffc82891b39a05197b6dec0b307ff449644c0342a195cabeef03bec294eb513c537857e75d5b4d60d066eb5d26c237167eaf1718eaf4e74aa0cf9ecbf4c58fa5e909b6d39cb86883f8b1ca81632d5fe6db9f1f8b3ead791f6364778c0272a15c768d6f4c5fc4f4ec8673f102d409ff11ec96148e7a703fc31730cf04688fe56da492995ef09daa3e5beef60ecd954a0599c28bd54ef66157f874c84dba60e95672e517b3439b641c28c846826dc240209e7818e0a972defeea7b998a60f818dc710b5e1ed982f486f53854964789bec5dac970b5526c3efba8dc8d1a52f5a7f936b611a339b18b8a26210de24ea76e12f43ebecdd7c12342489da2855aee5754e312b6763b6a8d7ab730a03cec5ea593fc7eb2a45aea8625b2f009939abb45f73c308ec80118f470e8f2a1343e191066255bbffba3da9a93d260faeca7d628b155589d694344dd665",
          "SignatureAlgorithmOID": "1.2.840.113549.1.1.5",
          "Subject": "C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority",
          "TBS": {
            "MD5": "53c41bc1164e09e0cd1617a5bf913efd",
            "SHA1": "93c03aac8951d494ecd5696b1c08658541b18727",
            "SHA256": "40bddadac24dc61ca4fb5cab2a2bc5d876bc36808311039a7a3e1a4066f7489b",
            "SHA384": "f51d4e75ba638f7314cd59b8d6d45f3b34d35ce6986e9d205cd6f333e8e8d8e9c91f636e6bc84731b6661673f40963d8"
          },
          "ValidFrom": "2006-05-23 17:01:29",
          "ValidTo": "2016-05-23 17:11:29",
          "Version": 3
        }
      ],
      "CertificatesInfo": "",
      "Signer": [
        {
          "Issuer": "C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https://www.verisign.com/rpa (c)09, CN=VeriSign Class 3 Code Signing 2009,2 CA",
          "SerialNumber": "42abdc237d1ba31664ba4e7b05f23652",
          "Version": 1
        }
      ],
      "SignerInfo": ""
    }
    

    source

    last_updated: 2026-06-16