shiloyalty64.sys

Chongqing Shahai Information Tech Co.,Ltd

It runs as a Windows 64-bit kernel mode device driver named “SHILOYALTY”.
Publisher:
沙海  (signed by Chongqing Shahai Information Tech Co.,Ltd)

Product:
沙海

Description:
SecurityPassDrv

Version:
3, 0, 0, 0

MD5:
16bf0df8a3ce92ccb9cd2d643230c832

SHA-1:
823acd6b362a051d112ad9701365108af52f43b2

SHA-256:
d8c8e26af12c9ce524a04ad0f5fb089737e0ef90d31a0edf769e65bcd96f7423

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 1:52:00 PM UTC  (today)

File size:
459.8 KB (470,800 bytes)

Product version:
3, 0, 0, 0

Copyright:
沙海

Original file name:
SecurityPassDrv.sys

File type:
Driver (Win64 SYS)

Common path:
C:\windows\syswow64\drivers\shiloyalty64.sys

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/26/2014 8:00:00 AM

Valid to:
8/26/2015 7:59:59 AM

Subject:
CN="Chongqing Shahai Information Tech Co.,Ltd", OU=IT, O="Chongqing Shahai Information Tech Co.,Ltd", L=Chongqing, S=Chongqing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7ABA7B20248A50ACD93F3A01195662E1

File PE Metadata
Compilation timestamp:
3/23/2015 10:47:15 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
6144:F+BOhOeqqDL6DJ5PjzDEhy0tby1gzfupAKn7VIW:k0O7qn6DJ1jzDEhE1ofunX

Entry address:
0x668CC

Entry point:
E9, CA, FB, FF, FF, 0F, 83, B5, 2E, 00, 00, 48, C1, FF, 3F, 66, FF, CF, 66, 0F, B6, D9, 48, 89, C3, 66, 0F, BC, CF, 66, C1, DF, 05, 66, C1, F9, 07, 48, 89, C7, FE, C9, B9, 04, 01, 00, 00, F6, C1, 43, E9, 96, 28, 00, 00, 48, 8D, 34, 55, E5, F7, CF, 84, 66, 0F, CE, 48, 8D, 35, EC, 31, 00, 00, E9, 35, 61, 00, 00, 0F, 85, 5C, A4, FF, FF, 66, 89, CE, 48, 8B, 35, 3E, 3D, 00, 00, E9, 85, 03, 00, 00, 48, 89, C3, 80, FC, B9, F9, F5, 48, 89, C7, 66, 0F, BB, E1, B9, 04, 01, 00, 00, F8, F8, F8, 30, C0, F5, F2, AE, E9...
 
[+]

Entropy:
3.8346

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
44.4 KB (45,440 bytes)

Driver
Display name:
SHILOYALTY

Type:
Kernel device driver (KernelDriver)


Scan shiloyalty64.sys - Powered by Reason Core Security