Windows
Analysis Report
OpenHardwareMonitorLib.sys
Overview
General Information
Sample name: | OpenHardwareMonitorLib.sys |
Analysis ID: | 1629927 |
MD5: | 0c0195c48b6b8582fa6f6373032118da |
SHA1: | d25340ae8e92a6d29f599fef426a2bc1b5217299 |
SHA256: | 11bd2c9f9e2397c9a16e0990e4ed2cf0679498fe0fd418a3dfdac60b5c160ee5 |
Errors
|
Detection
Score: | 0 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | Static PE information: |
Source: | Binary string: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Binary or memory string: |
Source: | Binary string: |
Source: | Classification label: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs | |||
4% | Virustotal | Browse |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1629927 |
Start date and time: | 2025-03-05 10:05:24 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 1m 28s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 0 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | OpenHardwareMonitorLib.sys |
Detection: | UNKNOWN |
Classification: | unknown0.winSYS@0/0@0/0 |
Cookbook Comments: |
|
- No process behavior to analyse
as no analysis process or sam ple was found - Corrupt sample or wrongly sele
cted analyzer. Details: unsucc essful
File type: | |
Entropy (8bit): | 6.2660301556221185 |
TrID: |
|
File name: | OpenHardwareMonitorLib.sys |
File size: | 14'544 bytes |
MD5: | 0c0195c48b6b8582fa6f6373032118da |
SHA1: | d25340ae8e92a6d29f599fef426a2bc1b5217299 |
SHA256: | 11bd2c9f9e2397c9a16e0990e4ed2cf0679498fe0fd418a3dfdac60b5c160ee5 |
SHA512: | ab28e99659f219fec553155a0810de90f0c5b07dc9b66bda86d7686499fb0ec5fddeb7cd7a3c5b77dccb5e865f2715c2d81f4d40df4431c92ac7860c7e01720d |
SSDEEP: | 192:nqjKhp+GQvzj3i+5T9oGYJh1wAoxhSF6OOoe068jSJUbueq1H2PIP0:qjKL+v/y+5TWGYOf2OJ06dUb+pQ |
TLSH: | 096218874B7E1906FB969F7592E9C7936D34F6C0CFA825CF421299982C413E0AF2861C |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......5:n.q[..q[..q[..q[..}[..V.{.t[..V.}.p[..V.m.r[..V.q.p[..V.|.p[..V.x.p[..Richq[..................PE..d....&.H.........."........ |
Icon Hash: | 7ae282899bbab082 |
Entrypoint: | 0x15008 |
Entrypoint Section: | INIT |
Digitally signed: | true |
Imagebase: | 0x10000 |
Subsystem: | native |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | |
Time Stamp: | 0x488B26C1 [Sat Jul 26 13:29:37 2008 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | d41fa95d4642dc981f10de36f4dc8cd7 |
Signature Valid: | true |
Signature Issuer: | CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE |
Signature Validation Error: | The operation completed successfully |
Error Number: | 0 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | 61EADF0DF84EEDC335550AE8944B77C4 |
Thumbprint SHA-1: | CDA98AC4019456095593902E4B4A87AC283ED54A |
Thumbprint SHA-256: | 2AD31BFCB4B28F2051767A3812DA4913336A95CF614A9AF79DB439A278EA8F50 |
Serial: | 01000000000115372421A8 |
Instruction |
---|
dec eax |
mov eax, dword ptr [FFFFE0F1h] |
dec ecx |
mov ecx, 2DDFA232h |
cdq |
sub eax, dword ptr [eax] |
add byte ptr [eax-7Bh], cl |
sal byte ptr [ebp+eax+49h], 0000003Bh |
sal dword ptr [ebp+2Fh], 4Ch |
lea eax, dword ptr [FFFFE0D6h] |
dec eax |
mov eax, 00000320h |
xor bh, FFFFFFFFh |
dec dword ptr [eax-75h] |
add byte ptr [ecx+33h], cl |
ror byte ptr [ecx-48h], FFFFFFFFh |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x5064 | 0x3c | INIT |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x6000 | 0x3c0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x4000 | 0x60 | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x1a00 | 0x1ed0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x2070 | 0x1c | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x70 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x6c6 | 0x800 | 1c3d5bb2285dafcf3b7746bf717c1a51 | False | 0.55810546875 | data | 5.391022592524746 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_NOT_PAGED, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x2000 | 0x17c | 0x200 | 08362d1269d5a5ef4e7560cab993590d | False | 0.4921875 | data | 3.2845065466422056 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_NOT_PAGED, IMAGE_SCN_MEM_READ |
.data | 0x3000 | 0x114 | 0x200 | 043c46095689123e1f5be96c109c2f46 | False | 0.072265625 | data | 0.30140680731160896 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_NOT_PAGED, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0x4000 | 0x60 | 0x200 | 077af14197899077aa36d2c72ba1773f | False | 0.1640625 | data | 0.8576227162916705 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_NOT_PAGED, IMAGE_SCN_MEM_READ |
INIT | 0x5000 | 0x222 | 0x400 | ba375d2de342e7d7a93487a35ea5d36d | False | 0.3583984375 | data | 3.0572080503988466 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x6000 | 0x3c0 | 0x400 | 5459c1fdb222b651d36692c4ca5df895 | False | 0.421875 | data | 3.1267280965534163 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x6060 | 0x35c | data | English | United States | 0.4604651162790698 |
DLL | Import |
---|---|
ntoskrnl.exe | IoDeleteSymbolicLink, RtlInitUnicodeString, IoDeleteDevice, IoCreateDevice, MmMapIoSpace, KeBugCheckEx, IoCreateSymbolicLink, MmUnmapIoSpace, IofCompleteRequest, __C_specific_handler |
HAL.dll | HalSetBusDataByOffset, HalGetBusDataByOffset |
Description | Data |
---|---|
Comments | The modified BSD license |
CompanyName | OpenLibSys.org |
FileDescription | WinRing0 |
FileVersion | 1.2.0.5 |
InternalName | WinRing0.sys |
LegalCopyright | Copyright (C) 2007-2008 OpenLibSys.org. All rights reserved. |
OriginalFilename | WinRing0.sys |
ProductName | WinRing0 |
ProductVersion | 1.2.0.5 |
Translation | 0x0411 0x04b0 |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |