← Back to driver explorer
Driver intelligenceMaliciousVerified

driver_668c5bea.sys

Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

UUID / 04eefdf4-448d-45bb-87fc-93f263fc77f4ADDED / 2024-09-10AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

driver_668c5bea.sysSample 1 · HVCI TRUE
MD5
5983eaf01499c65f35302cd962b849f5
SHA1
06b733b2b02753089d743793232bd326204b8919
SHA256
668c5bead3c7fcd919afd742ede7e5fe07972dc4cf730ff37deabdd22d88de4a
Imphash
0a36076c1d71bc5362d962fbe0089ccb
Authentihash MD5
1651be97f95e7572cfdd3024800b7f1d
Authentihash SHA1
fd936a868fc6732c8e67e92503380cd44ec5ec28
Authentihash SHA256
f43b0b9a1d1445ba66e8370397cb22142439fa4062b7b05e30f9b26a370d767c
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create driver_fdd16a94.sys binPath=C:\windows\temp\driver_fdd16a94.sys type=kernel && sc.exe start driver_fdd16a94.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references