← Back to driver explorer
Driver intelligenceMaliciousVerified
driver_ab811ca5.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Known samples 1
1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
driver_ab811ca5.sysSample 1 · HVCI TRUE
- MD5
a5fae487dc0d0919eae60638eabd1c85- SHA1
903934206ee381baf097edba6217029085601a1f- SHA256
ab811ca59a8a8e92fff3eca9d359a8ed5482e781c97e63dbece046d929d0a79c- Imphash
ce10082e1aa4c1c2bd953b4a7208e56a- Authentihash MD5
780edcaad7c0d3bb257db1c5e47a0e97- Authentihash SHA1
37bf2103543db3312bd8844b7081efa411b03fd1- Authentihash SHA256
7e82d60575309a6bf6145e7d509dac0b2e815a734a492055bf591c8a7ab55865- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Recorded command
sc.exe create driver_bfcbc010.sys binPath=C:\windows\temp\driver_bfcbc010.sys type=kernel && sc.exe start driver_bfcbc010.sysElevate privileges · Privileges: kernel · OS: Windows 10

