← Back to driver explorer
Driver intelligenceMaliciousVerified

driver_ab811ca5.sys

Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

UUID / 09d2e61d-e041-4ec8-ab7b-385848456a36ADDED / 2024-09-10AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

driver_ab811ca5.sysSample 1 · HVCI TRUE
MD5
a5fae487dc0d0919eae60638eabd1c85
SHA1
903934206ee381baf097edba6217029085601a1f
SHA256
ab811ca59a8a8e92fff3eca9d359a8ed5482e781c97e63dbece046d929d0a79c
Imphash
ce10082e1aa4c1c2bd953b4a7208e56a
Authentihash MD5
780edcaad7c0d3bb257db1c5e47a0e97
Authentihash SHA1
37bf2103543db3312bd8844b7081efa411b03fd1
Authentihash SHA256
7e82d60575309a6bf6145e7d509dac0b2e815a734a492055bf591c8a7ab55865
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create driver_bfcbc010.sys binPath=C:\windows\temp\driver_bfcbc010.sys type=kernel && sc.exe start driver_bfcbc010.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references