gftkyj64.sys
SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses. Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes. We first reported our discovery to Microsoft’s Security Response Center (MSRC) in October 2022 and received an official case number (75361). Today, MSRC released an associated advisory under ADV220005. This research is being released alongside Mandiant, a SentinelOne technology and incident response partner.
Known samples 1
1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
gftkyj64.sysSample 1 · HVCI TRUE
- MD5
04a88f5974caa621cee18f34300fc08a- SHA1
a804ebec7e341b4d98d9e94f6e4860a55ea1638d- SHA256
9b1b15a3aacb0e786a608726c3abfc94968915cedcbd239ddf903c4a54bfcf0c- Imphash
832219eb71b8bdb771f1d29d27b0acf4- Authentihash MD5
4252d83e18ad41f0cea7ac168218d95b- Authentihash SHA1
cf9cb05c9b725efca68c4b7d6f53c8e233217ac4- Authentihash SHA256
cd66e893300e7e59a749fe4e1b1706f8ccb5ae140254def9f5a614648e2da36f- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Recorded command
sc.exe create gftkyj64.sys binPath=C:\windows\temp\gftkyj64.sys type=kernel && sc.exe start gftkyj64.sysElevate privileges · Privileges: kernel · OS: Windows 10

