← Back to driver explorer
Driver intelligenceMaliciousVerified

gftkyj64.sys

SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses. Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes. We first reported our discovery to Microsoft’s Security Response Center (MSRC) in October 2022 and received an official case number (75361). Today, MSRC released an associated advisory under ADV220005. This research is being released alongside Mandiant, a SentinelOne technology and incident response partner.

UUID / 0fc0563c-de9f-41d8-806a-748e04d57365ADDED / 2023-03-04AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

gftkyj64.sysSample 1 · HVCI TRUE
MD5
04a88f5974caa621cee18f34300fc08a
SHA1
a804ebec7e341b4d98d9e94f6e4860a55ea1638d
SHA256
9b1b15a3aacb0e786a608726c3abfc94968915cedcbd239ddf903c4a54bfcf0c
Imphash
832219eb71b8bdb771f1d29d27b0acf4
Authentihash MD5
4252d83e18ad41f0cea7ac168218d95b
Authentihash SHA1
cf9cb05c9b725efca68c4b7d6f53c8e233217ac4
Authentihash SHA256
cd66e893300e7e59a749fe4e1b1706f8ccb5ae140254def9f5a614648e2da36f
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create gftkyj64.sys binPath=C:\windows\temp\gftkyj64.sys type=kernel && sc.exe start gftkyj64.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references