sysdiag.sys
Huorong sysdiag.sys 6.0.0.3 contains an IOCTL 0x2200b8 path that resolves a supplied process identifier and calls ZwTerminateProcess. The reported Bring Your Own Trusted Caller (BYOTC) chain uses administrator-level control of a genuine Huorong client to reach the product-restricted interface; trusting the client image does not establish the integrity of code executing inside it. Static analysis of this exact sample confirms the dispatcher and termination helper, while the client-classification bypass and ordinary-child termination result are externally reported. The driver must be loaded and the product-specific caller conditions met. This record does not establish access from a standard user, termination of protected processes, or applicability to other versions.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
sysdiag.sysSample 1 · HVCI unknown
- MD5
1b2497558f05c560e25b09c45d033245- SHA1
6e3bf05225d003e401e81edbe38afc7aa7156cb5- SHA256
5aeae04dd27ff148cb8c0f646e34b0404a963b8ec6fc930e75ae5b09d5ec3291- Imphash
54f82d5e9dac107659ee1b9ed28e8856- Authentihash MD5
74714572f39906324544a315a7e9f6fb- Authentihash SHA1
422539d16cdcadfbb9e76d1b70279bb6d69280ad- Authentihash SHA256
33d8462183bc0c8bb5a2a8530ce1842fd60f1610d00f9616444ec3946f121663- Machine
- AMD64
- Version
- 6.0.0.3
- Publisher
- Beijing Huorong Network Technology Co., Ltd.
Research & references
Acknowledgement: Xusheng Li @xusheng6

