← Back to driver explorer
Driver intelligenceVulnerableVerified

sysdiag.sys

Huorong sysdiag.sys 6.0.0.3 contains an IOCTL 0x2200b8 path that resolves a supplied process identifier and calls ZwTerminateProcess. The reported Bring Your Own Trusted Caller (BYOTC) chain uses administrator-level control of a genuine Huorong client to reach the product-restricted interface; trusting the client image does not establish the integrity of code executing inside it. Static analysis of this exact sample confirms the dispatcher and termination helper, while the client-classification bypass and ordinary-child termination result are externally reported. The driver must be loaded and the product-specific caller conditions met. This record does not establish access from a standard user, termination of protected processes, or applicability to other versions.

UUID / 11d2230e-d9a4-5841-a508-ca8ffa827e56ADDED / 2026-09-19AUTHOR / Xusheng Li

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

sysdiag.sysSample 1 · HVCI unknown
MD5
1b2497558f05c560e25b09c45d033245
SHA1
6e3bf05225d003e401e81edbe38afc7aa7156cb5
SHA256
5aeae04dd27ff148cb8c0f646e34b0404a963b8ec6fc930e75ae5b09d5ec3291
Imphash
54f82d5e9dac107659ee1b9ed28e8856
Authentihash MD5
74714572f39906324544a315a7e9f6fb
Authentihash SHA1
422539d16cdcadfbb9e76d1b70279bb6d69280ad
Authentihash SHA256
33d8462183bc0c8bb5a2a8530ce1842fd60f1610d00f9616444ec3946f121663
Machine
AMD64
Version
6.0.0.3
Publisher
Beijing Huorong Network Technology Co., Ltd.

Research & references

Acknowledgement: Xusheng Li @xusheng6