← Back to driver explorer
Driver intelligenceMaliciousVerified
f.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Known samples 1
1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
f.sysSample 1 · HVCI TRUE
- MD5
7190f99ecf8bc3f4c496443ff1f9ee83- SHA1
6ec298a9aff2708c3e28a8510e3735e841b14e06- SHA256
54942b92790dc0b84c56d4a00f3ac419b0a506344ca7e9f1fb666a86dbc4117f- Imphash
9050905feaae8f52f58d56b3fdb862de- Authentihash MD5
1f679ab07e74f82c9f2f606109d55052- Authentihash SHA1
2801aa69e63680b9691e6c5064eab8c957069144- Authentihash SHA256
25819a8c8f2ebceef661d751a56a024a5584f8283d9600273e52d18923c9f455- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Recorded command
sc.exe create f.sys binPath=C:\windows\temp\f.sys type=kernel && sc.exe start f.sysElevate privileges · Privileges: kernel · OS: Windows 10

