← Back to driver explorer
Driver intelligenceMaliciousVerified

f.sys

Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

UUID / 17a1ad58-ecf3-4dea-b1ca-336880d15256ADDED / 2024-09-10AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

f.sysSample 1 · HVCI TRUE
MD5
7190f99ecf8bc3f4c496443ff1f9ee83
SHA1
6ec298a9aff2708c3e28a8510e3735e841b14e06
SHA256
54942b92790dc0b84c56d4a00f3ac419b0a506344ca7e9f1fb666a86dbc4117f
Imphash
9050905feaae8f52f58d56b3fdb862de
Authentihash MD5
1f679ab07e74f82c9f2f606109d55052
Authentihash SHA1
2801aa69e63680b9691e6c5064eab8c957069144
Authentihash SHA256
25819a8c8f2ebceef661d751a56a024a5584f8283d9600273e52d18923c9f455
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create f.sys binPath=C:\windows\temp\f.sys type=kernel && sc.exe start f.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references