← Back to driver explorer
Driver intelligenceMaliciousVerified

a236e7d654cd932b7d11cb604629a2d0.sys

Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.

UUID / 2866bd72-a4b1-4764-a838-9ed0790c2631ADDED / 2023-07-31AUTHOR / Alice Climent-Pommeret

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

a236e7d654cd932b7d11cb604629a2d0.sysSample 1 · HVCI TRUE
MD5
a236e7d654cd932b7d11cb604629a2d0
SHA1
bf2f8ada4e80aed4710993cedf4c5d32c95cd509
SHA256
497a836693be1b330993e2be64f6c71bf290c127faca1c056abd0dc374654830
Imphash
be0dd8b8e045356d600ee55a64d9d197
Authentihash MD5
bfb9d2676665a9791c81ebfd08054d8d
Authentihash SHA1
85c2a04f6c165640758466eb5f73a5070bc127f2
Authentihash SHA256
d9d4e7d594b4b318ac78baa79f119e4c85493eec1c1f939ae10b1633346c6e9e
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create a236e7d654cd932b7d11cb604629a2d0.sys binPath=C:\windows\temp\a236e7d654cd932b7d11cb604629a2d0.sys type=kernel && sc.exe start a236e7d654cd932b7d11cb604629a2d0.sys

· Privileges: kernel · OS: Windows 10

Research & references