← Back to driver explorer
Driver intelligenceMaliciousVerified

4748696211bd56c2d93c21cab91e82a5.sys

Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.

UUID / 2d6c1da6-17e2-4385-ad93-1430f83bde83ADDED / 2023-07-31AUTHOR / Alice Climent-Pommeret

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

4748696211bd56c2d93c21cab91e82a5.sysSample 1 · HVCI TRUE
MD5
4748696211bd56c2d93c21cab91e82a5
SHA1
d4cf9296271a9c5c40b0fa34f69b6125c2d14457
SHA256
888491196bd8ff528b773a3e453eae49063ad31fb4ca0f9f2e433f8d35445440
Imphash
be0dd8b8e045356d600ee55a64d9d197
Authentihash MD5
529310cd6840d1f3288e33acb9dd5096
Authentihash SHA1
670f181a172ae68a675cf4c0ce52c0b6be0196e9
Authentihash SHA256
e6a53d4cf39b4b0b5069359d0a3b32eb1aa7b56c427487c9f838eb279c6a90d1
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create 4748696211bd56c2d93c21cab91e82a5.sys binPath=C:\windows\temp\4748696211bd56c2d93c21cab91e82a5.sys type=kernel && sc.exe start 4748696211bd56c2d93c21cab91e82a5.sys

· Privileges: kernel · OS: Windows 10

Research & references