← Back to driver explorer
Driver intelligenceVulnerableVerified
wsftprm.sys
Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 6.1, indicating a antivirus killer impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.
Known samples 2
1 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
wsftprm.sysSample 1 · HVCI TRUE
- MD5
2f4b5a0d98bc4e5616f2dd04337ae674- SHA1
f8a3f28ecbd0b08ecab73ef571f16c3d0bd5e009- SHA256
ff5dbdcf6d7ae5d97b6f3ef412df0b977ba4a844c45b30ca78c0eeb2653d69a8- Imphash
70d95d244db4c9ba22a801a149570551- Authentihash MD5
fef5c6b4bf229133ff0ba9b3187db3fa- Authentihash SHA1
2e453dc7c70d25a59b09006d9b28360a0aca1720- Authentihash SHA256
a3b12d9f35f9acd46d7e21627ad3e29149d203e211d665a3e03103f9cb7e4b86- Machine
- AMD64
- Version
- 2.0.0.0
- Publisher
- Topaz OFD
wsftprm.sysSample 2 · HVCI unknown
- MD5
521f17a8b04bffb3ad5130fb24a8c372- SHA1
ddf6112b8124ecbaf05f6b315c28302c3ee6ffd2- SHA256
252a8bb2eb9c96c5e6cc7cab822e2ed0d508032f9350351221781684e86c03ab- Imphash
70d95d244db4c9ba22a801a149570551- Machine
- AMD64
- Version
- 2.0.0.0
- Publisher
- TPZ SOLUCOES DIGITAIS LTDA
Recorded command
sc.exe create wsftprm binPath=C:\windows\temp\wsftprm.sys type=kernel && sc.exe start wsftprmElevate privileges · Privileges: kernel · OS: Windows 10
Research & references
- https://northwave-cybersecurity.com/vulnerability-notice-topaz-antifraud
- https://github.com/xM0kht4r/AV-EDR-Killer
- https://github.com/wesmar/kvcKiller
- https://github.com/BlackSnufkin/BYOVD/tree/main/Wsftprm-Killer
- https://www.security.com/threat-intelligence/dragonforce-msteams-backdoor
- https://www.catonetworks.com/blog/cato-ctrl-silverfox-evolves/
Acknowledgement: Northwave Cyber Security

