← Back to driver explorer
Driver intelligenceVulnerableVerified

HwOs2Ec10x64.sys

Huawei HwOs2Ec 1.0.0.1 exposes kernel process termination to administrative callers. In the tracked HwOs2Ec.sys build, IOCTL 0x22400C accepts a four-byte PID, rejects only PID 0 and PID 4, opens the target with full process access, and calls ZwTerminateProcess. Proofpoint observed this exact signed driver deployed by Cruciferra as an alternative BYOVD helper for tampering with endpoint security tools.

UUID / 3ab0d182-6365-47a7-89f4-34121e889503ADDED / 2023-01-09AUTHOR / Michael Haag

Known samples 2

1 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

HwOs2Ec10x64.sysSample 1 · HVCI TRUE
MD5
37086ae5244442ba552803984a11d6cb
SHA1
dc0e97adb756c0f30b41840a59b85218cbdd198f
SHA256
bb1135b51acca8348d285dc5461d10e8f57260e7d0c8cc4a092734d53fc40cbc
Imphash
071356ee9d8c7f91cbe8fa3c448286a2
Authentihash MD5
20be6af18d3b97968b2a8d5a9513caaa
Authentihash SHA1
b6a4ef3babbd79479723b8586ea0e8c7a33d1661
Authentihash SHA256
ab494aba56e9ea7b6055ac437f6b678e7239b0fda54bf28019480565a098a6e3
Machine
AMD64
Version
1.0.0.1
Publisher
Huawei
HwOs2Ec.sysSample 2 · HVCI unknown
MD5
63bfd6567f4c704e8ed6530f5cdd704e
SHA1
080fdb73a6bbc99625c2190730257d1e54723952
SHA256
c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c
Imphash
dcf524d72961e33f0c6462f869bb6a4a
Authentihash MD5
620301316b071f339f8ffe7ee4d24990
Authentihash SHA1
846c4f2abdbef8492f4478505b205375b0c88159
Authentihash SHA256
30de6a51d0a56e8d2b3d37393252eaa16728b6c4747f57153e6b4ca0b6022f56
Machine
AMD64
Version
1.0.0.1
Publisher
Huawei Device Co., Ltd.

Recorded command

sc.exe create HwOs2Ec10x64.sys binPath=C:\windows\temp\HwOs2Ec10x64.sys     type=kernel && sc.exe start HwOs2Ec10x64.sys

Terminate protected security processes · Privileges: Administrator · OS: Windows 10

Research & references

Acknowledgement: fluffycats31 @fluffycats31