← Back to driver explorer
Driver intelligenceVulnerableVerified
HwOs2Ec10x64.sys
Huawei HwOs2Ec 1.0.0.1 exposes kernel process termination to administrative callers. In the tracked HwOs2Ec.sys build, IOCTL 0x22400C accepts a four-byte PID, rejects only PID 0 and PID 4, opens the target with full process access, and calls ZwTerminateProcess. Proofpoint observed this exact signed driver deployed by Cruciferra as an alternative BYOVD helper for tampering with endpoint security tools.
Known samples 2
1 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
HwOs2Ec10x64.sysSample 1 · HVCI TRUE
- MD5
37086ae5244442ba552803984a11d6cb- SHA1
dc0e97adb756c0f30b41840a59b85218cbdd198f- SHA256
bb1135b51acca8348d285dc5461d10e8f57260e7d0c8cc4a092734d53fc40cbc- Imphash
071356ee9d8c7f91cbe8fa3c448286a2- Authentihash MD5
20be6af18d3b97968b2a8d5a9513caaa- Authentihash SHA1
b6a4ef3babbd79479723b8586ea0e8c7a33d1661- Authentihash SHA256
ab494aba56e9ea7b6055ac437f6b678e7239b0fda54bf28019480565a098a6e3- Machine
- AMD64
- Version
- 1.0.0.1
- Publisher
- Huawei
HwOs2Ec.sysSample 2 · HVCI unknown
- MD5
63bfd6567f4c704e8ed6530f5cdd704e- SHA1
080fdb73a6bbc99625c2190730257d1e54723952- SHA256
c4e93449453cf67c5d5605bb8f425207a738a242fdb432d720acc32faa74926c- Imphash
dcf524d72961e33f0c6462f869bb6a4a- Authentihash MD5
620301316b071f339f8ffe7ee4d24990- Authentihash SHA1
846c4f2abdbef8492f4478505b205375b0c88159- Authentihash SHA256
30de6a51d0a56e8d2b3d37393252eaa16728b6c4747f57153e6b4ca0b6022f56- Machine
- AMD64
- Version
- 1.0.0.1
- Publisher
- Huawei Device Co., Ltd.
Recorded command
sc.exe create HwOs2Ec10x64.sys binPath=C:\windows\temp\HwOs2Ec10x64.sys type=kernel && sc.exe start HwOs2Ec10x64.sysTerminate protected security processes · Privileges: Administrator · OS: Windows 10
Research & references
Acknowledgement: fluffycats31 @fluffycats31

