← Back to driver explorer
Driver intelligenceMaliciousVerified

malicious.sys

This demo is a presentation at the CYBERSEC 2023 in Taiwan. The presentation showcases the abuse of RTCore64.sys (CVE-2019-16098) from MSI and the nullification of the DSE flag to load a malicious unsigned driver. The presentation also demonstrates an attack on 360 Total Security by nulling out its ObRegisterCallbacks and notify callbacks, enabling the execution of any malicious behavior on the processes of 360 Total Security.

UUID / 3e5c0fc4-bfe8-4af2-9613-4f56b0e3c2c8ADDED / 2023-06-05AUTHOR / Guus Verbeek

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

malicious.sysSample 1 · HVCI TRUE
MD5
0b311af53d2f4f77d30f1aed709db257
SHA1
43501832ce50ccaba2706be852813d51de5a900f
SHA256
23e89fd30a1c7db37f3ea81b779ce9acf8a4294397cbb54cff350d54afcfd931
Imphash
2de3451f3e7b02970582bb8f9fd8c73a
Authentihash MD5
b877e53d3bc3df3d62dc7b26c9b9b006
Authentihash SHA1
8fb8d175848525061418e80fe95ced27cc0ba0a4
Authentihash SHA256
4cfd9cb41a51b1e1fdfc9a6855323bf11a0baf18e5d8f0ee7480a8cb5be7c8ac
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create malicious.sys binPath=C:\windows\temp\malicious.sys type=kernel && sc.exe start malicious.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references