← Back to driver explorer
Driver intelligenceMaliciousVerified
malicious.sys
This demo is a presentation at the CYBERSEC 2023 in Taiwan. The presentation showcases the abuse of RTCore64.sys (CVE-2019-16098) from MSI and the nullification of the DSE flag to load a malicious unsigned driver. The presentation also demonstrates an attack on 360 Total Security by nulling out its ObRegisterCallbacks and notify callbacks, enabling the execution of any malicious behavior on the processes of 360 Total Security.
Known samples 1
1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
malicious.sysSample 1 · HVCI TRUE
- MD5
0b311af53d2f4f77d30f1aed709db257- SHA1
43501832ce50ccaba2706be852813d51de5a900f- SHA256
23e89fd30a1c7db37f3ea81b779ce9acf8a4294397cbb54cff350d54afcfd931- Imphash
2de3451f3e7b02970582bb8f9fd8c73a- Authentihash MD5
b877e53d3bc3df3d62dc7b26c9b9b006- Authentihash SHA1
8fb8d175848525061418e80fe95ced27cc0ba0a4- Authentihash SHA256
4cfd9cb41a51b1e1fdfc9a6855323bf11a0baf18e5d8f0ee7480a8cb5be7c8ac- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Recorded command
sc.exe create malicious.sys binPath=C:\windows\temp\malicious.sys type=kernel && sc.exe start malicious.sysElevate privileges · Privileges: kernel · OS: Windows 10

