← Back to driver explorer
Driver intelligenceMaliciousUnverified
ollama.sys
Elastic Security Labs reports that RONINGLOADER writes ollama.sys to a temporary directory, creates a temporary service to load it, and sends target process IDs to the driver to terminate antivirus processes. The service is deleted after the termination request. The reported October 2025 sample uses standard signing procedures and does not contain the HookSignTool artifacts identified in earlier related samples.
The project has not confirmed this driver's sample hashes.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
ollama.sysSample 1 · HVCI unknown
- MD5
96dcdb8bb7934abdb6cd87c33d17be87- SHA1
5c0100a6b2fcc5e74649a356d322c2568a4e15ed- SHA256
2515b546125d20013237aeadec5873e6438ada611347035358059a77a32c54f5- Imphash
b28b9b353aa8985c6c7b7db3091e7346- Authentihash SHA256
663cfcc91d31898f6274cf30b70f2fd54edee8445e4c10512405a416833ce88f- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Research & references
Acknowledgement: Liran Ravich, Cribl

