← Back to driver explorer
Driver intelligenceMaliciousUnverified

ollama.sys

Elastic Security Labs reports that RONINGLOADER writes ollama.sys to a temporary directory, creates a temporary service to load it, and sends target process IDs to the driver to terminate antivirus processes. The service is deleted after the termination request. The reported October 2025 sample uses standard signing procedures and does not contain the HookSignTool artifacts identified in earlier related samples.

UUID / 4364d33d-c0ef-4317-835e-b6705b94f756ADDED / 2026-10-01AUTHOR / Liran Ravich, Cribl

The project has not confirmed this driver's sample hashes.

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

ollama.sysSample 1 · HVCI unknown
MD5
96dcdb8bb7934abdb6cd87c33d17be87
SHA1
5c0100a6b2fcc5e74649a356d322c2568a4e15ed
SHA256
2515b546125d20013237aeadec5873e6438ada611347035358059a77a32c54f5
Imphash
b28b9b353aa8985c6c7b7db3091e7346
Authentihash SHA256
663cfcc91d31898f6274cf30b70f2fd54edee8445e4c10512405a416833ce88f
Machine
AMD64
Version
Not recorded
Publisher
Not recorded
View on VirusTotal

Research & references

Acknowledgement: Liran Ravich, Cribl