47d4b71f-eebd-4775-9e7c-b031135e8f1b
LECOMAx64.sys 
Description
LECOMAx64.sys is a signed LECO LECOMA device driver referenced by public PPLShade supported-driver research.
- UUID: 47d4b71f-eebd-4775-9e7c-b031135e8f1b
- Created: 2026-06-16
- Author: Michael Haag
- Acknowledgement: Arnim Rupp | ruppde
This download link contains the vulnerable driver!
Commands
sc.exe create LECOMAx64 binPath=C:\windows\temp\LECOMAx64.sys type=kernel && sc.exe start LECOMAx64
| Use Case | Privileges | Operating System |
|---|---|---|
| Load a vulnerable signed kernel driver | kernel | Windows 10 |
Detections
YARA 🏹
Expand
with header and size limitation
without header and size limitation
for renamed driver files
Resources
Known Vulnerable Samples
| Property | Value |
|---|---|
| Filename | LECOMAx64.sys |
| Creation Timestamp | |
| MD5 | 8ac99a014b36c4cf1eeee98f99410cca |
| SHA1 | eb817e8af016f6a3ece2b7cf421ec6d96970e285 |
| SHA256 | 0f2dff4116a84241d8cafe534b63454fb4ea26272da8977be03670701ec6631c |
| Publisher | LECO Corporation |
| Date | 07:30 PM 05/09/2007 |
| Company | LECO Corporation |
| Description | LECO LECOMA Device Driver |
| OriginalFilename | LECOMAx.SYS |
Imports
Expand
Imported Functions
Expand
Exported Functions
Expand
Sections
Expand
Signature
Expand
last_updated: 2026-06-16
