← Back to driver explorer
Driver intelligenceMaliciousVerified

driver_930da474.sys

Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

UUID / 4c4e7664-af86-4483-858a-f59346f3d304ADDED / 2024-09-10AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

driver_930da474.sysSample 1 · HVCI TRUE
MD5
475f33ff28ba2c8007f39602c5f7ecf1
SHA1
011954de4094ae7e4562db7e749d5c66b268f1b4
SHA256
930da474a6d1be97b54f2c81e883e14d62897aa58622e5b040e412bd36cee0a7
Imphash
b72d2bef646e421c7a0789881378490f
Authentihash MD5
8b4bc159909565f0287091c3984cf6a7
Authentihash SHA1
a63ee75a4b4a8e4e6007cf19784ef0c9a01168ae
Authentihash SHA256
16aca71339240826d226f4adbfa73ea7b065f0f2d145d82d6ac2349d2ebba0d2
Machine
I386
Version
1.0.0.808
Publisher
Pinchins Technology Co.,Ltd.

Recorded command

sc.exe create driver_c3d48ddd.sys binPath=C:\windows\temp\driver_c3d48ddd.sys type=kernel && sc.exe start driver_c3d48ddd.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references