← Back to driver explorer
Driver intelligenceMaliciousVerified
driver_930da474.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Known samples 1
1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
driver_930da474.sysSample 1 · HVCI TRUE
- MD5
475f33ff28ba2c8007f39602c5f7ecf1- SHA1
011954de4094ae7e4562db7e749d5c66b268f1b4- SHA256
930da474a6d1be97b54f2c81e883e14d62897aa58622e5b040e412bd36cee0a7- Imphash
b72d2bef646e421c7a0789881378490f- Authentihash MD5
8b4bc159909565f0287091c3984cf6a7- Authentihash SHA1
a63ee75a4b4a8e4e6007cf19784ef0c9a01168ae- Authentihash SHA256
16aca71339240826d226f4adbfa73ea7b065f0f2d145d82d6ac2349d2ebba0d2- Machine
- I386
- Version
- 1.0.0.808
- Publisher
- Pinchins Technology Co.,Ltd.
Recorded command
sc.exe create driver_c3d48ddd.sys binPath=C:\windows\temp\driver_c3d48ddd.sys type=kernel && sc.exe start driver_c3d48ddd.sysElevate privileges · Privileges: kernel · OS: Windows 10

