← Back to driver explorer
Driver intelligenceMaliciousVerified
driver_b4f33ffe.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Known samples 1
1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
driver_b4f33ffe.sysSample 1 · HVCI TRUE
- MD5
1010d96b7682e1f9c92666df47864e82- SHA1
aaac157478d24bb6225b489e3b6bad6de5d8d704- SHA256
b4f33ffef069c18e8a8834eb448dd1f1dbdaae93b140cfff5a1db015eb3ada2f- Imphash
f0c41590bbc46e6d23dd089a0ef51dd4- Authentihash MD5
b09eff67ace142cda2e346968611c596- Authentihash SHA1
0374fa46436b2ce53ea15950a70a6c8ceebeb5d3- Authentihash SHA256
ea7440064405fb9d4bb63876905f14beb70b0b01d26a7ea9b9d25c00932c8cca- Machine
- AMD64
- Version
- 0.1 built by: WinDDK
- Publisher
- Chingachguk & Denger2k
Recorded command
sc.exe create driver_fdd16a94.sys binPath=C:\windows\temp\driver_fdd16a94.sys type=kernel && sc.exe start driver_fdd16a94.sysElevate privileges · Privileges: kernel · OS: Windows 10

