← Back to driver explorer
Driver intelligenceMaliciousVerified

driver_b4f33ffe.sys

Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

UUID / 51a44484-8bcc-4150-8b94-4a755cff0af8ADDED / 2024-09-10AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

driver_b4f33ffe.sysSample 1 · HVCI TRUE
MD5
1010d96b7682e1f9c92666df47864e82
SHA1
aaac157478d24bb6225b489e3b6bad6de5d8d704
SHA256
b4f33ffef069c18e8a8834eb448dd1f1dbdaae93b140cfff5a1db015eb3ada2f
Imphash
f0c41590bbc46e6d23dd089a0ef51dd4
Authentihash MD5
b09eff67ace142cda2e346968611c596
Authentihash SHA1
0374fa46436b2ce53ea15950a70a6c8ceebeb5d3
Authentihash SHA256
ea7440064405fb9d4bb63876905f14beb70b0b01d26a7ea9b9d25c00932c8cca
Machine
AMD64
Version
0.1 built by: WinDDK
Publisher
Chingachguk & Denger2k

Recorded command

sc.exe create driver_fdd16a94.sys binPath=C:\windows\temp\driver_fdd16a94.sys type=kernel && sc.exe start driver_fdd16a94.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references