AToolsKrnl64.sys
Antiy ATool AToolsKrnl64.sys from the reported 2.0.26.819 package exposes process termination through IOCTL 0x99000050. Its caller check validates an Antiy-signed executable on disk and caches the accepted process, but does not verify the integrity of the running client. A modified genuine client can therefore pass this check and request termination of caller-selected processes. Static analysis of this sample confirms a world-readable device and a kernel-mode target-open path that does not require the caller to already hold termination rights. The termination path rejects targets with a nonzero driver-defined protection/state byte. The public demonstration terminates only a self-created ordinary child; protected-process and EDR termination are not established.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
AToolsKrnl64.sysSample 1 · HVCI unknown
- MD5
f0a5d14e0a8acea507ef9a694661e544- SHA1
8f18c4c157b4078669364c081068fc2bb271c12b- SHA256
f85af685660a28e3cd18e2c9ef6b1fbb440ae0c5934e625e8a055e1f158c3e56- Imphash
79724a023a31b15116d696a24877176a- Authentihash MD5
fcf3fe21b796b21967ac2f9c292c22d1- Authentihash SHA1
c5acaa2a55817ea99875a159c761530c8aa16a0d- Authentihash SHA256
613d60ec08d1383b38d0c6c01b870712864865a70f13677dee7cc1270caacab1- Machine
- AMD64
- Version
- 2.0.26.819
- Publisher
- Antiy Labs
Research & references
Acknowledgement: Xusheng Li @xusheng6

