834761775.sys
Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Known samples 1
1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
834761775.sysSample 1 · HVCI TRUE
- MD5
072ba2309b825ce1dba37d8d924ea8ed- SHA1
89a74d0e9fd03129082c5b868f5ad62558ca34fd- SHA256
24c900024d213549502301c366d18c318887630f04c96bf0a3d6ba74e0df164f- Imphash
0262d4147f21d681f8519ab2af79283f- Authentihash MD5
d572a2339ab3259578bfb39301b78884- Authentihash SHA1
d8e79ba181f2a646bbaa9e28ce2c4c490074fda2- Authentihash SHA256
22074c412bb82bd97768eba0cb40e451d75d969e94d0548af804aafc04ca02fd- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Recorded command
sc.exe create 834761775.sys binPath=C:\windows\temp\834761775.sys type=kernel && sc.exe start 834761775.sysElevate privileges · Privileges: kernel · OS: Windows 10

