← Back to driver explorer
Driver intelligenceMaliciousVerified

834761775.sys

Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.

UUID / 66813e1f-13c8-4884-931a-62b46350c345ADDED / 2023-07-12AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

834761775.sysSample 1 · HVCI TRUE
MD5
072ba2309b825ce1dba37d8d924ea8ed
SHA1
89a74d0e9fd03129082c5b868f5ad62558ca34fd
SHA256
24c900024d213549502301c366d18c318887630f04c96bf0a3d6ba74e0df164f
Imphash
0262d4147f21d681f8519ab2af79283f
Authentihash MD5
d572a2339ab3259578bfb39301b78884
Authentihash SHA1
d8e79ba181f2a646bbaa9e28ce2c4c490074fda2
Authentihash SHA256
22074c412bb82bd97768eba0cb40e451d75d969e94d0548af804aafc04ca02fd
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create 834761775.sys binPath=C:\windows\temp\834761775.sys type=kernel && sc.exe start 834761775.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references