← Back to driver explorer
Driver intelligenceVulnerableVerified

BdApiUtil.sys

Driver can be used to load unsigned drivers. IOCTL code which takes a PID and terminates it (arbitrary process termination). Admin privileges required to install the driver, but if it's already installed, can be called by any user (non admin).

UUID / 708650ed-c497-48be-97bc-9edd48cf2a1aADDED / 2025-12-09AUTHOR / christopher-ellis-workday, plisskien, Julian Pena

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

BdApiUtil.sysSample 1 · HVCI unknown
MD5
29e1264dd642b646fbef9bd347b1b860
SHA1
2d0a8394180e728755e8e13547d572c9e89b7262
SHA256
32198295d2a2700b9895fff999c2b233f9befb0bc175815ec4b71ee926b6edfc
Imphash
7f0cfc7ad79e21e810f2f8b940b85130
Authentihash MD5
55759e7cd4e7816f800aac30081ba5c0
Authentihash SHA1
9f7ba541a3dc52e1cb765cd9a4157788eea7797a
Authentihash SHA256
b3811667f28da08859380173611954b5ed3cd8deb972a26caeba8f53d64a103d
Machine
AMD64
Version
5,2,3,116083
Publisher
Baidu, Inc.

Recorded command

sc.exe create BdApiUtil.sys binPath=C:\windows\temp\BdApiUtil.sys type=kernel && sc.exe start BdApiUtil.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references