← Back to driver explorer
Driver intelligenceMaliciousVerified

driver_89036534.sys

Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

UUID / 750a8aa9-a87c-4142-b96b-18ea139ada14ADDED / 2024-09-10AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

driver_89036534.sysSample 1 · HVCI TRUE
MD5
f157ac999b29ac010862177c1c66cee7
SHA1
905c66938437218b27dccb4d54b1222cf7a313c8
SHA256
89036534a3da657882da96d9f211ae41efab4083bd6dbedbeaa2516d1d04cff4
Imphash
63ef87ab3b1750e564436dc6e6428fa9
Authentihash MD5
34687c5f0f1d81135ed5b86a4d7a07b7
Authentihash SHA1
f329cd844706772c18f52b6a0f8a3b02ac84d0bd
Authentihash SHA256
1df739ca8e7763776f84b421c7859fccb2fbfd47cf27f9980f646597f5ae7836
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create driver_ef9d653a.sys binPath=C:\windows\temp\driver_ef9d653a.sys type=kernel && sc.exe start driver_ef9d653a.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references