← Back to driver explorer
Driver intelligenceMaliciousVerified

5a4fe297c7d42539303137b6d75b150d.sys

Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.

UUID / 75b9b0c5-dd3e-4cf3-a693-c80f2feabb6aADDED / 2023-07-31AUTHOR / Alice Climent-Pommeret

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

5a4fe297c7d42539303137b6d75b150d.sysSample 1 · HVCI TRUE
MD5
5a4fe297c7d42539303137b6d75b150d
SHA1
ebd8b7e964b8c692eea4a8c406b9cd0be621ebe2
SHA256
9a67626fb468d3f114c23ac73fd8057f43d06393d3eca04da1d6676f89da2d40
Imphash
be0dd8b8e045356d600ee55a64d9d197
Authentihash MD5
e5c54b958d6608cbb97e1a21c200dcd9
Authentihash SHA1
cc9b2ee8d9f3031eeab893e29231208eee30e494
Authentihash SHA256
47bcbe0e7087cde7a9fb01fcec12b5ab185112c8f7f5638543715efa774b0cec
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create 5a4fe297c7d42539303137b6d75b150d.sys binPath=C:\windows\temp\5a4fe297c7d42539303137b6d75b150d.sys type=kernel && sc.exe start 5a4fe297c7d42539303137b6d75b150d.sys

· Privileges: kernel · OS: Windows 10

Research & references