← Back to driver explorer
Driver intelligenceMaliciousVerified

avkiller.sys

Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

UUID / 7a9d34e4-c660-4388-ab61-4fd6f6bf1ad4ADDED / 2024-09-10AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

avkiller.sysSample 1 · HVCI TRUE
MD5
a8480c3b63db47212041042685afd753
SHA1
009328378ad988c7bc5b1e0f29837f52663b55d6
SHA256
b6cb163089f665c05d607a465f1b6272cdd5c949772ab9ce7227120cf61f971a
Imphash
acfd876a8d041c6baf407a21a36cf484
Authentihash MD5
7f0c6c15be6d37232ec196b64fc20ba6
Authentihash SHA1
bbea672633fa3be7dac0585673f4cfabca0d980c
Authentihash SHA256
6365024365fb0899e8a81735369a2e01f55523888e84b091858b48ef14a79e23
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create avkiller.sys binPath=C:\windows\temp\avkiller.sys type=kernel && sc.exe start avkiller.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references