← Back to driver explorer
Driver intelligenceMaliciousVerified
avkiller.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Known samples 1
1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
avkiller.sysSample 1 · HVCI TRUE
- MD5
a8480c3b63db47212041042685afd753- SHA1
009328378ad988c7bc5b1e0f29837f52663b55d6- SHA256
b6cb163089f665c05d607a465f1b6272cdd5c949772ab9ce7227120cf61f971a- Imphash
acfd876a8d041c6baf407a21a36cf484- Authentihash MD5
7f0c6c15be6d37232ec196b64fc20ba6- Authentihash SHA1
bbea672633fa3be7dac0585673f4cfabca0d980c- Authentihash SHA256
6365024365fb0899e8a81735369a2e01f55523888e84b091858b48ef14a79e23- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Recorded command
sc.exe create avkiller.sys binPath=C:\windows\temp\avkiller.sys type=kernel && sc.exe start avkiller.sysElevate privileges · Privileges: kernel · OS: Windows 10

