← Back to driver explorer
Driver intelligenceMaliciousVerified
SakDriver.sys
SakDriver is a malicious Windows kernel rootkit analyzed by 0xSec. It uses a registry callback for command dispatch and process-memory manipulation, conceals its driver file and service registry entries, and hides network connections through an NSI hook. It also implements WFP destination filtering and HTTP reporting. The sample uses the device name \Device\SakDriverWFP and carries a CrackerDrv.pdb path. These findings apply to the analyzed sample; current Windows loadability and HVCI compatibility have not been established.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
SakDriver.sysSample 1 · HVCI unknown
- MD5
b5f122f3f07f618c0a7678fa40801faa- SHA1
7440358c5041eba34e8673100989df756a6426da- SHA256
4e95aba17c1a423cda5cc9f9f04f7cf8db17e294eb31ed1aa85063601b82fe8d- Imphash
7afd4d4bb61395a3cd7d1b040e1cfd9b- Authentihash MD5
c151927ea37d72f1f08ccdc94ba37524- Authentihash SHA1
a13988ece3adc1f1cb5166cd48abd32050d8540d- Authentihash SHA256
47b766019e0e18251ba39e24d20a99f45bdd5c310a4e94091e4f19d9fef27996- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Research & references
Acknowledgement: 0xSec

