← Back to driver explorer
Driver intelligenceMaliciousVerified

ktmutil7ODM.sys

Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.

UUID / 809e7c77-f0fa-46fb-862c-71969ae0c032ADDED / 2023-07-12AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

ktmutil7ODM.sysSample 1 · HVCI TRUE
MD5
0b9b78d1281c7d4ab50497cf6ea7452a
SHA1
c3ca396b5af2064c6f7d05fa0fb697e68d0b9631
SHA256
751e9376cb7cb9de63e1808d43579d787d3f6d659173038fe44a2d7fdb4fd17e
Imphash
d51f0f6034eb5e45f0ed4e9b7bbc9c97
Authentihash MD5
66027547e4679835323129a1aa2427eb
Authentihash SHA1
cccd3eca8716d9a3b111ca0cf89d384fbd852b39
Authentihash SHA256
625fce937dd4fed61bc3a0475e10b6f05d9061c99b5335bf3f33dc43511300b3
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create ktmutil7ODM.sys binPath=C:\windows\temp\ktmutil7ODM.sys type=kernel && sc.exe start ktmutil7ODM.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references