← Back to driver explorer
Driver intelligenceMaliciousVerified

driver_4fc254af.sys

Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

UUID / 85335187-dae0-4f06-acea-209efaf74973ADDED / 2024-09-10AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

driver_4fc254af.sysSample 1 · HVCI TRUE
MD5
7cd54df7962a91032a643f152a79cd19
SHA1
261f76e625b0bc71a2cbf1e4b451555c2feeb959
SHA256
4fc254af8ebfa6fc1050f65c17015b39b36693b58f029c2fa1873976cbca52df
Imphash
0ca72f969ffaacca4008ae469f9508a4
Authentihash MD5
3180cd3d468ce1e96f45fd970a6c2065
Authentihash SHA1
b062862596bb9fa1e96e6422c994f5f92c6fb7a1
Authentihash SHA256
628c559f9f5de53cad74bc1f0c489bbe1aa5ef5672f47f73c0bfff1fcf98faca
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create driver_fdd16a94.sys binPath=C:\windows\temp\driver_fdd16a94.sys type=kernel && sc.exe start driver_fdd16a94.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references