← Back to driver explorer
Driver intelligenceMaliciousVerified

driver_206006a1.sys

Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

UUID / 9e0a1bae-6509-41fd-a5bf-dfe6cf388682ADDED / 2024-09-10AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

driver_206006a1.sysSample 1 · HVCI TRUE
MD5
d04043db948ce9f4c5ba03dc23675556
SHA1
04e55c61f01529fb6c579ca5bf3ce81f0241a477
SHA256
206006a11f233b9ae876952308f6d60d7a75c80b4d530a3e6146a0b4d8cd3e4f
Imphash
4acb54175cf28b6cb60fc93a8cd171e4
Authentihash MD5
2a8d905d06f54bd8abc4b28e70cfe839
Authentihash SHA1
93e31aaac7af96d42b40614c9ae33ff08b71e4ce
Authentihash SHA256
ebe86f9f6c9c6639f3327f210c2a945bbbf069f505b1b85e3aee8d1cddf702f9
Machine
AMD64
Version
1.6.5.7
Publisher
Windows (R) Win 7 DDK provider

Recorded command

sc.exe create driver_bfcbc010.sys binPath=C:\windows\temp\driver_bfcbc010.sys type=kernel && sc.exe start driver_bfcbc010.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references