IoDrv.sys
IoDrv.sys is a hardware I/O driver with an embedded TOPSTAR OVERSEAS ELECTRONICS Co.,Ltd signature. Beazley Security identified this exact sample, renamed Redacted.sys, in an INC ransomware affiliate intrusion. The accompanying Redacted EDR Blinder reportedly used the driver to modify security-driver code and impair endpoint defenses. The sample contains physical-memory mapping and port-I/O interfaces. The reported EDR-targeting logic belongs to the accompanying executable, not a built-in target list in the driver. Current Windows loading-policy compatibility and the runtime attack were not independently tested.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
IoDrv.sysSample 1 · HVCI unknown
- MD5
a63d5ed574d0231c958551903c4ddf28- SHA1
844304be902d933f0b335b35bebbe620b6c8d613- SHA256
266d2027a8fc999773c88defd4591d02b8819cf6b07699182319338270b399d2- Imphash
85f86c7c8ce81a78e84efa545d7edc65- Authentihash MD5
0eacee5e31837ad90f20db9a8f781aed- Authentihash SHA1
99100b871242499156d6360082d240a6fd9fdd4b- Authentihash SHA256
6601964a52268d49def829aacd687faad911be77a3d5240394a4b63967fe4838- Machine
- AMD64
- Version
- Not recorded
- Publisher
- TOPSTAR OVERSEAS ELECTRONICS Co.,Ltd
Research & references
Acknowledgement: Beazley Security DFIR and MXDR teams

