← Back to driver explorer
Driver intelligenceVulnerableVerified

CorMem.sys

Teledyne Digital Imaging CorMem.sys (Sapera Memory Manager) exposes physical memory read/write, contiguous memory allocation, and I/O port access to user-mode processes via CorMem.dll wrapper functions. The driver provides 36 exported functions including CorMemGetPhysMemory, CorMemMapPhysMemory, CorMemAllocPhysMemory, CorMemReadIo, and CorMemWriteIo. Actively abused for BYOVD with 0/71 VT detection. Execution parents include Cobalt Strike/IcedID malware and game cheat kernel loaders.

UUID / a7c3e2d1-8f4b-4e6a-b5d9-3c1f0e7a9b82ADDED / 2026-04-06AUTHOR / Michael Haag

Known samples 1

0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

CorMem.sysSample 1 · HVCI FALSE
MD5
78fb9882e498d964f42169ce511f07fc
SHA1
bceae6dc87c9c6c33555a4a9008be14c66fd1e20
SHA256
40c855d20d497823716a08a443dc85846233226985ee653770bc3b245cf2ed0f
Imphash
d4c9146f538e07774dc7a0e570b47edc
Authentihash MD5
559ede4607c9953fc5804a575c9a661b
Authentihash SHA1
505b7c56888009ab3b9531caeee6fa9a9b88916a
Authentihash SHA256
475df18e82d6e8ee09cbc9896f23f75b71aba43b7592d4962737cdc9230eb52d
Machine
AMD64
Version
9.00
Publisher
Teledyne Digital Imaging Inc.

Recorded command

sc.exe create CorMem.sys binPath=C:\windows\temp\CorMem.sys type=kernel && sc.exe start CorMem.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references

Acknowledgement: skept1kal @skept1kal