← Back to driver explorer
Driver intelligenceVulnerableVerified

fildds.sys

Twister Antivirus, fildds.sys, DoS2 CVE-2023-1444 From IoControlCode 0x8011206B, a normal user can cause DoS due to writing into null address.

UUID / af98f6e6-f19e-4705-a7b9-e7ee7377447bADDED / 2024-06-20AUTHOR / VirarK

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

fildds.sysSample 1 · HVCI TRUE
MD5
afdb17f38361130453ea1098c7ddb754
SHA1
538bcb13cc8de64f7115429dbd9917a5a96f9bcd
SHA256
f8c07b6e2066a5a22a92d9f521ecdeb8c68698c400e4b83e0501b9f340957c22
Imphash
8a83e9dfc88f971a2dfc34e277724d28
Authentihash MD5
1485041cae109ae12931b4e3d566d16c
Authentihash SHA1
1b77dd7da15e583db86707a8ce8633699488f627
Authentihash SHA256
2d345b048fabc9d2013358fb20fca0eb441909129f1d81965eadad8c7f812886
Machine
AMD64
Version
2, 0, 0, 8553
Publisher
Filseclab Corporation

Recorded command

sc.exe create fildds.sys binPath=C:\windows\temp\fildds.sys type=kernel && sc.exe start fildds.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references