← Back to driver explorer
Driver intelligenceMaliciousVerified

spwizimgVT.sys

Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.

UUID / b759adfa-b353-4ca3-9dfb-8fadf7a437ebADDED / 2023-07-12AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

spwizimgVT.sysSample 1 · HVCI TRUE
MD5
5917e415a5bf30b3fcbcbcb8a4f20ee0
SHA1
4dd86ff6f7180abebcb92e556a486abe7132754c
SHA256
30061ef383e18e74bb067fbca69544f1a7544e8dc017d4e7633d8379aff4c3c3
Imphash
d51f0f6034eb5e45f0ed4e9b7bbc9c97
Authentihash MD5
d4b2c5fa7675cb780e8d4bc6bee7e41c
Authentihash SHA1
69fb9f2483c8e571780175dd607d455d9ed8ce47
Authentihash SHA256
c9fbff8b749a1f580b5b5b9e59ec3ffd769b4179970b82e32a3d36e7a3a8cb1a
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create spwizimgVT.sys binPath=C:\windows\temp\spwizimgVT.sys type=kernel && sc.exe start spwizimgVT.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references