← Back to driver explorer
Driver intelligenceMaliciousVerified

2.sys

Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

UUID / bb1f80f3-d2fd-463e-9403-57c919bd976bADDED / 2024-09-10AUTHOR / Michael Haag

Known samples 1

0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

2.sysSample 1 · HVCI FALSE
MD5
c1ade0fc97f6a774fd036892c8056907
SHA1
e23dff8959176dc17a1e37356a99c3333e75e8d3
SHA256
df72cb33a23ae8f6f9dc64bb738fcfaea959368ce05cf399f3c7db5e90104bd7
Imphash
8d5129d39204fcf88ffca488305e4480
Authentihash MD5
fd757ea1ff06f0e7dfd2b49d9597a2c8
Authentihash SHA1
627692c0cfb3cb52056d506928bda718f6177080
Authentihash SHA256
2a82a5b833cf03738f2d159e2912d2947f5216a4d2adf31a204f365d7ceab430
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create 2.sys binPath=C:\windows\temp\2.sys type=kernel && sc.exe start 2.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references