← Back to driver explorer
Driver intelligenceMaliciousVerified
2.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Known samples 1
0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
2.sysSample 1 · HVCI FALSE
- MD5
c1ade0fc97f6a774fd036892c8056907- SHA1
e23dff8959176dc17a1e37356a99c3333e75e8d3- SHA256
df72cb33a23ae8f6f9dc64bb738fcfaea959368ce05cf399f3c7db5e90104bd7- Imphash
8d5129d39204fcf88ffca488305e4480- Authentihash MD5
fd757ea1ff06f0e7dfd2b49d9597a2c8- Authentihash SHA1
627692c0cfb3cb52056d506928bda718f6177080- Authentihash SHA256
2a82a5b833cf03738f2d159e2912d2947f5216a4d2adf31a204f365d7ceab430- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Recorded command
sc.exe create 2.sys binPath=C:\windows\temp\2.sys type=kernel && sc.exe start 2.sysElevate privileges · Privileges: kernel · OS: Windows 10

