← Back to driver explorer
Driver intelligenceMaliciousVerified

e29f6311ae87542b3d693c1f38e4e3ad.sys

Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.

UUID / c00f818c-1c90-4b47-bc29-fb949f6efb65ADDED / 2023-07-31AUTHOR / Alice Climent-Pommeret

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

e29f6311ae87542b3d693c1f38e4e3ad.sysSample 1 · HVCI TRUE
MD5
e29f6311ae87542b3d693c1f38e4e3ad
SHA1
27371f45f42383029c3c2e6d64a22e35dc772a72
SHA256
d25b5e4d07f594c640dcd93cfc8ab3f0a38348150bd0bfae89f404fbb0d811c6
Imphash
be0dd8b8e045356d600ee55a64d9d197
Authentihash MD5
20b5622a89defecbf5fc8aa084c4b43e
Authentihash SHA1
6e80c1b17905dca548dc5a3a8751f1b75159b916
Authentihash SHA256
3db84cbf299307b1d3500b50355cf35f63d69c6c56d117335fbef7c84ddcc09b
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create e29f6311ae87542b3d693c1f38e4e3ad.sys binPath=C:\windows\temp\e29f6311ae87542b3d693c1f38e4e3ad.sys type=kernel && sc.exe start e29f6311ae87542b3d693c1f38e4e3ad.sys

· Privileges: kernel · OS: Windows 10

Research & references