← Back to driver explorer
Driver intelligenceVulnerableVerified
NSecKrnl.sys
Driver used by ValleyRAT malware to terminate security processes via IOCTL 0x2248E0
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261Sample 1 · HVCI unknown
- MD5
80961850786d6531f075b8a6f9a756ad- SHA1
b0b912a3fd1c05d72080848ec4c92880004021a1- SHA256
206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261- Imphash
fdbdf8ea09a9af32d54979c574260475- Authentihash MD5
0cd31f752c2fc1164a3c7b9486c1cd8d- Authentihash SHA1
383ceae579aa77bd7076eb03615e0469e425fd4f- Authentihash SHA256
cf24c69123d4a72445547f7b5ad6738fb47f2d3fab06e3d628b7278113a63ae0- Machine
- AMD64
- Version
- 3.7.40.5314
- Publisher
- NSEC Co.,Ltd
Recorded command
sc.exe create NSecKrnl binPath=C:\windows\temp\NSecKrnl.sys type=kernel && sc.exe start NSecKrnlTerminate security processes · Privileges: kernel · OS: Windows 10
Research & references
- https://hexastrike.com/resources/blog/threat-intelligence/valleyrat-exploiting-byovd-to-kill-endpoint-security/
- https://github.com/ANYLNK/NSecSoftBYOVD
- https://symantec-blogs.broadcom.com/threat-intelligence/black-basta-ransomware-byovd
- https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/
- https://www.trendmicro.com/en_gb/research/26/c/dissecting-a-warlock-attack.html
- https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure
Acknowledgement: Liran Ravich, Cribl

