← Back to driver explorer
Driver intelligenceMaliciousVerified
fur.sys
SophosLabs has discovered that threat actors are using a new driver loader called BURNTCIGAR to install a malicious driver signed with Microsoft.
Known samples 1
0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
fur.sysSample 1 · HVCI FALSE
- MD5
6a066d2be83cf83f343d0550b0b8f206- SHA1
8e126f4f35e228fdd3aa78d533225db7122d8945- SHA256
0d10c4b2f56364b475b60bd2933273c8b1ed2176353e59e65f968c61e93b7d99- Imphash
28dc68bb6d6bf4f6b2db8dd7588b2511- Authentihash MD5
5c23bab622d6bbabd23d29b4adaa4ae0- Authentihash SHA1
9fbb6f9a22d1c676ff1b97a33d4c5e94f18aca5f- Authentihash SHA256
aab97fb324c883f1de71112e1d9fb716cef40636e39a3b9f4a5b8678cf7bde3f- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Recorded command
sc.exe create fur.sys binPath=C:\windows\temp\fur.sys type=kernel && sc.exe start fur.sysElevate privileges · Privileges: kernel · OS: Windows 10

