← Back to driver explorer
Driver intelligenceMaliciousVerified

driver_146b8f4f.sys

Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

UUID / cea8bd08-a3c5-4ae1-a568-387b909ada67ADDED / 2024-09-10AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

driver_146b8f4f.sysSample 1 · HVCI TRUE
MD5
448453590f8694e15f1f2092fdfd5efd
SHA1
a9146d13e031e7c9ce40b7be7c7dc6dc0e422e54
SHA256
146b8f4fc91a4915e8f6aa6e0d871f7161a809c46760ef602bab534836142436
Imphash
7e58835e3886a2ff4d2230f8bf78639e
Authentihash MD5
dc0531b199dcebf3d9326c195436ea30
Authentihash SHA1
76fbc550334430d4986794018d7f9a5c30cb05a4
Authentihash SHA256
0058db5dab98d570d418af5c2ea15333bec7723b5819ab4f433d7e7760fae8ed
Machine
I386
Version
0.1.0.251
Publisher
Pinchins Technology Co.,Ltd.

Recorded command

sc.exe create driver_c3d48ddd.sys binPath=C:\windows\temp\driver_c3d48ddd.sys type=kernel && sc.exe start driver_c3d48ddd.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references