← Back to driver explorer
Driver intelligenceMaliciousVerified

driver_1afc1d06.sys

Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

UUID / d7773616-9860-4768-b6a2-d74f32c23b4eADDED / 2024-09-10AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

driver_1afc1d06.sysSample 1 · HVCI TRUE
MD5
ef814560ab68d384aa056881cf4342a4
SHA1
41ec85e991909519ccb08bc004ba7f0a09f19f50
SHA256
1afc1d0672c14df8c9e4caa88f5d3b7968421d72c548b6df307e371b9a8776d5
Imphash
bf06985f2031c08da05742e19dae38a7
Authentihash MD5
d605c0ffeb415a694fd8542cfd7b90d0
Authentihash SHA1
945b17ce098ff381bf3cba405fd8b571c016e77c
Authentihash SHA256
cba6df77d819fc098c160402a47ccb616414cbe7e42ea91417cbb5941e04ce41
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create driver_bfcbc010.sys binPath=C:\windows\temp\driver_bfcbc010.sys type=kernel && sc.exe start driver_bfcbc010.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references