← Back to driver explorer
Driver intelligenceMaliciousVerified

LcTkA.sys

SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses. Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes. We first reported our discovery to Microsoft’s Security Response Center (MSRC) in October 2022 and received an official case number (75361). Today, MSRC released an associated advisory under ADV220005. This research is being released alongside Mandiant, a SentinelOne technology and incident response partner.

UUID / d827f7a6-1832-4ddb-90dd-7a8cf1c7f25eADDED / 2023-03-04AUTHOR / Michael Haag

Known samples 1

0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

LcTkA.sysSample 1 · HVCI FALSE
MD5
909f3fc221acbe999483c87d9ead024a
SHA1
b2f955b3e6107f831ebe67997f8586d4fe9f3e98
SHA256
c8f9e1ad7b8cce62fba349a00bc168c849d42cfb2ca5b2c6cc4b51d054e0c497
Imphash
ce10082e1aa4c1c2bd953b4a7208e56a
Authentihash MD5
b663d79a688800d84065ccc2809874b7
Authentihash SHA1
46a9d9e9904ba5f4c011ad69d0795969c721c662
Authentihash SHA256
675329ef7a63a7c58d3daa6cb5c6e299143decec7a149c36a6bfe204bbf0407e
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create LcTkA.sys binPath=C:\windows\temp\LcTkA.sys type=kernel && sc.exe start LcTkA.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references