← Back to driver explorer
Driver intelligenceVulnerableVerified
rspot.sys
Rising Antivirus rspot.sys driver with kernel-level process termination capabilities. Identified in ESET EDR killers research (March 2026) as actively abused by threat actors to disable EDR products.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
rspot.sysSample 1 · HVCI unknown
- MD5
054a32d6033b1744dca7f49b2e466ea2- SHA1
c85c9a09cd1cb1691da0d96772391be6ddba3555- SHA256
ea8c8f834523886b07d87e85e24f124391d69a738814a0f7c31132b6b712ed65- Imphash
33df0c29b1e8562acd8168ef019b3f66- Authentihash MD5
76d32c7414a895472faa84ce1eb97b87- Authentihash SHA1
5a7b5f578ec0919e82af48deedcd55bacafd1bd0- Authentihash SHA256
87d4a698bcc41a0e725bfeb00d464478d7add9e1abb687e52c8ef3d0d66cc730- Machine
- AMD64
- Version
- 1, 0, 0, 16
- Publisher
- Beijing Rising Network Security Technology Co., Ltd.
Recorded command
sc.exe create rspot.sys binPath=C:\windows\temp\rspot.sys type=kernel && sc.exe start rspot.sysElevate privileges · Privileges: kernel · OS: Windows 10
Research & references
Acknowledgement: ESET Research @ESETresearch

