← Back to driver explorer
Driver intelligenceVulnerableVerified

rspot.sys

Rising Antivirus rspot.sys driver with kernel-level process termination capabilities. Identified in ESET EDR killers research (March 2026) as actively abused by threat actors to disable EDR products.

UUID / d9a9fd72-e789-4bba-9b96-549b123e5c40ADDED / 2026-03-20AUTHOR / Michael Haag

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

rspot.sysSample 1 · HVCI unknown
MD5
054a32d6033b1744dca7f49b2e466ea2
SHA1
c85c9a09cd1cb1691da0d96772391be6ddba3555
SHA256
ea8c8f834523886b07d87e85e24f124391d69a738814a0f7c31132b6b712ed65
Imphash
33df0c29b1e8562acd8168ef019b3f66
Authentihash MD5
76d32c7414a895472faa84ce1eb97b87
Authentihash SHA1
5a7b5f578ec0919e82af48deedcd55bacafd1bd0
Authentihash SHA256
87d4a698bcc41a0e725bfeb00d464478d7add9e1abb687e52c8ef3d0d66cc730
Machine
AMD64
Version
1, 0, 0, 16
Publisher
Beijing Rising Network Security Technology Co., Ltd.

Recorded command

sc.exe create rspot.sys binPath=C:\windows\temp\rspot.sys type=kernel && sc.exe start rspot.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references

Acknowledgement: ESET Research @ESETresearch