← Back to driver explorer
Driver intelligenceMaliciousVerified

driver_bfcbc010.sys

Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.

UUID / dbfcce10-76a3-44a4-a9b8-d7126152a235ADDED / 2024-09-10AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

driver_bfcbc010.sysSample 1 · HVCI TRUE
MD5
c22ab4197c4a6a1ea1945248ddc2d19d
SHA1
92bb5c6e50d5e05b0cd3852412668b79344127ab
SHA256
bfcbc010432a89714349bd487555cec1ab5299a70f533a16d326a69e15e0c203
Imphash
ce10082e1aa4c1c2bd953b4a7208e56a
Authentihash MD5
ffd2f3b8ec7850c6068f310f6b8a2e85
Authentihash SHA1
ab2fc7a155ba7c693731375d8c09e72108b5c2b9
Authentihash SHA256
a282ba45dd3727203ba40cc8f5f79167bb2d461fe294a49557f4667db1e05658
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create driver_bfcbc010.sys binPath=C:\windows\temp\driver_bfcbc010.sys type=kernel && sc.exe start driver_bfcbc010.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references