← Back to driver explorer
Driver intelligenceMaliciousVerified
driver_bfcbc010.sys
Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.
Known samples 1
1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
driver_bfcbc010.sysSample 1 · HVCI TRUE
- MD5
c22ab4197c4a6a1ea1945248ddc2d19d- SHA1
92bb5c6e50d5e05b0cd3852412668b79344127ab- SHA256
bfcbc010432a89714349bd487555cec1ab5299a70f533a16d326a69e15e0c203- Imphash
ce10082e1aa4c1c2bd953b4a7208e56a- Authentihash MD5
ffd2f3b8ec7850c6068f310f6b8a2e85- Authentihash SHA1
ab2fc7a155ba7c693731375d8c09e72108b5c2b9- Authentihash SHA256
a282ba45dd3727203ba40cc8f5f79167bb2d461fe294a49557f4667db1e05658- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Recorded command
sc.exe create driver_bfcbc010.sys binPath=C:\windows\temp\driver_bfcbc010.sys type=kernel && sc.exe start driver_bfcbc010.sysElevate privileges · Privileges: kernel · OS: Windows 10

