← Back to driver explorer
Driver intelligenceMaliciousVerified

c94f405c5929cfcccc8ad00b42c95083.sys

Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.

UUID / ddefecdd-9410-46d9-8957-e23aac1aba0cADDED / 2023-07-31AUTHOR / Alice Climent-Pommeret

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

c94f405c5929cfcccc8ad00b42c95083.sysSample 1 · HVCI TRUE
MD5
c94f405c5929cfcccc8ad00b42c95083
SHA1
03e82eae4d8b155e22ffdafe7ba0c4ab74e8c1a7
SHA256
da70fa44290f949e9b3e0fcfe0503de46e82e0472e8e3c360da3fd2bfa364eee
Imphash
be0dd8b8e045356d600ee55a64d9d197
Authentihash MD5
0895b0ede1999778543eed8b8ea48fda
Authentihash SHA1
6d7cbfc4e0bb441863e6a7b4c865e05948d6390d
Authentihash SHA256
e42d8953f90e0b052adacd6c8e6cc240d723e5b4605ac897fe9667e661f9ed3c
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create c94f405c5929cfcccc8ad00b42c95083.sys binPath=C:\windows\temp\c94f405c5929cfcccc8ad00b42c95083.sys type=kernel && sc.exe start c94f405c5929cfcccc8ad00b42c95083.sys

· Privileges: kernel · OS: Windows 10

Research & references