← Back to driver explorer
Driver intelligenceVulnerableVerified

Chaos-Rootkit.sys

Chaos-Rootkit is a x64 ring0 rootkit with process hiding, privilege escalation, and capabilities for protecting and unprotecting processes and ability to restrict access to files except for whitelisted process work seamlessly on the latest Windows versions.

UUID / de62baae-872d-4e9a-b6d9-b0ac99854c66ADDED / 2024-06-20AUTHOR / goosvorbook

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

Chaos-Rootkit.sysSample 1 · HVCI TRUE
MD5
443e8d915c04c370b7c31bb5f11ebab7
SHA1
c3f8b7f0995073abb58c2aec1b6062f89fe838a0
SHA256
bdc73f752c1353d41e877d8bf42a1c53f0bba7d6f52348aaef60e06f4d3087d0
Imphash
0abe54d37cd1a70ed9041ab7d80318a9
Authentihash MD5
cec49dd8b1dbb091e3d6f8134cee5bdc
Authentihash SHA1
a4b5442d906715caaadc011d0c2fa44cd894dbfe
Authentihash SHA256
23be3616a4fb4e620f971e4348dc46b7980abca6463be3cb4b83769a955f2810
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create Chaos-Rootkit.sys binPath=C:\windows\temp\Chaos-Rootkit.sys type=kernel && sc.exe start Chaos-Rootkit.sys

Elevate privileges · Privileges: kernel · OS: Windows 11

Research & references