← Back to driver explorer
Driver intelligenceMaliciousVerified

a26363e7b02b13f2b8d697abb90cd5c3.sys

Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.

UUID / ef6b5fe8-6c4b-4b32-8adc-c1d8a83e8558ADDED / 2023-07-31AUTHOR / Alice Climent-Pommeret

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

a26363e7b02b13f2b8d697abb90cd5c3.sysSample 1 · HVCI TRUE
MD5
a26363e7b02b13f2b8d697abb90cd5c3
SHA1
18693de1487c55e374b46a7728b5bf43300d4f69
SHA256
42ff11ddb46dfe5fa895e7babf88ee27790cde53a9139fc384346a89e802a327
Imphash
be0dd8b8e045356d600ee55a64d9d197
Authentihash MD5
973487ded5a1e7b32d97de36ce4a45cc
Authentihash SHA1
fe263450295cfa07653d2c9a6bc6f75324c9163b
Authentihash SHA256
4225bd4ba3f5d6d5cbd0606402aedca7342e2538abf85309ed3ccef0a738cbb8
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create a26363e7b02b13f2b8d697abb90cd5c3.sys binPath=C:\windows\temp\a26363e7b02b13f2b8d697abb90cd5c3.sys type=kernel && sc.exe start a26363e7b02b13f2b8d697abb90cd5c3.sys

· Privileges: kernel · OS: Windows 10

Research & references