← Back to driver explorer
Driver intelligenceVulnerableVerified
athpexnt.sys
AhnLab kernel driver exposing arbitrary physical memory read/write via IOCTL 0x81000000. Device accessible at \\.\ATHpEx. Signed by AhnLab Inc. with VeriSign certificate (first seen 2014). Zero detections (0/73) on VirusTotal but exploitable for privilege escalation by mapping attacker-controlled physical memory into kernel address space.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
ATHpExNt.sysSample 1 · HVCI unknown
- MD5
bf77a19e1396d6d36e32ff8d23eb5d3f- SHA1
e630a14b4c74264cbe702999f78750ec49359ca4- SHA256
fa0902daefbd9e716faaac8e854144ea0573e2a41192796f3b3138fe7a1d19f1- Imphash
3bac3002e583d000a28f76a62f67bfed- Authentihash MD5
2beabc796f5ba54d9cb08c6db2aa2490- Authentihash SHA1
4cd5fa8a875644fc803013dc4bfb116b13d70dc1- Authentihash SHA256
fc22650cae4722a174da31addbaf088a04ad4f8b2460191da946b3de529f6a0a- Machine
- AMD64
- Version
- 1,0,0,2
- Publisher
- AhnLab, Inc.
Recorded command
sc.exe create ATHpExNt binPath=C:\windows\temp\ATHpExNt.sys type=kernel && sc.exe start ATHpExNtElevate privileges · Privileges: kernel · OS: Windows 10

