← Back to driver explorer
Driver intelligenceVulnerableVerified

athpexnt.sys

AhnLab kernel driver exposing arbitrary physical memory read/write via IOCTL 0x81000000. Device accessible at \\.\ATHpEx. Signed by AhnLab Inc. with VeriSign certificate (first seen 2014). Zero detections (0/73) on VirusTotal but exploitable for privilege escalation by mapping attacker-controlled physical memory into kernel address space.

UUID / f4e00816-97a8-4c2d-b990-9812f16fe3d3ADDED / 2026-03-20AUTHOR / Michael Haag

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

ATHpExNt.sysSample 1 · HVCI unknown
MD5
bf77a19e1396d6d36e32ff8d23eb5d3f
SHA1
e630a14b4c74264cbe702999f78750ec49359ca4
SHA256
fa0902daefbd9e716faaac8e854144ea0573e2a41192796f3b3138fe7a1d19f1
Imphash
3bac3002e583d000a28f76a62f67bfed
Authentihash MD5
2beabc796f5ba54d9cb08c6db2aa2490
Authentihash SHA1
4cd5fa8a875644fc803013dc4bfb116b13d70dc1
Authentihash SHA256
fc22650cae4722a174da31addbaf088a04ad4f8b2460191da946b3de529f6a0a
Machine
AMD64
Version
1,0,0,2
Publisher
AhnLab, Inc.

Recorded command

sc.exe create ATHpExNt binPath=C:\windows\temp\ATHpExNt.sys type=kernel && sc.exe start ATHpExNt

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references