0590655c-baa2-481a-b909-463534bd7a5e
daxin_blank5.sys
Description
Driver used in the Daxin malware campaign.
This download link contains the malicious driver!
Commands
sc.exe create daxin_blank5.sys binPath=C:\windows\temp\daxin_blank5.sys type=kernel && sc.exe start daxin_blank5.sys
Use Case | Privileges | Operating System |
---|---|---|
Elevate privileges | kernel | Windows 10 |
Detections
YARA 🏹
Resources
Known Vulnerable Samples
Property | Value |
---|---|
Filename | daxin_blank5.sys |
Creation Timestamp | 2008-07-17 19:29:43 |
MD5 | f242cffd9926c0ccf94af3bf16b6e527 |
SHA1 | 53f776d9a183c42b93960b270dddeafba74eb3fb |
SHA256 | 9c2f3e9811f7d0c7463eaa1ee6f39c23f902f3797b80891590b43bbe0fdf0e51 |
Authentihash MD5 | da0d70a9fd3a61a2802af4a07bed29d4 |
Authentihash SHA1 | 99a969b2deded8b2d403268cd49139463c06b484 |
Authentihash SHA256 | 954789c665098cf491a9bdf4e04886bad8992a393f91ccbca239bff40cc6dca6 |
RichPEHeaderHash MD5 | 6c5319c52cabf708cac1121ed7df420b |
RichPEHeaderHash SHA1 | 4d9f5c969d83ff20b202263d6d4a38aed8deb9f3 |
RichPEHeaderHash SHA256 | cb3c84a0789027aef0c0aef452da254f600b2f17ed53054a5a68765f708302d4 |
Publisher | n/a |
Imports
Expand
- ntoskrnl.exe
- HAL.dll
- NDIS.SYS
Imported Functions
Expand
- MmUnlockPages
- KeInsertQueueApc
- strncmp
- KeInitializeApc
- MmProbeAndLockPages
- IoAllocateMdl
- _except_handler3
- IoQueueWorkItem
- KeAttachProcess
- KeDetachProcess
- IoGetCurrentProcess
- IoFreeWorkItem
- RtlFreeUnicodeString
- ZwClose
- ZwWriteFile
- ZwCreateFile
- RtlAnsiStringToUnicodeString
- IofCompleteRequest
- ExFreePool
- ExAllocatePoolWithTag
- InterlockedDecrement
- MmMapLockedPagesSpecifyCache
- IoFreeMdl
- InterlockedExchange
- InterlockedIncrement
- swprintf
- RtlCopyUnicodeString
- ExfInterlockedInsertTailList
- wcsncmp
- IoCreateSymbolicLink
- RtlInitUnicodeString
- IoCreateDevice
- IoDeleteSymbolicLink
- KeInitializeSpinLock
- IoDeleteDevice
- _strnicmp
- ExfInterlockedRemoveHeadList
- IoAllocateWorkItem
- KfAcquireSpinLock
- KfReleaseSpinLock
- NdisAllocateMemory
- NdisFreePacket
- NdisAllocatePacket
- NdisResetEvent
- NdisCloseAdapter
- NdisAllocateBuffer
- NdisInitializeEvent
- NdisOpenAdapter
- NdisFreeMemory
- NdisQueryAdapterInstanceName
- NdisDeregisterProtocol
- NdisSetEvent
- NdisFreeBufferPool
- NdisAllocatePacketPool
- NdisFreePacketPool
- NdisRegisterProtocol
- NdisWaitEvent
- NdisAllocateBufferPool
- NdisCopyFromPacketToPacket
Exported Functions
Expand
Sections
Expand
- .text
- .rdata
- .data
- INIT
- .reloc
Signature
Expand
last_updated: 2024-09-26