3ea63674-2599-43b5-9390-4a929ec99f48
ktgn.sys
We were not able to verify the hash of this driver successfully, it has not been confirmed.
Description
BlackCat Ransomware Deploys New Signed Kernel Driver. BlackCat ransomware incident that occurred in February 2023.
Commands
sc.exe create ktgn.sys binPath=C:\windows\temp\ktgn.sys type=kernel && sc.exe start ktgn.sys
Use Case | Privileges | Operating System |
---|---|---|
Elevate privileges | kernel | Windows 10 |
Detections
YARA 🏹
Resources
Known Vulnerable Samples
Property | Value |
---|---|
Filename | ktgn.sys |
Creation Timestamp | |
MD5 | |
SHA1 | 994e3f5dd082f5d82f9cc84108a60d359910ba79 |
SHA256 |
Imports
Expand
Imported Functions
Expand
Exported Functions
Expand
Sections
Expand
Signature
Expand
last_updated: 2024-09-26