51808fa6-89a4-4f4d-aabc-0a7b0e99e34d
kdriver.sys
Description
Confirmed vulnerable driver from Microsoft Block List
Use Case | Privileges | Operating System |
---|---|---|
Elevate privileges | kernel | Windows |
Detections
YARA 🏹
Expand
Resources
CVE
Known Vulnerable Samples
Property | Value |
---|---|
Filename | |
Creation Timestamp | 2020-08-16 21:38:03 |
MD5 | 70053ab9df31eb2dcd6f5b001386a8d2 |
SHA1 | b1266873fa36a2104fd5d7f498a9957bc3d9d450 |
SHA256 | 603ccc97a198b004f9fa56deed2295d1b2d42ef01f22d80a00cb28bcf1b85646 |
Authentihash MD5 | ff295de93e6b6dcc3938d50901a7240d |
Authentihash SHA1 | 484c72dd4fd91083b249f3ccc733a3c8335e583f |
Authentihash SHA256 | 0c7809ac1fa074408518ddc0ac118912c9cd43ed9c89213bc4d59043016b040c |
RichPEHeaderHash MD5 | ffdf660eb1ebf020a1d0a55a90712dfb |
RichPEHeaderHash SHA1 | 3e905e3d061d0d59de61fcf39c994fcb0ec1bab3 |
RichPEHeaderHash SHA256 | 2b3f99a94b7a7132854be769e27b331419c53989ef42f686d6f5ba09ddefefd6 |
Imports
Expand
- ntoskrnl.exe
- WDFLDR.SYS
Imported Functions
Expand
- NtQuerySystemInformation
- RtlInitUnicodeString
- ExAllocatePool
- ExAllocatePoolWithTag
- ExFreePoolWithTag
- IofCompleteRequest
- IoCreateDevice
- IoCreateSymbolicLink
- IoDeleteDevice
- IoDeleteSymbolicLink
- _wcsicmp
- RtlInitString
- RtlAnsiStringToUnicodeString
- RtlFreeUnicodeString
- IoGetDeviceObjectPointer
- ZwClose
- MmIsAddressValid
- ZwOpenDirectoryObject
- ZwQueryDirectoryObject
- ObReferenceObjectByName
- ZwQuerySystemInformation
- __C_specific_handler
- MmHighestUserAddress
- IoDriverObjectType
- KeQueryTimeIncrement
- KeStackAttachProcess
- KeUnstackDetachProcess
- PsGetProcessWow64Process
- PsGetProcessPeb
- MmUnlockPages
- MmGetSystemRoutineAddress
- MmUnmapLockedPages
- IoFreeMdl
- ZwTerminateProcess
- PsGetProcessImageFileName
- ObOpenObjectByPointer
- PsReferenceProcessFilePointer
- IoQueryFileDosDeviceName
- ZwQueryVirtualMemory
- MmProbeAndLockPages
- PsLookupProcessByProcessId
- MmMapLockedPagesSpecifyCache
- IoAllocateMdl
- IoGetCurrentProcess
- MmCopyVirtualMemory
- KeClearEvent
- KeSetEvent
- KeWaitForSingleObject
- MmMapLockedPages
- ObReferenceObjectByHandle
- PsSetCreateProcessNotifyRoutineEx
- PsSetCreateThreadNotifyRoutine
- PsRemoveCreateThreadNotifyRoutine
- PsSetLoadImageNotifyRoutine
- PsRemoveLoadImageNotifyRoutine
- ExEventObjectType
- ObRegisterCallbacks
- ObUnRegisterCallbacks
- ObGetFilterVersion
- IoThreadToProcess
- strcmp
- PsProcessType
- PsThreadType
- RtlGetVersion
- ObfReferenceObject
- ObGetObjectType
- ExEnumHandleTable
- ExfUnblockPushLock
- _snprintf
- vsprintf_s
- ZwCreateFile
- ZwWriteFile
- PsLookupThreadByThreadId
- NtQueryInformationThread
- PsGetThreadProcess
- DbgPrint
- KeDelayExecutionThread
- KdDisableDebugger
- KdChangeOption
- PsCreateSystemThread
- PsTerminateSystemThread
- KdDebuggerEnabled
- PsGetVersion
- KeInitializeEvent
- RtlCopyUnicodeString
- ObfDereferenceObject
- ExReleaseFastMutex
- ExAcquireFastMutex
- MmBuildMdlForNonPagedPool
- WdfVersionBindClass
- WdfVersionBind
- WdfVersionUnbind
- WdfVersionUnbindClass
Exported Functions
Expand
Sections
Expand
- .text
- .rdata
- .data
- .pdata
- PAGE
- INIT
- .upx0
- .reloc
- .rsrc
Signature
Expand
last_updated: 2024-09-26