724d7989-dfce-4bb2-9beb-dee15df5b790
skill.sys
Description
Confirmed vulnerable driver from Microsoft Block List
Use Case | Privileges | Operating System |
---|---|---|
Elevate privileges | kernel | Windows |
Detections
YARA 🏹
Expand
Resources
CVE
Known Vulnerable Samples
Property | Value |
---|---|
Filename | |
Creation Timestamp | 2016-09-05 00:43:33 |
MD5 | 2b36d61f6e7420977648ed27e784adf1 |
SHA1 | c92a386622f04a5733cb238d33cedea4272a3f85 |
SHA256 | 0c1b21978c6aef881f056f7b9c909b56488019459ed256511d78a4588d1aa7a4 |
Authentihash MD5 | 37458813b5115cbf06552da28fefbbbb |
Authentihash SHA1 | 1d1cafc73c97c6bcd2331f8777d90fdca57125a3 |
Authentihash SHA256 | faa08cb609a5b7be6bfdb61f1e4a5e8adf2f5a1d2492f262483df7326934f5d4 |
RichPEHeaderHash MD5 | b2f23c03be4553a744ff25735a80073c |
RichPEHeaderHash SHA1 | 2703d60c8f12df9d6adf5ae475bfeb1786486888 |
RichPEHeaderHash SHA256 | 46ffd109664b6694974986a39d508002d564434d60a0fb9f861401f2cb2c83f1 |
Imports
Expand
- ntoskrnl.exe
Imported Functions
Expand
- IoDeleteSymbolicLink
- RtlInitUnicodeString
- IofCompleteRequest
- MmGetSystemRoutineAddress
- IoCreateSymbolicLink
- IoCreateDevice
- IoDeleteDevice
Exported Functions
Expand
Sections
Expand
- .text
- .data
- .pdata
- .info
- INIT
Signature
Expand
last_updated: 2024-09-26