7a7630d6-d007-4d84-a17d-81236d9693e1
d.sys
We were not able to verify the hash of this driver successfully, it has not been confirmed.
Description
d.sys is a vulnerable driver and more information will be added as found.
This download link contains the vulnerable driver!
Commands
sc.exe create d.sys binPath=C:\windows\temp\d.sys type=kernel && sc.exe start d.sys
Use Case | Privileges | Operating System |
---|---|---|
Elevate privileges | kernel | Windows 10 |
Detections
YARA 🏹
Expand
with header and size limitation
without header and size limitation
for renamed driver files
Resources
Known Vulnerable Samples
Property | Value |
---|---|
Filename | d.sys |
Creation Timestamp | 2007-06-19 23:46:07 |
MD5 | a60c9173563b940203cf4ad38ccf2082 |
SHA1 | a3636986cdcd1d1cb8ab540f3d5c29dcc90bb8f0 |
SHA256 | c1c4310e5d467d24e864177bdbfc57cb5d29aac697481bfa9c11ddbeebfd4cc8 |
Authentihash MD5 | 19dd018ebddfa9044b05fbb9ddffd7f9 |
Authentihash SHA1 | 80111a99c4f127cca12f1902ca241b3e65f339ff |
Authentihash SHA256 | a4ca4a0932afa09e8df3469768f5ac6feaff2b7ae27ac208a218288fc4fbf102 |
RichPEHeaderHash MD5 | f3e1fc89f2b01c40ea38fc9510166f54 |
RichPEHeaderHash SHA1 | e532da616b3b77c80bdcb3512ea2ed13872d5c52 |
RichPEHeaderHash SHA256 | 7e846d33fc8dd8d0efe1e5aab73002ad4d85b7d714cf1740430761c502b839b3 |
Imports
Expand
- ntoskrnl.exe
- HAL.dll
Imported Functions
Expand
- KeInitializeEvent
- ObReferenceObjectByHandle
- ZwClose
- ObfDereferenceObject
- PsCreateSystemThread
- IoGetCurrentProcess
- _stricmp
- strchr
- ZwCreateFile
- RtlInitUnicodeString
- ZwReadFile
- ZwQueryInformationFile
- KeDetachProcess
- ProbeForRead
- ZwQueryInformationProcess
- KeAttachProcess
- KeLeaveCriticalRegion
- KeEnterCriticalRegion
- ObOpenObjectByName
- KeServiceDescriptorTable
- KeAddSystemServiceTable
- PsGetCurrentProcessId
- ProbeForWrite
- wcsstr
- ObQueryNameString
- IoFileObjectType
- SeSinglePrivilegeCheck
- KeGetPreviousMode
- KeDelayExecutionThread
- ZwAllocateVirtualMemory
- ZwQuerySection
- ExfInterlockedInsertTailList
- ExFreePoolWithTag
- sprintf
- RtlVolumeDeviceToDosName
- IoGetDeviceObjectPointer
- MmSectionObjectType
- strstr
- _strlwr
- PsProcessType
- PsSetCreateProcessNotifyRoutine
- KeInitializeSpinLock
- PsThreadType
- PsTerminateSystemThread
- vsprintf
- KeQuerySystemTime
- ExfInterlockedRemoveHeadList
- NtBuildNumber
- ExAllocatePoolWithTag
- ZwOpenKey
- ZwEnumerateKey
- ZwDeleteKey
- _except_handler3
- swprintf
- _wcsnicmp
- ZwQuerySystemInformation
- PsLookupProcessByProcessId
- wcstombs
- ExAcquireFastMutex
- ExReleaseFastMutex
- KfAcquireSpinLock
- KfReleaseSpinLock
Exported Functions
Expand
Sections
Expand
- .text
- .rdata
- .data
- INIT
- .reloc
Signature
Expand
last_updated: 2024-09-26