833fc08f-217d-4d3f-8c8e-782c61120407
kt2.sys
We were not able to verify the hash of this driver successfully, it has not been confirmed.
Description
BlackCat Ransomware Deploys New Signed Kernel Driver. BlackCat ransomware incident that occurred in February 2023.
Commands
sc.exe create kt2.sys binPath=C:\windows\temp\kt2.sys type=kernel && sc.exe start kt2.sys
Use Case | Privileges | Operating System |
---|---|---|
Elevate privileges | kernel | Windows 10 |
Detections
YARA 🏹
Resources
Known Vulnerable Samples
Property | Value |
---|---|
Filename | kt2.sys |
Creation Timestamp | |
MD5 | |
SHA1 | cb25a5125fb353496b59b910263209f273f3552d |
SHA256 |
Imports
Expand
Imported Functions
Expand
Exported Functions
Expand
Sections
Expand
Signature
Expand
last_updated: 2024-09-26