9a4fb66e-9084-4b21-9d76-a7afbe330606
AMDPowerProfiler.sys
Description
AMDPowerProfiler.sys is a vulnerable driver and more information will be added as found.
This download link contains the vulnerable driver!
Commands
sc.exe create AMDPowerProfiler.sys binPath=C:\windows\temp\AMDPowerProfiler.sys type=kernel && sc.exe start AMDPowerProfiler.sys
Use Case | Privileges | Operating System |
---|---|---|
Elevate privileges | kernel | Windows 10 |
Detections
YARA 🏹
Expand
with header and size limitation
without header and size limitation
for renamed driver files
Resources
Known Vulnerable Samples
Property | Value |
---|---|
Filename | AMDPowerProfiler.sys |
Creation Timestamp | 2021-07-26 10:06:46 |
MD5 | e4266262a77fffdea2584283f6c4f51d |
SHA1 | b480c54391a2a2f917a44f91a5e9e4590648b332 |
SHA256 | 0af5ccb3d33a9ba92071c9637be6254030d61998733a5eb3583e865e17844e05 |
Authentihash MD5 | 7ed9c787e267b2606441010b65767771 |
Authentihash SHA1 | 07a5aac8abb0a85822bf792607b9e90914b454dc |
Authentihash SHA256 | e1d3963c55c7ffa96d16e47ec4bbb4e171f828650ce853eb0b83c90ae9c6265a |
RichPEHeaderHash MD5 | f738aebbde053d70ac80a3e913b2205a |
RichPEHeaderHash SHA1 | 5a6f2f340be31f31d82d22202b4489fc1fb03893 |
RichPEHeaderHash SHA256 | 878dda98771551824d963e08ecadef9233c5854b143d5c1d9d42c05620c8cd73 |
Company | Advanced Micro Devices, Inc. |
Description | AMD Power Profiling Driver |
Product | AMD uProf |
OriginalFilename | AMDPowerProfiler.sys |
Certificates
Expand
Certificate 0d424ae0be3a88ff604021ce1400f0dd
Field | Value |
---|---|
ToBeSigned (TBS) MD5 | c0189c338449a42fe8358c2c1fbecc60 |
ToBeSigned (TBS) SHA1 | b8ac0ee6875594b80ad86a6df6dd1fa3048c187c |
ToBeSigned (TBS) SHA256 | a43de6baf968a942da017b70769fdb65b3cfb1bbca1f9174da26a7d8aae78ec5 |
Subject | C=US, O=DigiCert, Inc., CN=DigiCert Timestamp 2021 |
ValidFrom | 2021-01-01 00:00:00 |
ValidTo | 2031-01-06 00:00:00 |
Signature | 481cdcb5e99a23bce71ae7200e8e6746fd427251740a2347a3ab92d225c47059be14a0e52781a54d1415190779f0d104c386d93bbdfe4402664ded69a40ff6b870cf62e8f5514a7879367a27b7f3e7529f93a7ed439e7be7b4dd412289fb87a246034efcf4feb76477635f2352698382fa1a53ed90cc8da117730df4f36539704bf39cd67a7bda0cbc3d32d01bcbf561fc75080076bc810ef8c0e15ccfc41172e71b6449d8229a751542f52d323881daf460a2bab452fb5ce06124254fb2dfc929a8734351dabd63d61f5b9bf72e1b4f131df74a0d717e97b7f43f84ebc1e3a349a1facea7bf56cfba597661895f7ea7b48e6778f93698e1cb28da5b87a68a2f |
SignatureAlgorithmOID | 1.2.840.113549.1.1.11 |
IsCertificateAuthority | False |
SerialNumber | 0d424ae0be3a88ff604021ce1400f0dd |
Version | 3 |
Certificate 0aa125d6d6321b7e41e405da3697c215
Field | Value |
---|---|
ToBeSigned (TBS) MD5 | 8d26184fc613f89aba1cefb30fce1b53 |
ToBeSigned (TBS) SHA1 | 63a7e376bad5ec2e419d514a403bcf46c8d31d95 |
ToBeSigned (TBS) SHA256 | 56b5f0d9db578e3f142921daa387902722a76700375c7e1c4ae0ba004bacaa0c |
Subject | C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Assured ID Timestamping CA |
ValidFrom | 2016-01-07 12:00:00 |
ValidTo | 2031-01-07 12:00:00 |
Signature | 719512e951875669cdefddda7caa637ab378cf06374084ef4b84bfcacf0302fdc5a7c30e20422caf77f32b1f0c215a2ab705341d6aae99f827a266bf09aa60df76a43a930ff8b2d1d87c1962e85e82251ec4ba1c7b2c21e2d65b2c1435430468b2db7502e072c798d63c64e51f4810185f8938614d62462487638c91522caf2989e5781fd60b14a580d7124770b375d59385937eb69267fb536189a8f56b96c0f458690d7cc801b1b92875b7996385228c61ca79947e59fc8c0fe36fb50126b66ca5ee875121e458609bba0c2d2b6da2c47ebbc4252b4702087c49ae13b6e17c424228c61856cf4134b6665db6747bf55633222f2236b24ba24a95d8f5a68e52 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.11 |
IsCertificateAuthority | True |
SerialNumber | 0aa125d6d6321b7e41e405da3697c215 |
Version | 3 |
Certificate 535091e6cab13af393b51ead0825f627
Field | Value |
---|---|
ToBeSigned (TBS) MD5 | f2f60243e26dcdf4729d28b1beb55f01 |
ToBeSigned (TBS) SHA1 | a23ac91136dd79d77b93b12c813e0c6669ed9f4d |
ToBeSigned (TBS) SHA256 | 192ee517f8ae928808632422a6461613d65ee324fa58d2f099a27a3d0da9ca6b |
Subject | C=US, ST=California, L=Santa Clara, O=Advanced Micro Devices Inc., CN=Advanced Micro Devices Inc. |
ValidFrom | 2021-05-11 00:00:00 |
ValidTo | 2024-05-10 23:59:59 |
Signature | 8444e268ff381c9148985f408e5cc1453a560c9dd94d2a6cfa01dd7f2adc8af633053d2c79027db4f185f477b0d5db8b362b37dbd0d258823831ace7058baf3feb80a9eb2de9dd886bcf390fae9b586fc833e63db5c6a07019f35a9fce6899502852737b32d25ea7832c3786df0642d21622e56c0b0171e96f9520d07f73950376ff555bcf9c8a55bf4f86c088b58e2cb625a0ef4680ed7281f09a40c7be9f69cba77a6967030e39b2cfa46692698ced9e5347dd7056b476545c3442f934cb2c30cb986afabd29a9a9e2eb28c5bd6ee47dabf5ef587f850ea49b124eb868aac68de949616d08f875192b93388549c7327a3ef085e287d5a743810c151b250c64 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.11 |
IsCertificateAuthority | False |
SerialNumber | 535091e6cab13af393b51ead0825f627 |
Version | 3 |
Certificate 3972443af922b751d7d36c10dd313595
Field | Value |
---|---|
ToBeSigned (TBS) MD5 | 3f5b269ded03667a7bad47c1885062b0 |
ToBeSigned (TBS) SHA1 | 0f01247aaf8b46e3617880e0f5f5dfac696ed7a3 |
ToBeSigned (TBS) SHA256 | 593e2d49a74023555526aef9b7422b19e5b8b167391b6dee5ed292b1ca23a74c |
Subject | C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority |
ValidFrom | 2019-03-12 00:00:00 |
ValidTo | 2028-12-31 23:59:59 |
Signature | 188751dc74213d9c8ae027b733d02eccecf0e6cb5e11de226f9b758e9e72fee4d6feaa1f9c962def034a7eaef48d6f723c433bc03febb8df5caaa9c6aef2fcd8eea37b43f686367c14e0cdf4f73ffedeb8b48af09196fefd43647efdccd201a17d7df81919c9422b13bf588bbaa4a266047688914e0c8914cea24dc932b3bae8141abc71f15bf0410b98000a220310e50cb1f9cd923719ed3bf1e43ab6f945132675afbbaaef3f7b773bd2c402913d1900d3175c39db3f7b180d45cd9385962f5ddf59164f3f51bdd545183fed4a8ee80661742316b50d50732744477f105d892a6b853114c4e8a96a4c80bc6a78cfb87f8e7672990c9dfed7910816a1a35f95 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.12 |
IsCertificateAuthority | True |
SerialNumber | 3972443af922b751d7d36c10dd313595 |
Version | 3 |
Certificate 1da248306f9b2618d082e0967d33d36a
Field | Value |
---|---|
ToBeSigned (TBS) MD5 | c1eabfb5994258ad955adb7c2df165e6 |
ToBeSigned (TBS) SHA1 | fa33b3c00cebc469b269220d9eab26926c9b8ad8 |
ToBeSigned (TBS) SHA256 | 70dffac37eb787b2198816982c7d44f541d2e39a7dac069d37b367dc9f354b32 |
Subject | C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Code Signing CA |
ValidFrom | 2018-11-02 00:00:00 |
ValidTo | 2030-12-31 23:59:59 |
Signature | 4d6350ed47344a61a4dbde6a2a8c9bf100001e1d627b3ad732c2f6b3e063b3fb6100889a1b6d1007044fbeb8ea897822eb0f46ecf3465e40468912f40b775a9c2a413afcd6f4ebe7f7159533c3a18328b7de2fe494f78533832d4a4048bf9ac24f4ab18f24f4b38137d3b764b0a6236a596852425fff04ebe174657908f5a993de6b71409996ba78f1b9c8e2c30816b1ab635ac815806d745e4a757ea5b8c36cb5cfdf4a79875cc7404d6335f630d3cfb50a0e0b047fa04baebba3a5d08400933e535d34a50035696cbe9f2025100d19fb509061be398f7a8e4df69f0e1efe075112668326194895ce4ac9c17ff33a059bf96fdf887fc0239ed21e437a4531c19c4da9f059b25919e86a8d290402777c4b4bcd70be3ab2555a783ebcbb6f0310257715348af936cc4392e4ba4ff1629328255729fb5119c7a125406a8457c6b29db1bc1c0ada7c677e7d2ee9284c187ec47b3141719a4b29ec0b3d5750d2caddfd9e0551e54478dd01deb175980d5424fdf04ee3e2f883bd72bacb3d3aeef05e1792686dc861f9a6f12a0a0ba5b9f49eee983205859eebf98329d3c62c7dbd3a772e8b3742a06a82ed3b4aaa9410a4e10df817c5b65a79331892e3b575f8a1e98e0a251ee41ef19f5a8723ff9fa4519efb398011cddbb5c4a7a8806fe553d4e0e3a2c2d25b1afa32262d6a57701c3ca4582ea3f35b4b07dc3259f387a71a6d58 |
SignatureAlgorithmOID | 1.2.840.113549.1.1.12 |
IsCertificateAuthority | True |
SerialNumber | 1da248306f9b2618d082e0967d33d36a |
Version | 3 |
Imports
Expand
- AMDPCore.SYS
- ntoskrnl.exe
- HAL.dll
Imported Functions
Expand
- PcoreRemoveAllConfigurations
- PcoreIsLoaded
- PcoreAddConfiguration
- PcoreUnregister
- PcoreVersion
- PcoreRegister
- PcoreGetResourceCount
- KeGetProcessorNumberFromIndex
- KeInitializeDpc
- KeSetTargetProcessorDpcEx
- MmMapIoSpace
- MmUnmapIoSpace
- KeQueryActiveGroupCount
- KeSetEvent
- ExAllocatePoolWithTag
- ExFreePoolWithTag
- KeInitializeEvent
- KeWaitForSingleObject
- KeQueryActiveProcessorCountEx
- ExSystemTimeToLocalTime
- KeGetCurrentProcessorNumberEx
- RtlInitUnicodeString
- IoDeleteDevice
- IoDeleteSymbolicLink
- RtlGetVersion
- IofCompleteRequest
- IoCreateSymbolicLink
- MmUnlockPages
- PsRemoveLoadImageNotifyRoutine
- ZwOpenSection
- ZwUnmapViewOfSection
- MmProbeAndLockPages
- PsSetLoadImageNotifyRoutine
- ObfDereferenceObject
- IoAllocateMdl
- PsRemoveCreateThreadNotifyRoutine
- ZwMapViewOfSection
- ObReferenceObjectByHandle
- IoFreeMdl
- MmIsAddressValid
- PsSetCreateThreadNotifyRoutine
- PsSetCreateProcessNotifyRoutine
- ZwClose
- IoSizeofWorkItem
- ZwQueryVolumeInformationFile
- IoQueryFileDosDeviceName
- IoInitializeWorkItem
- IoQueueWorkItemEx
- ObfReferenceObject
- IoUninitializeWorkItem
- ZwOpenFile
- IoIs32bitProcess
- MmGetSystemRoutineAddress
- ZwSetSecurityObject
- IoDeviceObjectType
- IoCreateDevice
- ObOpenObjectByPointer
- RtlGetDaclSecurityDescriptor
- RtlGetGroupSecurityDescriptor
- RtlGetOwnerSecurityDescriptor
- RtlGetSaclSecurityDescriptor
- SeCaptureSecurityDescriptor
- _snwprintf
- RtlLengthSecurityDescriptor
- SeExports
- RtlCreateSecurityDescriptor
- _wcsnicmp
- wcschr
- RtlAbsoluteToSelfRelativeSD
- RtlAddAccessAllowedAce
- RtlLengthSid
- IoIsWdmVersionAvailable
- RtlSetDaclSecurityDescriptor
- ZwOpenKey
- ZwSetValueKey
- ZwQueryValueKey
- ZwCreateKey
- RtlFreeUnicodeString
- KeBugCheckEx
- KeInsertQueueDpc
- KeSetImportanceDpc
- DbgPrint
- MmMapLockedPagesSpecifyCache
- RtlIsNtDdiVersionAvailable
- ZwCreateFile
- ZwWriteFile
- __C_specific_handler
- strcmp
- KeQueryPerformanceCounter
- HalAllocateHardwareCounters
- HalFreeHardwareCounters
Exported Functions
Expand
Sections
Expand
- .text
- .rdata
- .data
- .pdata
- .gfids
- PAGE
- INIT
- .rsrc
- .reloc
Signature
Expand
{
"Certificates": [
{
"IsCertificateAuthority": false,
"SerialNumber": "0d424ae0be3a88ff604021ce1400f0dd",
"Signature": "481cdcb5e99a23bce71ae7200e8e6746fd427251740a2347a3ab92d225c47059be14a0e52781a54d1415190779f0d104c386d93bbdfe4402664ded69a40ff6b870cf62e8f5514a7879367a27b7f3e7529f93a7ed439e7be7b4dd412289fb87a246034efcf4feb76477635f2352698382fa1a53ed90cc8da117730df4f36539704bf39cd67a7bda0cbc3d32d01bcbf561fc75080076bc810ef8c0e15ccfc41172e71b6449d8229a751542f52d323881daf460a2bab452fb5ce06124254fb2dfc929a8734351dabd63d61f5b9bf72e1b4f131df74a0d717e97b7f43f84ebc1e3a349a1facea7bf56cfba597661895f7ea7b48e6778f93698e1cb28da5b87a68a2f",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, O=DigiCert, Inc., CN=DigiCert Timestamp 2021",
"TBS": {
"MD5": "c0189c338449a42fe8358c2c1fbecc60",
"SHA1": "b8ac0ee6875594b80ad86a6df6dd1fa3048c187c",
"SHA256": "a43de6baf968a942da017b70769fdb65b3cfb1bbca1f9174da26a7d8aae78ec5",
"SHA384": "76d3a316a5a106050298418cce3beea16100524723d9e3220b0de51bfb6f1c35a5d4c7cd10b358fef7bf94c3e3562150"
},
"ValidFrom": "2021-01-01 00:00:00",
"ValidTo": "2031-01-06 00:00:00",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "0aa125d6d6321b7e41e405da3697c215",
"Signature": "719512e951875669cdefddda7caa637ab378cf06374084ef4b84bfcacf0302fdc5a7c30e20422caf77f32b1f0c215a2ab705341d6aae99f827a266bf09aa60df76a43a930ff8b2d1d87c1962e85e82251ec4ba1c7b2c21e2d65b2c1435430468b2db7502e072c798d63c64e51f4810185f8938614d62462487638c91522caf2989e5781fd60b14a580d7124770b375d59385937eb69267fb536189a8f56b96c0f458690d7cc801b1b92875b7996385228c61ca79947e59fc8c0fe36fb50126b66ca5ee875121e458609bba0c2d2b6da2c47ebbc4252b4702087c49ae13b6e17c424228c61856cf4134b6665db6747bf55633222f2236b24ba24a95d8f5a68e52",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Assured ID Timestamping CA",
"TBS": {
"MD5": "8d26184fc613f89aba1cefb30fce1b53",
"SHA1": "63a7e376bad5ec2e419d514a403bcf46c8d31d95",
"SHA256": "56b5f0d9db578e3f142921daa387902722a76700375c7e1c4ae0ba004bacaa0c",
"SHA384": "d8c9691fe9dbe182f07b49b07fbb4f589fa7b38b5c4d21f265d3a2e818f4b1bfb39e03faab2ec05bb10333a99914fb8a"
},
"ValidFrom": "2016-01-07 12:00:00",
"ValidTo": "2031-01-07 12:00:00",
"Version": 3
},
{
"IsCertificateAuthority": false,
"SerialNumber": "535091e6cab13af393b51ead0825f627",
"Signature": "8444e268ff381c9148985f408e5cc1453a560c9dd94d2a6cfa01dd7f2adc8af633053d2c79027db4f185f477b0d5db8b362b37dbd0d258823831ace7058baf3feb80a9eb2de9dd886bcf390fae9b586fc833e63db5c6a07019f35a9fce6899502852737b32d25ea7832c3786df0642d21622e56c0b0171e96f9520d07f73950376ff555bcf9c8a55bf4f86c088b58e2cb625a0ef4680ed7281f09a40c7be9f69cba77a6967030e39b2cfa46692698ced9e5347dd7056b476545c3442f934cb2c30cb986afabd29a9a9e2eb28c5bd6ee47dabf5ef587f850ea49b124eb868aac68de949616d08f875192b93388549c7327a3ef085e287d5a743810c151b250c64",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, ST=California, L=Santa Clara, O=Advanced Micro Devices Inc., CN=Advanced Micro Devices Inc.",
"TBS": {
"MD5": "f2f60243e26dcdf4729d28b1beb55f01",
"SHA1": "a23ac91136dd79d77b93b12c813e0c6669ed9f4d",
"SHA256": "192ee517f8ae928808632422a6461613d65ee324fa58d2f099a27a3d0da9ca6b",
"SHA384": "beb93a1ff1715564a418ecb07cee42465dbf9c76cc703e7088bdafb2099b003afa0c335bcd15d318dcb2bf8519c199da"
},
"ValidFrom": "2021-05-11 00:00:00",
"ValidTo": "2024-05-10 23:59:59",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "3972443af922b751d7d36c10dd313595",
"Signature": "188751dc74213d9c8ae027b733d02eccecf0e6cb5e11de226f9b758e9e72fee4d6feaa1f9c962def034a7eaef48d6f723c433bc03febb8df5caaa9c6aef2fcd8eea37b43f686367c14e0cdf4f73ffedeb8b48af09196fefd43647efdccd201a17d7df81919c9422b13bf588bbaa4a266047688914e0c8914cea24dc932b3bae8141abc71f15bf0410b98000a220310e50cb1f9cd923719ed3bf1e43ab6f945132675afbbaaef3f7b773bd2c402913d1900d3175c39db3f7b180d45cd9385962f5ddf59164f3f51bdd545183fed4a8ee80661742316b50d50732744477f105d892a6b853114c4e8a96a4c80bc6a78cfb87f8e7672990c9dfed7910816a1a35f95",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.12",
"Subject": "C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority",
"TBS": {
"MD5": "3f5b269ded03667a7bad47c1885062b0",
"SHA1": "0f01247aaf8b46e3617880e0f5f5dfac696ed7a3",
"SHA256": "593e2d49a74023555526aef9b7422b19e5b8b167391b6dee5ed292b1ca23a74c",
"SHA384": "13baa039635f1c5292a8c2f36aae7e1d25c025202e9092f5b0f53f5f752dfa9c71b3d1b8d9a6358fcee6ec75622fabf9"
},
"ValidFrom": "2019-03-12 00:00:00",
"ValidTo": "2028-12-31 23:59:59",
"Version": 3
},
{
"IsCertificateAuthority": true,
"SerialNumber": "1da248306f9b2618d082e0967d33d36a",
"Signature": "4d6350ed47344a61a4dbde6a2a8c9bf100001e1d627b3ad732c2f6b3e063b3fb6100889a1b6d1007044fbeb8ea897822eb0f46ecf3465e40468912f40b775a9c2a413afcd6f4ebe7f7159533c3a18328b7de2fe494f78533832d4a4048bf9ac24f4ab18f24f4b38137d3b764b0a6236a596852425fff04ebe174657908f5a993de6b71409996ba78f1b9c8e2c30816b1ab635ac815806d745e4a757ea5b8c36cb5cfdf4a79875cc7404d6335f630d3cfb50a0e0b047fa04baebba3a5d08400933e535d34a50035696cbe9f2025100d19fb509061be398f7a8e4df69f0e1efe075112668326194895ce4ac9c17ff33a059bf96fdf887fc0239ed21e437a4531c19c4da9f059b25919e86a8d290402777c4b4bcd70be3ab2555a783ebcbb6f0310257715348af936cc4392e4ba4ff1629328255729fb5119c7a125406a8457c6b29db1bc1c0ada7c677e7d2ee9284c187ec47b3141719a4b29ec0b3d5750d2caddfd9e0551e54478dd01deb175980d5424fdf04ee3e2f883bd72bacb3d3aeef05e1792686dc861f9a6f12a0a0ba5b9f49eee983205859eebf98329d3c62c7dbd3a772e8b3742a06a82ed3b4aaa9410a4e10df817c5b65a79331892e3b575f8a1e98e0a251ee41ef19f5a8723ff9fa4519efb398011cddbb5c4a7a8806fe553d4e0e3a2c2d25b1afa32262d6a57701c3ca4582ea3f35b4b07dc3259f387a71a6d58",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.12",
"Subject": "C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Code Signing CA",
"TBS": {
"MD5": "c1eabfb5994258ad955adb7c2df165e6",
"SHA1": "fa33b3c00cebc469b269220d9eab26926c9b8ad8",
"SHA256": "70dffac37eb787b2198816982c7d44f541d2e39a7dac069d37b367dc9f354b32",
"SHA384": "20adc5b59cb532e215f01ba09a9c745898c206555613512fea7c295ccfd17ced4fe2c5bc3274ca8a270fc68799b8343c"
},
"ValidFrom": "2018-11-02 00:00:00",
"ValidTo": "2030-12-31 23:59:59",
"Version": 3
}
],
"CertificatesInfo": "",
"Signer": [
{
"Issuer": "C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Code Signing CA",
"SerialNumber": "535091e6cab13af393b51ead0825f627",
"Version": 1
}
],
"SignerInfo": ""
}
last_updated: 2024-09-26