d3111e83-52eb-4a8c-817d-761ea72d37e2
fgme.sys
We were not able to verify the hash of this driver successfully, it has not been confirmed.
Description
BlackCat Ransomware Deploys New Signed Kernel Driver. BlackCat ransomware incident that occurred in February 2023.
Commands
sc.exe create fgme.sys binPath=C:\windows\temp\fgme.sys type=kernel && sc.exe start fgme.sys
Use Case | Privileges | Operating System |
---|---|---|
Elevate privileges | kernel | Windows 10 |
Detections
YARA 🏹
Resources
Known Vulnerable Samples
Property | Value |
---|---|
Filename | fgme.sys |
Creation Timestamp | |
MD5 | |
SHA1 | 0bec69c1b22603e9a385495fbe94700ac36b28e5 |
SHA256 |
Imports
Expand
Imported Functions
Expand
Exported Functions
Expand
Sections
Expand
Signature
Expand
last_updated: 2024-09-26