eef1fcf4-8c54-420b-8d38-9c5f95129dcc
ntbios.sys
Description
Driver used in the Daxin malware campaign.
This download link contains the malicious driver!
Commands
sc.exe create ntbios.sys binPath=C:\windows\temp \n \n \n tbios.sys type=kernel && sc.exe start ntbios.sys
Use Case | Privileges | Operating System |
---|---|---|
Elevate privileges | kernel | Windows 10 |
Detections
YARA 🏹
Resources
Known Vulnerable Samples
Property | Value |
---|---|
Filename | ntbios.sys |
Creation Timestamp | 2009-11-19 03:26:14 |
MD5 | 14580bd59c55185115fd3abe73b016a2 |
SHA1 | 71469dce9c2f38d0e0243a289f915131bf6dd2a8 |
SHA256 | 96bf3ee7c6673b69c6aa173bb44e21fa636b1c2c73f4356a7599c121284a51cc |
Authentihash MD5 | dd3f6fe14dadb95f5d8c963006dec9d7 |
Authentihash SHA1 | 2374491565e5798dccd4db2dc2af7e9bbefafd5b |
Authentihash SHA256 | 50f9323eaf7c49cfca5890c6c46d729574d0caca89f7acc9f608c8226f54a975 |
RichPEHeaderHash MD5 | ebd225fe8cf34907033d6b6123047339 |
RichPEHeaderHash SHA1 | 642936e6d95c6231c8427a1c7a76dd99910fc635 |
RichPEHeaderHash SHA256 | b04e0a7d507b0838174bb9df686e4ce60c5b81e183867441ed5951a5d3555510 |
Publisher | n/a |
Company | Microsoft Corporation |
Description | ntbios driver |
Product | Microsoft(R) Windows (R) NT Operating System |
OriginalFilename | ntbios.sys |
Imports
Expand
- NTOSKRNL.EXE
- HAL.DLL
- ntoskrnl.exe
- NDIS.SYS
Imported Functions
Expand
- MmUnlockPages
- MmProbeAndLockPages
- IoAllocateMdl
- IoQueueWorkItem
- IoAllocateWorkItem
- IoGetCurrentProcess
- _stricmp
- IoFreeWorkItem
- RtlFreeUnicodeString
- ZwClose
- ZwWriteFile
- ZwCreateFile
- RtlAnsiStringToUnicodeString
- _strnicmp
- RtlUnwind
- RtlCopyUnicodeString
- wcsncmp
- swprintf
- IoCreateDevice
- IoCreateSymbolicLink
- KeInitializeSpinLock
- ExfInterlockedInsertTailList
- RtlInitUnicodeString
- MmMapLockedPagesSpecifyCache
- IoFreeMdl
- InterlockedDecrement
- InterlockedIncrement
- InterlockedExchange
- IoDeleteSymbolicLink
- IoDeleteDevice
- ExfInterlockedRemoveHeadList
- IofCompleteRequest
- ExAllocatePoolWithTag
- strncmp
- ExFreePool
- KfAcquireSpinLock
- KfReleaseSpinLock
- KeInitializeApc
- KeInsertQueueApc
- KeAttachProcess
- KeDetachProcess
- NtQuerySystemInformation
- NdisAllocatePacket
- NdisCopyFromPacketToPacket
- NdisAllocateMemory
- NdisFreePacket
- NdisAllocateBuffer
- NdisSetEvent
- NdisResetEvent
- NdisFreeBufferPool
- NdisFreePacketPool
- NdisFreeMemory
- NdisWaitEvent
- NdisQueryAdapterInstanceName
- NdisOpenAdapter
- NdisInitializeEvent
- NdisAllocatePacketPool
- NdisRegisterProtocol
- NdisAllocateBufferPool
- NdisCloseAdapter
- NdisDeregisterProtocol
Exported Functions
Expand
Sections
Expand
- .text
- .rdata
- .data
- INIT
- .rsrc
- .reloc
Signature
Expand
last_updated: 2024-09-26