2.sys
- Driver Name
2.sys- SpcSpOpusInfo
N/A- MD5
1e5cd320e9a8f8fa1b976ffe54cebd8a- SHA1
cb7d4a1ec8964c81ec81e937ffe9b812cfb6cc81- SHA256
26fbfbca729ff07f5210ff30b4b7a453b6d9da11f46aed277272d33a2c06d912- Imphash
2d9361d9b1ba51deb57c1de0cfe2768d- Vhash
03407666151d15165519z16z2bxz- Authentihash
1d1e891c375c64560c14683adfd0346a1d6939d34935dd135bd08bb815035feb- Rich PE header hash
N/A- SSDEEP
384:nkKYhgDwcfsHGaWGj6F7uqj5PBGykuG0IdXVuu446rrgc2mNDGLWpy8RbmL4nNyI:tY6wzWpz/GkG0Id3xuBhoo5AL6- TLSH
T11E039DA1C55168F6F91BD9B8D1F5043FEAB1B1846751C6CF2120C4AD0FA3FD22A3E1A9- PDB path
N/A- Compilation time
2026-08-31- Country submitter
- N/A
Description
A kernel rootkit that hooks syscalls through ETW.
It switches on Windows' Circular Kernel Context Logger with the SYSTEMCALL flag, so the kernel fires an ETW event on every syscall, then hijacks that session's clock callback. On each call, it finds the syscall dispatcher's frame on the kernel stack and rewrites the stack copy of the service-routine pointer.
It hooks four syscalls:
• NtQuerySystemInformation
• NtOpenProcess
• NtReadFile
• NtWriteFile
It also deletes itself from disk after installing the hook.