← Back to malicious drivers

2.sys

Malicious Xue Sun 02:12 PM 08/31/2026
Driver Name
2.sys
SpcSpOpusInfo
N/A
MD5
1e5cd320e9a8f8fa1b976ffe54cebd8a
SHA1
cb7d4a1ec8964c81ec81e937ffe9b812cfb6cc81
SHA256
26fbfbca729ff07f5210ff30b4b7a453b6d9da11f46aed277272d33a2c06d912
Imphash
2d9361d9b1ba51deb57c1de0cfe2768d
Vhash
03407666151d15165519z16z2bxz
Authentihash
1d1e891c375c64560c14683adfd0346a1d6939d34935dd135bd08bb815035feb
Rich PE header hash
N/A
SSDEEP
384:nkKYhgDwcfsHGaWGj6F7uqj5PBGykuG0IdXVuu446rrgc2mNDGLWpy8RbmL4nNyI:tY6wzWpz/GkG0Id3xuBhoo5AL6
TLSH
T11E039DA1C55168F6F91BD9B8D1F5043FEAB1B1846751C6CF2120C4AD0FA3FD22A3E1A9
PDB path
N/A
Compilation time
2026-08-31
Country submitter
N/A

Description

A kernel rootkit that hooks syscalls through ETW.

It switches on Windows' Circular Kernel Context Logger with the SYSTEMCALL flag, so the kernel fires an ETW event on every syscall, then hijacks that session's clock callback. On each call, it finds the syscall dispatcher's frame on the kernel stack and rewrites the stack copy of the service-routine pointer.

It hooks four syscalls:

• NtQuerySystemInformation

• NtOpenProcess

• NtReadFile

• NtWriteFile

It also deletes itself from disk after installing the hook.