2.sys
- Driver Name
2.sys- SpcSpOpusInfo
成都彩程软件设计有限公司; 广州思迈特软件有限公司; 华义控股(北京)有限公司; 播氪(杭州)软件有限公司; 上海信数科技有限公司; 福州熵合驱动科技有限公司; 上海寻梦信息技术有限公司; 汇智道晟(杭州)软件有限公司; 重庆云联融智科技有限公司; 郑州谦翔信息技术有限公司; 东方瀚宇科技有限公司- MD5
3916a8f931b2be5bb4762490635d8560- SHA1
4be487d0ab57df126262fd147160622595e64794- SHA256
5e89beed2d6f6231e3dd1ed07f04aa15a401eeaec39a0b6ec56261665a3b4b06- Imphash
2d9361d9b1ba51deb57c1de0cfe2768d- Vhash
01507666151d15165519z16z2bxz- Authentihash
8c671869c51fa33dba2b7e5e6a69950430a754280765e96980249e21c27300c2- Rich PE header hash
N/A- SSDEEP
3072:NdFuFpPDTvYc5ToavqZMRa4p2TnnznCBl5SE:NsVoA8zO3- TLSH
T1E9044CD645399083EE46AD7083E8EE93BC3D73C72B5189E711AAE5805D873C2E33916D- PDB path
N/A- Compilation time
2026-08-31- Country submitter
- N/A
Description
A kernel rootkit that hooks syscalls through ETW.
It switches on Windows' Circular Kernel Context Logger with the SYSTEMCALL flag, so the kernel fires an ETW event on every syscall, then hijacks that session's clock callback. On each call, it finds the syscall dispatcher's frame on the kernel stack and rewrites the stack copy of the service-routine pointer.
It hooks four syscalls:
• NtQuerySystemInformation
• NtOpenProcess
• NtReadFile
• NtWriteFile
It also deletes itself from disk after installing the hook.