4.sys
- Driver Name
4.sys- SpcSpOpusInfo
N/A- MD5
2e32563fab90260a2b339288be900740- SHA1
d194b830048c0350017f74c4d538caa761635f19- SHA256
8b778ca89f79447e25ad74253157e58437d30ce59a452b3627da901cde4d0787- Imphash
2d9361d9b1ba51deb57c1de0cfe2768d- Vhash
03407666151d15165519z16z2bxz- Authentihash
f0555a6f6d615f1e994ef841d10114e3c12414fd89c257b6e90572b6bfdbaefb- Rich PE header hash
N/A- SSDEEP
768:lYMnNW2D/GzeXUG0IdixuBh8nAHD5AL+8:2cyeXndiCqAf8- TLSH
T16A039E91C5516CE6F91ADAB8D1F5043FEAB0B1847751C9CF2120C4AD1FA3BD22A3E1A9- PDB path
N/A- Compilation time
2026-08-31- Country submitter
- N/A
Description
A kernel rootkit that hooks syscalls through ETW.
It switches on Windows' Circular Kernel Context Logger with the SYSTEMCALL flag, so the kernel fires an ETW event on every syscall, then hijacks that session's clock callback. On each call, it finds the syscall dispatcher's frame on the kernel stack and rewrites the stack copy of the service-routine pointer.
It hooks four syscalls:
• NtQuerySystemInformation
• NtOpenProcess
• NtReadFile
• NtWriteFile
It also deletes itself from disk after installing the hook.