← Back to malicious drivers

4.sys

Malicious Xue Sun 02:57 PM 08/31/2026
Driver Name
4.sys
SpcSpOpusInfo
N/A
MD5
2e32563fab90260a2b339288be900740
SHA1
d194b830048c0350017f74c4d538caa761635f19
SHA256
8b778ca89f79447e25ad74253157e58437d30ce59a452b3627da901cde4d0787
Imphash
2d9361d9b1ba51deb57c1de0cfe2768d
Vhash
03407666151d15165519z16z2bxz
Authentihash
f0555a6f6d615f1e994ef841d10114e3c12414fd89c257b6e90572b6bfdbaefb
Rich PE header hash
N/A
SSDEEP
768:lYMnNW2D/GzeXUG0IdixuBh8nAHD5AL+8:2cyeXndiCqAf8
TLSH
T16A039E91C5516CE6F91ADAB8D1F5043FEAB0B1847751C9CF2120C4AD1FA3BD22A3E1A9
PDB path
N/A
Compilation time
2026-08-31
Country submitter
N/A

Description

A kernel rootkit that hooks syscalls through ETW.

It switches on Windows' Circular Kernel Context Logger with the SYSTEMCALL flag, so the kernel fires an ETW event on every syscall, then hijacks that session's clock callback. On each call, it finds the syscall dispatcher's frame on the kernel stack and rewrites the stack copy of the service-routine pointer.

It hooks four syscalls:

• NtQuerySystemInformation

• NtOpenProcess

• NtReadFile

• NtWriteFile

It also deletes itself from disk after installing the hook.