← Back to malicious drivers

1.sys

Malicious Xue Sun 02:46 PM 08/31/2026
Driver Name
1.sys
SpcSpOpusInfo
N/A
MD5
adbaa97ab2f82bf409c1784c1208833b
SHA1
7bb66fc255eebc153a70cc0e4da033ea5a6d4eab
SHA256
9d3042dea2f7356aefb042cf7da20060147af84f0e9263b94f56cdc8d96348b9
Imphash
2d9361d9b1ba51deb57c1de0cfe2768d
Vhash
03407666151d15165519z16z2bxz
Authentihash
182bfb2781c7e784b7c461013985355b9edd56b36a236af77f19f3ebec6e4a77
Rich PE header hash
N/A
SSDEEP
384:zkKYmgBgc/MBqKWTlvuqj5PBGJkuG0IdX2uu446rrgc2mNDGSlVy8RbmL4nNyrhB:JY/gxWxn/G7G0IdwxuBhoC5ALqE
TLSH
T1EA039DA1C55159E6F91ADEB8D1F4453BFAB1B0846342CACF2120C4ED0FB3BD2263D1A9
PDB path
N/A
Compilation time
2026-08-31
Country submitter
N/A

Description

A kernel rootkit that hooks syscalls through ETW.

It switches on Windows' Circular Kernel Context Logger with the SYSTEMCALL flag, so the kernel fires an ETW event on every syscall, then hijacks that session's clock callback. On each call, it finds the syscall dispatcher's frame on the kernel stack and rewrites the stack copy of the service-routine pointer.

It hooks four syscalls:

• NtQuerySystemInformation

• NtOpenProcess

• NtReadFile

• NtWriteFile

It also deletes itself from disk after installing the hook.