1.sys
- Driver Name
1.sys- SpcSpOpusInfo
N/A- MD5
adbaa97ab2f82bf409c1784c1208833b- SHA1
7bb66fc255eebc153a70cc0e4da033ea5a6d4eab- SHA256
9d3042dea2f7356aefb042cf7da20060147af84f0e9263b94f56cdc8d96348b9- Imphash
2d9361d9b1ba51deb57c1de0cfe2768d- Vhash
03407666151d15165519z16z2bxz- Authentihash
182bfb2781c7e784b7c461013985355b9edd56b36a236af77f19f3ebec6e4a77- Rich PE header hash
N/A- SSDEEP
384:zkKYmgBgc/MBqKWTlvuqj5PBGJkuG0IdX2uu446rrgc2mNDGSlVy8RbmL4nNyrhB:JY/gxWxn/G7G0IdwxuBhoC5ALqE- TLSH
T1EA039DA1C55159E6F91ADEB8D1F4453BFAB1B0846342CACF2120C4ED0FB3BD2263D1A9- PDB path
N/A- Compilation time
2026-08-31- Country submitter
- N/A
Description
A kernel rootkit that hooks syscalls through ETW.
It switches on Windows' Circular Kernel Context Logger with the SYSTEMCALL flag, so the kernel fires an ETW event on every syscall, then hijacks that session's clock callback. On each call, it finds the syscall dispatcher's frame on the kernel stack and rewrites the stack copy of the service-routine pointer.
It hooks four syscalls:
• NtQuerySystemInformation
• NtOpenProcess
• NtReadFile
• NtWriteFile
It also deletes itself from disk after installing the hook.