← Back to malicious drivers

5.sys

Malicious Xue Sun 03:02 PM 08/31/2026
Driver Name
5.sys
SpcSpOpusInfo
N/A
MD5
c0ddb1fcc2e30224a1bad1dd8ef7c991
SHA1
7db8d0bd55749f4f2fae1c76261c95335ce856f7
SHA256
b44de81f30ab1536798120ee7287abb259ec4e2a9e8a4ec113efe577ef1aa78d
Imphash
2d9361d9b1ba51deb57c1de0cfe2768d
Vhash
03407666151d15165519z16z2bxz
Authentihash
98cedc08fa205a8281d9b5de2351892f889446d25d6ef57937ce72003ca13ae7
Rich PE header hash
N/A
SSDEEP
384:tkKYIgVxcTiV3mWc93Luqj5PBGZ5kuG0IdXWuu446rrgc2mNDGoty8RbmL4nNy6G:jYNxaWKT/GVG0IdQxuBhoS5ALR
TLSH
T13F039EA1C1516CE2F91BD9B8D1F4053FE9B0B1857751C6CF2160C4AD1FA3BD22A3E1A9
PDB path
N/A
Compilation time
2026-08-31
Country submitter
N/A

Description

A kernel rootkit that hooks syscalls through ETW.

It switches on Windows' Circular Kernel Context Logger with the SYSTEMCALL flag, so the kernel fires an ETW event on every syscall, then hijacks that session's clock callback. On each call, it finds the syscall dispatcher's frame on the kernel stack and rewrites the stack copy of the service-routine pointer.

It hooks four syscalls:

• NtQuerySystemInformation

• NtOpenProcess

• NtReadFile

• NtWriteFile

It also deletes itself from disk after installing the hook.