5.sys
- Driver Name
5.sys- SpcSpOpusInfo
N/A- MD5
c0ddb1fcc2e30224a1bad1dd8ef7c991- SHA1
7db8d0bd55749f4f2fae1c76261c95335ce856f7- SHA256
b44de81f30ab1536798120ee7287abb259ec4e2a9e8a4ec113efe577ef1aa78d- Imphash
2d9361d9b1ba51deb57c1de0cfe2768d- Vhash
03407666151d15165519z16z2bxz- Authentihash
98cedc08fa205a8281d9b5de2351892f889446d25d6ef57937ce72003ca13ae7- Rich PE header hash
N/A- SSDEEP
384:tkKYIgVxcTiV3mWc93Luqj5PBGZ5kuG0IdXWuu446rrgc2mNDGoty8RbmL4nNy6G:jYNxaWKT/GVG0IdQxuBhoS5ALR- TLSH
T13F039EA1C1516CE2F91BD9B8D1F4053FE9B0B1857751C6CF2160C4AD1FA3BD22A3E1A9- PDB path
N/A- Compilation time
2026-08-31- Country submitter
- N/A
Description
A kernel rootkit that hooks syscalls through ETW.
It switches on Windows' Circular Kernel Context Logger with the SYSTEMCALL flag, so the kernel fires an ETW event on every syscall, then hijacks that session's clock callback. On each call, it finds the syscall dispatcher's frame on the kernel stack and rewrites the stack copy of the service-routine pointer.
It hooks four syscalls:
• NtQuerySystemInformation
• NtOpenProcess
• NtReadFile
• NtWriteFile
It also deletes itself from disk after installing the hook.