3.sys
- Driver Name
3.sys- SpcSpOpusInfo
N/A- MD5
57b9b562744038c7183b6cfabf0d1ad2- SHA1
2b5431043328762d3305cf9dd16e986d0299de63- SHA256
b7dfc6a85b30c11989844ea92703781807dfb2151623840fb9c093c91dabe989- Imphash
2d9361d9b1ba51deb57c1de0cfe2768d- Vhash
03407666151d15165519z16z2bxz- Authentihash
2ec27e30d5592d236425d0fbbeb985a1e9090ab99fa9a49fb6016957f567c6f6- Rich PE header hash
N/A- SSDEEP
384:DkKYegJac/Yx9OW25Luqj5PBGwkuG0IdXDluu446rrgc2mNDG2J1uy8RbmL4nNyK:5Y/a6W8D/GqG0IdDxuBhoKu5ALM- TLSH
T191039DA1C6516CE5F90AD9B8D1F5053BFAB1B0856741C6CF6120C4AD0FB3BE22A3D1A8- PDB path
N/A- Compilation time
2026-08-31- Country submitter
- N/A
Description
A kernel rootkit that hooks syscalls through ETW.
It switches on Windows' Circular Kernel Context Logger with the SYSTEMCALL flag, so the kernel fires an ETW event on every syscall, then hijacks that session's clock callback. On each call, it finds the syscall dispatcher's frame on the kernel stack and rewrites the stack copy of the service-routine pointer.
It hooks four syscalls:
• NtQuerySystemInformation
• NtOpenProcess
• NtReadFile
• NtWriteFile
It also deletes itself from disk after installing the hook.