← Back to malicious drivers

3.sys

Malicious Xue Sun 02:21 PM 08/31/2026
Driver Name
3.sys
SpcSpOpusInfo
N/A
MD5
57b9b562744038c7183b6cfabf0d1ad2
SHA1
2b5431043328762d3305cf9dd16e986d0299de63
SHA256
b7dfc6a85b30c11989844ea92703781807dfb2151623840fb9c093c91dabe989
Imphash
2d9361d9b1ba51deb57c1de0cfe2768d
Vhash
03407666151d15165519z16z2bxz
Authentihash
2ec27e30d5592d236425d0fbbeb985a1e9090ab99fa9a49fb6016957f567c6f6
Rich PE header hash
N/A
SSDEEP
384:DkKYegJac/Yx9OW25Luqj5PBGwkuG0IdXDluu446rrgc2mNDG2J1uy8RbmL4nNyK:5Y/a6W8D/GqG0IdDxuBhoKu5ALM
TLSH
T191039DA1C6516CE5F90AD9B8D1F5053BFAB1B0856741C6CF6120C4AD0FB3BE22A3D1A8
PDB path
N/A
Compilation time
2026-08-31
Country submitter
N/A

Description

A kernel rootkit that hooks syscalls through ETW.

It switches on Windows' Circular Kernel Context Logger with the SYSTEMCALL flag, so the kernel fires an ETW event on every syscall, then hijacks that session's clock callback. On each call, it finds the syscall dispatcher's frame on the kernel stack and rewrites the stack copy of the service-routine pointer.

It hooks four syscalls:

• NtQuerySystemInformation

• NtOpenProcess

• NtReadFile

• NtWriteFile

It also deletes itself from disk after installing the hook.