LOLDrivers high experimental sigma

Driver Load - 927e3aef03a8355d236230cace376b3023480a40c5ac08453c07dab343dd1f11

Detects loading of driver 927e3aef03a8355d236230cace376b3023480a40c5ac08453c07dab343dd1f11 via hash. According to Sophos X-Ops (Aug 06, 2025), a widely shared EDR-killer toolkit drops/loads a malicious kernel driver signed with compromised or revoked certificates to disable endpoint protections. Variants target many vendors, and are commonly HeartCrypt-packed and used by ransomware groups (e.g., RansomHub, INC). The payload uses hard-coded driver names (e.g., mraml.sys, noedt.sys) and kills security services/processes.

View Source

Detection Logic

{
  "selection_hashes": {
    "Hashes
| contains": [
      "MD5=13ab592c51354e97611b4a77859f3ce7",
      "SHA1=8cd5c8ec1638e178d985bb01777bf0e5ffd1da06",
      "SHA256=927e3aef03a8355d236230cace376b3023480a40c5ac08453c07dab343dd1f11",
      "IMPHASH=83686b18f6322e23404dd4d2b1957b1c"
    ]
  },
  "condition": "selection_hashes"
}

False Positives

  • Unknown

Field Validations

Loading…

Comments (0)

Loading comments...