Driver Load - a26363e7b02b13f2b8d697abb90cd5c3.sys
Detects loading of driver a26363e7b02b13f2b8d697abb90cd5c3.sys via hash. Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver's infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.
Detection Logic
{
"selection_hashes": {
"Hashes
| contains": [
"MD5=a26363e7b02b13f2b8d697abb90cd5c3",
"SHA1=18693de1487c55e374b46a7728b5bf43300d4f69",
"SHA256=42ff11ddb46dfe5fa895e7babf88ee27790cde53a9139fc384346a89e802a327",
"IMPHASH=be0dd8b8e045356d600ee55a64d9d197"
]
},
"condition": "selection_hashes"
} False Positives
- ⚠ Unknown
Field Validations
Loading…
Comments (0)
Loading comments...