YSR0.sys - Clean (17/100) - DriverShield Analysis

Analysis of YSR0.sys: clean verdict, risk score 17/100. 0 YARA matches, 0/75 multi-engine detections. SHA256 5c8893028da500a2. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

YSR0.sys - Analysis Report

DriverShield analyzed the Windows kernel driver YSR0.sys and assigned a verdict of Clean with a composite risk score of 17/100, indicating no notable risk signals (0-29 band).

VerdictClean (17/100)
YARA matches0
Multi-engine detections0 / 75
File size1268360 bytes
Code-signing signerSymantec Time Stamping Services CA - G2
Analyzed2026-03-22
SHA2565c8893028da500a21082afa61c4cbe893417db322762ee1ace8d02169e1c9ea9
SHA1402a3d19bdd0beb55be6b254e14c646ff6af3d5d
MD5e99b49570c2178cd0f3ca91323677153

Driver identity

Version resource data embedded in the YSR0.sys PE header, as extracted by the analysis engine.

File descriptionVirtualBox VMM - ring-0 context parts
ProductNox Limited VM VirtualBox
CompanyNox Limited Corporation
Original filenameYSR0.sys
Internal nameYSR0
File version5.2.36.135684
CopyrightCopyright (C) 2015-2020 Nox Limited

How the 17/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches0 / 100
Dangerous kernel imports0 / 100
IOCTL dispatch surface100 / 100
Known-vulnerable corpus0 / 100
Code-signing state80 / 100
Packing and entropy0 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

IOCTL dispatch codes (40)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x00800C4BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #786
0x00808DB7highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #877
0x0080A903highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #2624
0x008080B7highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #45
0x0080808BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #34
0x008083B7highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #237
0x0080850FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #323
0x0080840FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #259
0x008086FFhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #447
0x00803D07highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3905
0x0080FA83highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3744
0x0080FC8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3874
0x0080D893highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1572
0x0080C4BFhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #303
0x0080D493highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1316
0x0080F983highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3680
0x0080FC83highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3872
0x0080F98BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3682
0x0080D483highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1312
0x0080F8BBhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3630
0x00808A7FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #671
0x00808A6FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #667
0x00808F8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #994
0x0080838BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #226

Showing 24 of 40 extracted control codes.

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0xD204B0xD22006.43CODE, EXEC, READ
.rdata0x3901C0x392004.1IDATA, READ
.data0x33300x02000.8IDATA, READ, WRITE
.pdata0xB3E80xB4005.98IDATA, READ
VTGObj0x2D600x2E003.99IDATA, READ, WRITE
.edata0x95420x96006.15IDATA, READ
INIT0x111A0x12004.95CODE, EXEC, READ, WRITE, DISCARD
.rsrc0x03F80x04003.42IDATA, READ, DISCARD
.reloc0x4CB60x4E005.21IDATA, READ, DISCARD

Exploit mitigations

Control Flow GuardNot enabled
ASLRNot enabled
DEPNot enabled
Integrity checkEnforced
Mitigation score10 / 100

MITRE ATT&CK techniques (3)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1071Application Layer ProtocolCommand and Control
T1543.003Windows ServicePersistence
T1652Device Driver DiscoveryDiscovery

Code-signing chain

SignerSymantec Time Stamping Services CA - G2
Signer organisationSymantec Corporation
IssuerThawte Timestamping CA
Serial7E93EBFB7CC64E59EA4B9A77D406FC3B
Valid from2012-12-21 00:00 UTC
Valid until2020-12-30 23:59 UTC (expired)
Signature validityNot verified

Symbolic execution

Engine angr, status completed, 2 paths explored at a maximum depth of 2. Vulnerability classes reached: 0. Exploitable paths: 0.

Frequently asked questions about YSR0.sys

Is YSR0.sys safe?

Based on DriverShield static and dynamic analysis, YSR0.sys is assessed as clean, with no notable risk signals. Its composite risk score is 17/100 (verdict: clean). Always validate findings independently before acting.

What is the risk score of YSR0.sys?

YSR0.sys has a DriverShield composite risk score of 17/100, placing it in the clean verdict band. SHA256: 5c8893028da500a21082afa61c4cbe893417db322762ee1ace8d02169e1c9ea9.

What is YSR0.sys?

YSR0.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by Symantec Time Stamping Services CA - G2.

Related: Other drivers signed by Symantec Time Stamping Services CA - G2 · What an IOCTL dispatch code is · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact