Ld9BoxSup.sys - Suspicious (58/100) - DriverShield Analysis

Analysis of Ld9BoxSup.sys: suspicious verdict, risk score 58/100. 1 YARA match, 0/76 multi-engine detections. SHA256 980641ff6df79cc5. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

Ld9BoxSup.sys - Analysis Report

DriverShield analyzed the Windows kernel driver Ld9BoxSup.sys and assigned a verdict of Suspicious with a composite risk score of 58/100, indicating some risk signals warranting review (30-59 band).

VerdictSuspicious (58/100)
YARA matches1
Multi-engine detections0 / 76
File size354200 bytes
Code-signing signerMicrosoft Windows Hardware Compatibility Publisher
Analyzed2026-04-14
SHA256980641ff6df79cc598935e8888a8bcb136b94546781953c05f53fc3d068acb13
SHA1dc8222ccbd900d839917259d79c329be94ccd525
MD5d3ffe15c357ffa6080139570adc143c1

Driver identity

Version resource data embedded in the Ld9BoxSup.sys PE header, as extracted by the analysis engine.

File descriptionVirtualBox Support Driver
ProductOracle VM VirtualBox
CompanyOracle Corporation
Original filenameVBoxSup.sys
Internal nameVBoxSup
File version6.1.36.152435
CopyrightCopyright (C) 2009-2022 Oracle Corporation

How the 58/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches30 / 100
Dangerous kernel imports100 / 100
IOCTL dispatch surface100 / 100
Known-vulnerable corpus0 / 100
Code-signing state80 / 100
Packing and entropy0 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

Kernel imports (27)

Kernel-mode APIs resolved from the Import Address Table of Ld9BoxSup.sys, ranked by exploitation relevance.

APIRiskWhy it matters
MmMapLockedPagesSpecifyCachecriticalHighly dangerous - potential for arbitrary code execution, memory corruption, or process termination
MmMapLockedPagescriticalHighly dangerous - potential for arbitrary code execution, memory corruption, or process termination
MmMapIoSpacecriticalHighly dangerous - potential for arbitrary code execution, memory corruption, or process termination
MmGetSystemRoutineAddresshighPotentially dangerous - could be used for privilege escalation or security bypass
ZwSetSystemInformationhighPotentially dangerous - could be used for privilege escalation or security bypass
MmGetPhysicalAddresshighPotentially dangerous - could be used for privilege escalation or security bypass
MmAllocateContiguousMemorySpecifyCachehighPotentially dangerous - could be used for privilege escalation or security bypass
MmAllocateContiguousMemoryhighPotentially dangerous - could be used for privilege escalation or security bypass
ZwQuerySystemInformationmediumModerate risk - system modification capability
ObReferenceObjectByHandlemediumModerate risk - system modification capability
MmUnmapIoSpacemediumModerate risk - system modification capability
IoBuildDeviceIoControlRequestlowStandard kernel API - generally benign
IofCompleteRequestlowStandard kernel API - generally benign
ExFreePoollowStandard kernel API - generally benign
ExAllocatePoollowStandard kernel API - generally benign
ZwCloselowStandard kernel API - generally benign
RtlInitUnicodeStringlowStandard kernel API - generally benign
KeWaitForSingleObjectlowStandard kernel API - generally benign
KeInitializeEventlowStandard kernel API - generally benign
ProbeForReadlowStandard kernel API - generally benign
ExAllocatePoolWithTaglowStandard kernel API - generally benign
IoCreateDevicelowStandard kernel API - generally benign
KeSetEventlowStandard kernel API - generally benign
KeDelayExecutionThreadlowStandard kernel API - generally benign
DbgPrintlowStandard kernel API - generally benign
IoDeleteDevicelowStandard kernel API - generally benign
ProbeForWritelowStandard kernel API - generally benign

IOCTL dispatch codes (40)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x0080BD8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3938
0x0022804BhighMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #18
0x0080878BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #482
0x00809F8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #2018
0x00808987highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #609
0x0080A98BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #2658
0x0080968BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1442
0x0080A38BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #2274
0x0080998BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1634
0x0080BA8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3746
0x0022805FhighMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #23
0x0080B08BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3106
0x0080850FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #323
0x00228057highMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #21
0x00228053highMETHOD_NEITHERFILE_DEVICE_UNKNOWN Function #20
0x008083C7highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #241
0x0080880FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #515
0x00801C8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1826
0x0080048BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #290
0x00801483highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1312
0x0080B8C3highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3632
0x0080858BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #354
0x00347263highMETHOD_NEITHERFILE_DEVICE_DISK Function #3224
0x00805A4DmediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #1683

Showing 24 of 40 extracted control codes.

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0x33EF00x340006.43CODE, EXEC, READ
.rdata0x10FB00x110005.91IDATA, READ
.data0x20D400x52003.54IDATA, READ, WRITE
.pdata0x3B040x3C005.52IDATA, READ
.edata0x3E040x40005.87IDATA, READ
INIT0x085A0x0A004.54CODE, EXEC, READ, WRITE, DISCARD
.rsrc0x03F80x04003.4IDATA, READ, DISCARD
.reloc0x10440x12003.7IDATA, READ, DISCARD

Exploit mitigations

Control Flow GuardNot enabled
ASLRNot enabled
DEPNot enabled
Integrity checkNot enforced
Mitigation score5 / 100

YARA rule matches (1)

RuleSeverityDetects
SUSP_PhysMemhighPhysical memory mapping

MITRE ATT&CK techniques (11)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1003OS Credential DumpingCredential Access
T1003.001OS Credential Dumping: LSASS MemoryCredential Access
T1006Direct Volume AccessDefense Evasion
T1055.012Process HollowingDefense Evasion
T1068Exploitation for Privilege EscalationPrivilege Escalation
T1071Application Layer ProtocolCommand and Control
T1211Exploitation for Defense EvasionDefense Evasion
T1543.003Windows ServicePersistence
T1553.002Subvert Trust Controls: Code SigningDefense Evasion
T1569.002Service ExecutionExecution
T1652Device Driver DiscoveryDiscovery

Code-signing chain

SignerMicrosoft Windows Hardware Compatibility Publisher
Signer organisationMicrosoft Corporation
IssuerMicrosoft Windows Third Party Component CA 2012
Serial33000000DC341A520FBBCF3D8C0000000000DC
Valid from2022-03-10 19:58 UTC
Valid until2023-03-08 19:58 UTC (expired)
Signature validityNot verified

Symbolic execution

Engine angr, status static_approximation, 0 paths explored at a maximum depth of 0. Vulnerability classes reached: 0. Exploitable paths: 0.

Frequently asked questions about Ld9BoxSup.sys

Is Ld9BoxSup.sys safe?

Based on DriverShield static and dynamic analysis, Ld9BoxSup.sys shows some suspicious signals and warrants manual review. Its composite risk score is 58/100 (verdict: suspicious). Always validate findings independently before acting.

What is the risk score of Ld9BoxSup.sys?

Ld9BoxSup.sys has a DriverShield composite risk score of 58/100, placing it in the suspicious verdict band. SHA256: 980641ff6df79cc598935e8888a8bcb136b94546781953c05f53fc3d068acb13.

What is Ld9BoxSup.sys?

Ld9BoxSup.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by Microsoft Windows Hardware Compatibility Publisher.

Related: Other drivers signed by Microsoft Windows Hardware Compatibility Publisher · What an IOCTL dispatch code is · How YARA matching feeds the score · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact