bb264edd403b669ed04af27b8556e7... - Clean (7/100) - DriverShield Analysis

Analysis of bb264edd403b669ed04af27b8556e7bc747474a20aa18eafa772a820c706.sys: clean verdict, risk score 7/100. 0 YARA matches, 40/76 multi-engine detections. SHA256 bb264edd403b669e. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

bb264edd403b669ed04af27b8556e7bc747474a20aa18eafa772a820c706.sys - Analysis Report

DriverShield analyzed the Windows kernel driver bb264edd403b669ed04af27b8556e7bc747474a20aa18eafa772a820c706.sys and assigned a verdict of Clean with a composite risk score of 7/100, indicating no notable risk signals (0-29 band).

VerdictClean (7/100)
YARA matches0
Multi-engine detections40 / 76
File size17352 bytes
Code-signing signerBattlEye Innovations e.K.
Analyzed2026-04-01
SHA256bb264edd403b669ed04af27b8556e7bc747474a20aa18eafa772a820c7062e76
SHA166620c15ee2a4c81b3ec9c37e255bae41b99e2b1
MD5029fab0d6b04db053484feb1ad9106fa

How the 7/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches0 / 100
Dangerous kernel imports24 / 100
IOCTL dispatch surface21 / 100
Known-vulnerable corpus0 / 100
Code-signing state0 / 100
Packing and entropy0 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

Kernel imports (3)

Kernel-mode APIs resolved from the Import Address Table of bb264edd403b669ed04af27b8556e7bc747474a20aa18eafa772a820c706.sys, ranked by exploitation relevance.

APIRiskWhy it matters
IofCompleteRequestlowStandard kernel API - generally benign
IoCreateSymbolicLinklowStandard kernel API - generally benign
IoCreateDevicelowStandard kernel API - generally benign

IOCTL dispatch codes (7)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x002200F0mediumMETHOD_BUFFEREDFILE_DEVICE_UNKNOWN Function #60
0x0034FB0DmediumMETHOD_IN_DIRECTFILE_DEVICE_DISK Function #3779
0x00341B0DmediumMETHOD_IN_DIRECTFILE_DEVICE_DISK Function #1731
0x00802484mediumMETHOD_BUFFEREDFILE_DEVICE_CUSTOM Function #2337
0x0022B941mediumMETHOD_IN_DIRECTFILE_DEVICE_UNKNOWN Function #3664
0x00808789mediumMETHOD_IN_DIRECTFILE_DEVICE_CUSTOM Function #482
0x00340060mediumMETHOD_BUFFEREDFILE_DEVICE_DISK Function #24

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0x27AA0x28006.24CODE, EXEC, READ
.rdata0x084C0x0A003.48IDATA, READ
.data0x00880x02000.12IDATA, READ, WRITE
.pdata0x01EC0x02003.85IDATA, READ
INIT0x010C0x02002.55CODE, EXEC, READ, DISCARD
.reloc0x00240x02000.49IDATA, READ, DISCARD

Exploit mitigations

Control Flow GuardEnabled
ASLREnabled
DEPEnabled
Integrity checkNot enforced
Mitigation score100 / 100

MITRE ATT&CK techniques (3)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1543.003Windows ServicePersistence
T1569.002System Services: Service ExecutionExecution
T1652Device Driver DiscoveryDiscovery

Code-signing chain

SignerBattlEye Innovations e.K.
IssuerBattlEye Innovations e.K.
SerialEA3CAB2638C44E9E
Valid from2024-01-20 05:00 UTC
Valid until2029-01-20 05:00 UTC
Signature validityVerified

Symbolic execution

Engine angr, status completed, 3 paths explored at a maximum depth of 3. Vulnerability classes reached: 0. Exploitable paths: 0.

Frequently asked questions about bb264edd403b669ed04af27b8556e7bc747474a20aa18eafa772a820c706.sys

Is bb264edd403b669ed04af27b8556e7bc747474a20aa18eafa772a820c706.sys safe?

Based on DriverShield static and dynamic analysis, bb264edd403b669ed04af27b8556e7bc747474a20aa18eafa772a820c706.sys is assessed as clean, with no notable risk signals. Its composite risk score is 7/100 (verdict: clean). Always validate findings independently before acting.

What is the risk score of bb264edd403b669ed04af27b8556e7bc747474a20aa18eafa772a820c706.sys?

bb264edd403b669ed04af27b8556e7bc747474a20aa18eafa772a820c706.sys has a DriverShield composite risk score of 7/100, placing it in the clean verdict band. SHA256: bb264edd403b669ed04af27b8556e7bc747474a20aa18eafa772a820c7062e76.

What is bb264edd403b669ed04af27b8556e7bc747474a20aa18eafa772a820c706.sys?

bb264edd403b669ed04af27b8556e7bc747474a20aa18eafa772a820c706.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by BattlEye Innovations e.K..

Related: Other drivers signed by BattlEye Innovations e.K. · What an IOCTL dispatch code is · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact