File verdict·Decided by the MT AI Engine
Our call

Malicious

Signed Windows driver exhibiting process-injection behaviour; community YARA rules and signer history indicate rootkit malware.

Rootkit.Agent.AJNQVerified · Microsoft Windows Hardware Compatibility Publ…
Trust score18High risk
MT AI confidence · 72%
OceanGraper.sys
23.2 KB
4f412f9aa89994cda40e8725917e
Antivirus engines
0 of 75 flagged
Code signing
Signed by Microsoft Windows Hardware Compatibility Publ…
Age
First seen 4mo ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

72%Confidence
High
Reasoning

The file presents a complex profile: it carries a valid Microsoft Windows Hardware Compatibility Publisher signature and is silent across tier-1 antivirus engines, which would normally suggest legitimacy. However, the signer's history is damaging — the only prior sample we have with this signer was verdicted malicious (Rootkit.Agent.AJNQ, keylog.sys). Community YARA researchers have independently flagged this sample with 5 rules targeting rootkit and signed-driver injection patterns. The file exhibits T1055 (Process Injection) as its sole offensive MITRE technique, consistent with rootkit deployment. The combination of signer-history precedent, community rule convergence, and injection-focused behaviour outweighs the absence of tier-1 detections, which may reflect evasion or novelty rather than benignity.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. tier1Malicious=0; 17 tier-1 engines (Kaspersky, BitDefender, ESET, Fortinet, Avast, Ikarus, etc.) all report undetected — no tier-1 consensus on malware.

  2. signing.verified=true, signer='Microsoft Windows Hardware Compatibility Publisher', trustedPublisher.matched=true — Microsoft-signed driver.

  3. signerStats: 1/1 prior samples malicious (Rootkit.Agent.AJNQ); similarHashes[0] verdict='malicious' (score=12) for 'keylog.sys' signed by same publisher — signer history is malicious.

  4. triggeredHeuristics: T1055 (Process Injection) + yaraify_rules_fired=5 including 'killer_rookit' and 'signed_drv_IoCreateDevice' — community researchers converged on rootkit/injection signatures.

  5. behaviour: T1055 offensive technique present; no sandbox verdicts, no malicious contacted hosts, no dropped children — runtime behaviour is injection-focused but not conclusively malicious in isolation.

Points in its favour
  • Signed by Microsoft Windows Hardware Compatibility Publisher (verified)
  • 17 tier-1 antivirus engines report undetected
  • No malicious sandbox verdicts
  • No malicious contacted hosts or dropped children
Points against
  • Process injection (T1055) observed — rootkit deployment technique
  • 5 community YARA rules converge on rootkit/driver-injection signatures
  • Prior sample with same signer verdicted malicious (Rootkit.Agent.AJNQ)
  • Signed driver — elevated privilege execution context
  • Medium prevalence (53 submissions) — known malicious driver in circulation
What to do

Treat this file as malicious rootkit malware. The combination of signer-history precedent (prior Rootkit.Agent.AJNQ sample), community YARA rule convergence, and process-injection behaviour outweighs the absence of tier-1 detections. Isolate affected systems and perform forensic analysis; do not rely on the Microsoft signature as a safety indicator.

Threat family attribution

CP Script Inject Detector corroborated by 2 sources

  • 6 YARA rules
    CP_Script_Inject_Detector, DebuggerCheck__QueryInfo, killer_rookit
  • MT AI Engine
    Rootkit.Agent.AJNQ
External threat intelligence

1 corroborating signal from researcher-curated sources

YARAify HIT·6 community rules matchedView on YARAify
  • CP_Script_Inject_Detectorby DiegoAnalytics
    Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
  • DebuggerCheck__QueryInfo
  • killer_rookitby wtl
    detect killer rookit
  • PE_Digital_Certificateby albertzsigovits
  • signed_drv_IoCreateDeviceby wonderkun
    signed_sys_with_vulnerablity
Cross-referenced against MalwareBazaar (abuse.ch), YARAify, and the CIRCL hashlookup reference DB.
Signature matches

YARA + heuristic rules that fired

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

5 YARAify1 synthesis
MITRE ATT&CK profile
Defense evasion× 1
YARAify (community)
Researcher-authored rules via abuse.ch
  • CP_Script_Inject_Detector
  • DebuggerCheck__QueryInfo
  • killer_rookit
  • PE_Digital_Certificate
  • signed_drv_IoCreateDevice
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    T1055 (MITRE)
Antivirus engine breakdown

0 detections across 75 engines

0 malicious0 suspicious75 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust20 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 75 engines report this file as clean.
Hash 4f412f9aa899… cross-referenced against 75 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

ent 7.48Unpacked
Section entropy6 sections
.text
6.11
.rdata
3.79
.data
0.14
.pdata
3.23
INIT
4.33
.reloc
0.50
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
22
Moderate upload volume.
Total submissions
53
Includes repeat uploads by the same source.
First seen by VT
4mo ago
Feb 20, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
2/20/2026, 4:55:08 AM
First seen (MalwareBazaar)
Last analysis (VT)
6/27/2026, 3:41:39 PM
Scanned here
7/2/2026, 12:06:55 PM
File name
OceanGraper.sys
Size
23.2 KB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
4f412f9aa89994cda45422d23d6d961809225de9a4f5a8bfbfb9ac0e8725917e
MD5
3ee985c5fd1f5784e15a4d11b3ca70a1
SHA-1
33148c93465908ddad71cf189e22091dc0058ac4
PE imphash
07386745331387b83012a6786eacb5ac
First seen (VT)
2/20/2026, 4:55:08 AM
Last analysis (VT)
6/27/2026, 3:41:39 PM
First scan (MalwareTips)
7/2/2026, 12:06:55 PM
Last scan (MalwareTips)
7/2/2026, 12:06:55 PM
Code signer
Microsoft Windows Hardware Compatibility Publisherverified
Behavior tags
signedpeexenativeoverlay64bits
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.