ntoskrnl.exe

  • File Path: C:\Windows\system32\ntoskrnl.exe
  • Description: NT Kernel & System

Hashes

Type Hash
MD5 30AED7F155B6A610A5482422366F6C8D
SHA1 A4050D726C17EAF22F6A61E5BDA0EBF2B97337B0
SHA256 FBEBB420FCE2056E992E97B396DBFD11D856C61003619A8B68CFDC330F94012B
SHA384 5146E7F2B2A5AB3914E7AE2108044FD263F1CEECB0F48C3D420C69CDF3009264DED81D21CF852F1AE1212E25CE5F77ED
SHA512 82C3AB9DEA74684240F38569BAF593AAD1937B8870A5BE66C34DA386E6FD24DAE9AF92A5DAF019E35B642C566ED1153D10396999EAF84CF9F3C0D5C0FE5B37F3
SSDEEP 98304:CJDtua0BaYZ7EweXsy0rLc2f2fgwqzpMBSd8ugvM3vq2XAK:sJuaPYZ7uD0sylDRBfZQK

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: ntkrnlmp.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.17763.1397 (WinBuild.160101.0800)
  • Product Version: 10.0.17763.1397
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

Possible Misuse

The following table contains possible examples of ntoskrnl.exe being misused. While ntoskrnl.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
signature-base apt_hackingteam_rules.yar $x4 = “C:\\Windows\\Sysnative\\ntoskrnl.exe” fullword ascii /* PEStudio Blacklist: strings */ CC BY-NC 4.0
signature-base apt_winnti.yar $s17 = “NTOSKRNL.EXE” fullword wide /* Goodware String - occured 4 times */ CC BY-NC 4.0
signature-base apt_winnti.yar $a5 = “ntoskrnl.exe” ascii fullword CC BY-NC 4.0
signature-base apt_winnti.yar $a3 = “%SystemRoot%\System32\ntoskrnl.exe” ascii CC BY-NC 4.0
signature-base apt_winnti_hdroot.yar $s1 = “\system32\ntoskrnl.exe” fullword ascii CC BY-NC 4.0
signature-base spy_querty_fiveeyes.yar $s3 = “ntoskrnl.exe” fullword ascii CC BY-NC 4.0
signature-base spy_regin_fiveeyes.yar $s4 = “ntoskrnl.exe” fullword ascii CC BY-NC 4.0

MIT License. Copyright (c) 2020-2021 Strontic.