certmgr.exe

  • File Path: C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\arm64\certmgr.exe
  • Description: ECM Certificate Manager

Hashes

Type Hash
MD5 B18C3F2FD9A7E9C7FC8C91BA0BE5FD89
SHA1 D0B7077AA84C888D86B75D1EEFE006E0D81115BF
SHA256 800AB3A602177A4DE32310C0A1D260D96C610BC69E0AE3EA2192D891F38744F6
SHA384 8E4D84BDA7807981EE08DFAC615888049E0806C0AF4B00214777511E302FE846E80F8CE4DF943DA05E1645C308B4B9BD
SHA512 578E521C14EBA6B732384F234B2945F12E3AC6E801B22DA904D8D6EF5C19F7235656BC5E759DB0807BFDE4811AA23777E9DFD9DCF4D945F20CB5BBA318F1BFFD
SSDEEP 1536:T+VLohsoNqVWAN9Y4KFa5Qgmq8UBYw+WXsA9i9vYd:MuqVWv/E5QXUBt+WXsN+
IMP E49BAEF8540FDB04EDBDE6ACF06A5124
PESHA1 18825675570FBC97F447CA6E746EED8124FBB190
PE256 007289363E8FF081C5D997C1DC46BA9A0A6765ACBE59B82CE2725A30F74D31B1

Signature

  • Status: Signature verified.
  • Serial: 33000002B7E8E007A82AEF13150000000002B7
  • Thumbprint: 5A68625F1A516670A744F7EF919500A479D32A5B
  • Issuer: CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows Kits Publisher, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: CERTMGR.EXE
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit ARM

File Scan

  • VirusTotal Detections: Unknown

File Similarity (ssdeep match)

File Score
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x64\certmgr.exe 46
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x86\certmgr.exe 49

Possible Misuse

The following table contains possible examples of certmgr.exe being misused. While certmgr.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_root_certificate_installed.yml Image\|endswith: '\CertMgr.exe' # Example: CertMgr.exe /add CertificateFileName.cer /s /r localMachine root /all DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.