dns.exe

  • File Path: C:\windows\system32\dns.exe
  • Description: Domain Name System (DNS) Server

Hashes

Type Hash
MD5 E2444376A0BDB6F72BA02B637CED5B88
SHA1 A18CEB4D9EAC938F757342BC883A2F5ADA1ADC95
SHA256 0F841CE45A8BE1072614CF851D4C45BBE230F695718C3077B6435A902E405DC2
SHA384 1A76E4BC1623FFB6D36998FDE4D1C219D77ED69BE965E027A2AFE9F21E696BF2885B4C6E5F141C0F48606984A4158D2F
SHA512 D32282AC3BE8500E061071EADF7546829AD871E097CF4A4FEACFA361883D478711D8F984D2E3BCAA7347E425E2A4D0210031B0701241FB8EEB82DD79CA3BC6C4
SSDEEP 49152:j7gYLaYpTTKXvkvd1q69lS9aukO2m1h3Ft31lg9BPcPzxj84+IX:tpTTKXsv/q69vuh2YP9g9BUP+4

Signature

  • Status: The file C:\windows\system32\dns.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at http://go.microsoft.com/fwlink/?LinkID=135170
  • Serial: ``
  • Thumbprint: ``
  • Issuer:
  • Subject:

File Metadata

  • Original Filename: dns.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 6.3.9600.17327 (winblue_r3.140826-1500)
  • Product Version: 6.3.9600.17327
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

Possible Misuse

The following table contains possible examples of dns.exe being misused. While dns.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma net_connection_win_susp_rdp.yml - '\System32\dns.exe' DRL 1.0
sigma net_connection_win_susp_rdp.yml - domain controller using dns.exe DRL 1.0
sigma proc_creation_win_exploit_cve_2020_1350.yml ParentImage\|endswith: '\System32\dns.exe' DRL 1.0
sigma proc_creation_win_exploit_cve_2020_1350.yml - Unknown but benign sub processes of the Windows DNS service dns.exe DRL 1.0
LOLBAS Dnscmd.yml - Link: https://github.com/dim0x69/dns-exe-persistance/tree/master/dns-plugindll-vcpp  

MIT License. Copyright (c) 2020-2021 Strontic.