nshwfp.dll

  • File Path: C:\Windows\system32\nshwfp.dll
  • Description: Windows Filtering Platform Netsh Helper

Hashes

Type Hash
MD5 366C76832A6A12850407BF16F2D22441
SHA1 C91D0A95F14B3C899746CE876A4D061164066723
SHA256 D34797476361C9758E14416088382162C2BEE7B02A8B4C102E09AB2FBB635D32
SHA384 C717D69B2C80EA88B730A874DDEF4537DB24619A879A89C6269A28C4B2CC3546002B59AA0BC698EE5B695CCBD4D79D89
SHA512 AFAE75ABA40DAE20B7931B819A4A5F928DE0C365352134A67D8E5E8684DDF35265AE2DEF3F54099A9BA9A58638E2E9E0DD3281F35245374310E23B33DF5BFF32
SSDEEP 6144:ja5r1dDLRfobZVmsGNhfj0MVLPxjpOMUoikXVZTtYuP56GrMdAmbwjssU:CrzBfob+fhfjdPxjpE2TtYz3Lbww
IMP 4984C45904469493C3B89ED669139503
PESHA1 4816628B480C39CE55E3B76A214439DA1938F18E
PE256 8573CD8547F94BC32FC5633C6DD53C49ACF549C490BFA9A665FC80EBB3FB5E87

DLL Exports:

Function Name Ordinal Type
InitHelperDll 6 Exported Function
IdpConfigRemovePolicy 5 Exported Function
WfpCaptureStop 8 Exported Function
WfpCaptureExportedW 7 Exported Function
IdpConfigAllocateAndGetPolicy 2 Exported Function
IdpConfigAddPolicy 1 Exported Function
IdpConfigInitDefaultPolicy 4 Exported Function
IdpConfigFreePolicy 3 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: nshwfp.dll.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/66
  • VirusTotal Link: https://www.virustotal.com/gui/file/d34797476361c9758e14416088382162c2bee7b02a8b4c102e09ab2fbb635d32/detection/

File Similarity (ssdeep match)

File Score
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\arm64\tracefmt.exe 32
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x64\tracefmt.exe 33
C:\Program Files (x86)\Windows Kits\10\Debuggers\arm64\winxp\wmitrace.dll 35
C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\winext\rcdrkd.dll 38
C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\winxp\wmitrace.dll 32
C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\perf_wpp.dll 30
C:\Windows\system32\nltest.exe 35
C:\Windows\system32\nltest.exe 29
C:\Windows\system32\nltest.exe 35

MIT License. Copyright (c) 2020-2021 Strontic.