ntasn1.dll

  • File Path: C:\Windows\system32\ntasn1.dll
  • Description: Microsoft ASN.1 API

Hashes

Type Hash
MD5 F346BA8DC1ECEC3288E074945AE664B3
SHA1 962515ECEE03AE4CE92BEF2B2915E7735631A452
SHA256 58FD550AA23AED3290D78303889DA39FE3BCE33513DDBAB21624DEA575FE927B
SHA384 779ECD0B6CEF396E5DBA29925B1A3D3FE6B47A51B660F3F55B67542265FABE629D5F4FA8ABBE521F1F336065BE23BE6A
SHA512 3C1B60A0B34FD843C1EE23F9CE1E8217F7A7ACD507237E26797BD9CD42DFDD3E78AF617D744B7BF6ECD1FB75BB3EBEE6C40BD2700D689F87199CD3A7EF7C40BC
SSDEEP 3072:2M8WCC+fWLr6OU2nDNJrFFi4MCYL13Spx/MI4Em501X:2Uxre2JbJMCYLNU4De
IMP F7100EF886430CB1ABAF38BE7BB05DEF
PESHA1 26DEA41B0CF738CFD8C683F353429DFED7E1EC67
PE256 6ACA72BCAF58CFA4B251215BA060183565D7620FC548B97F9A2166F19C80A022

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: ntasn1.dll.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/71
  • VirusTotal Link: https://www.virustotal.com/gui/file/58fd550aa23aed3290d78303889da39fe3bce33513ddbab21624dea575fe927b/detection/

Possible Misuse

The following table contains possible examples of ntasn1.dll being misused. While ntasn1.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_mimikatz_inmemory_detection.yml - 'ntasn1.dll' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.