ntoskrnl.exe
- File Path:
C:\Windows\system32\ntoskrnl.exe
- Description: NT Kernel & System
Hashes
Type | Hash |
---|---|
MD5 | 87A2EA32A2FD980E6D373A3CB3A370AF |
SHA1 | AEE8B64BB4A4C66EDB68EF2570CC9345E22B6B9F |
SHA256 | 0E039C3BBD86D31CEB8F3FD2046134D067EE41EBD974597E59F6518B4D9B60B7 |
SHA384 | 392B334B570DEDA1D5ED60F33D4E867A716F34084692BF691250396AB628A06DBB38BE28FF4D53E7DE4B8AC0C9A7D290 |
SHA512 | C514EF205D27C6880140AFE3EE8DB5CC6CEC60065AB615CDDC40EBC2BBD6718E458EF645F3A6093AB58F44299D70B0728182263F37AE41EBC941F0C04385BF01 |
SSDEEP | 98304:CMe7W9UTG0Ka5Sj+Y6TmqHiqSpRbXR0HGWF6NRUL+jE7Or:ClVG0KaTaS6bB0HGWF6NaKjEqr |
IMP | 4D717BA02FC8AA76777B033C52AA4694 |
PESHA1 | 313A04DAAE83E27DF425343C0FD1D1C8363F6ADB |
PE256 | 417758D845E8CED56D2E8E82D9A19DBF40FE92DDD4D096FEE45AE19915FE7078 |
Signature
- Status: Signature verified.
- Serial:
3300000266BD1580EFA75CD6D3000000000266
- Thumbprint:
A4341B9FD50FB9964283220A36A1EF6F6FAA7840
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: ntkrnlmp.exe
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.17763.1518 (WinBuild.160101.0800)
- Product Version: 10.0.17763.1518
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
- Machine Type: 64-bit
File Scan
- VirusTotal Detections: 0/71
- VirusTotal Link: https://www.virustotal.com/gui/file/0e039c3bbd86d31ceb8f3fd2046134d067ee41ebd974597e59f6518b4d9b60b7/detection/
Possible Misuse
The following table contains possible examples of ntoskrnl.exe
being misused. While ntoskrnl.exe
is not inherently malicious, its legitimate functionality can be abused for malicious purposes.
Source | Source File | Example | License |
---|---|---|---|
signature-base | apt_hackingteam_rules.yar | $x4 = “C:\\Windows\\Sysnative\\ntoskrnl.exe” fullword ascii /* PEStudio Blacklist: strings */ | CC BY-NC 4.0 |
signature-base | apt_winnti.yar | $s17 = “NTOSKRNL.EXE” fullword wide /* Goodware String - occured 4 times */ | CC BY-NC 4.0 |
signature-base | apt_winnti.yar | $a5 = “ntoskrnl.exe” ascii fullword | CC BY-NC 4.0 |
signature-base | apt_winnti.yar | $a3 = “%SystemRoot%\System32\ntoskrnl.exe” ascii | CC BY-NC 4.0 |
signature-base | apt_winnti_hdroot.yar | $s1 = “\system32\ntoskrnl.exe” fullword ascii | CC BY-NC 4.0 |
signature-base | spy_querty_fiveeyes.yar | $s3 = “ntoskrnl.exe” fullword ascii | CC BY-NC 4.0 |
signature-base | spy_regin_fiveeyes.yar | $s4 = “ntoskrnl.exe” fullword ascii | CC BY-NC 4.0 |
MIT License. Copyright (c) 2020-2021 Strontic.