ntoskrnl.exe

  • File Path: C:\Windows\system32\ntoskrnl.exe
  • Description: NT Kernel & System

Hashes

Type Hash
MD5 87A2EA32A2FD980E6D373A3CB3A370AF
SHA1 AEE8B64BB4A4C66EDB68EF2570CC9345E22B6B9F
SHA256 0E039C3BBD86D31CEB8F3FD2046134D067EE41EBD974597E59F6518B4D9B60B7
SHA384 392B334B570DEDA1D5ED60F33D4E867A716F34084692BF691250396AB628A06DBB38BE28FF4D53E7DE4B8AC0C9A7D290
SHA512 C514EF205D27C6880140AFE3EE8DB5CC6CEC60065AB615CDDC40EBC2BBD6718E458EF645F3A6093AB58F44299D70B0728182263F37AE41EBC941F0C04385BF01
SSDEEP 98304:CMe7W9UTG0Ka5Sj+Y6TmqHiqSpRbXR0HGWF6NRUL+jE7Or:ClVG0KaTaS6bB0HGWF6NaKjEqr
IMP 4D717BA02FC8AA76777B033C52AA4694
PESHA1 313A04DAAE83E27DF425343C0FD1D1C8363F6ADB
PE256 417758D845E8CED56D2E8E82D9A19DBF40FE92DDD4D096FEE45AE19915FE7078

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: ntkrnlmp.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.17763.1518 (WinBuild.160101.0800)
  • Product Version: 10.0.17763.1518
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/71
  • VirusTotal Link: https://www.virustotal.com/gui/file/0e039c3bbd86d31ceb8f3fd2046134d067ee41ebd974597e59f6518b4d9b60b7/detection/

Possible Misuse

The following table contains possible examples of ntoskrnl.exe being misused. While ntoskrnl.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
signature-base apt_hackingteam_rules.yar $x4 = “C:\\Windows\\Sysnative\\ntoskrnl.exe” fullword ascii /* PEStudio Blacklist: strings */ CC BY-NC 4.0
signature-base apt_winnti.yar $s17 = “NTOSKRNL.EXE” fullword wide /* Goodware String - occured 4 times */ CC BY-NC 4.0
signature-base apt_winnti.yar $a5 = “ntoskrnl.exe” ascii fullword CC BY-NC 4.0
signature-base apt_winnti.yar $a3 = “%SystemRoot%\System32\ntoskrnl.exe” ascii CC BY-NC 4.0
signature-base apt_winnti_hdroot.yar $s1 = “\system32\ntoskrnl.exe” fullword ascii CC BY-NC 4.0
signature-base spy_querty_fiveeyes.yar $s3 = “ntoskrnl.exe” fullword ascii CC BY-NC 4.0
signature-base spy_regin_fiveeyes.yar $s4 = “ntoskrnl.exe” fullword ascii CC BY-NC 4.0

MIT License. Copyright (c) 2020-2021 Strontic.