WMIADAP.exe

  • File Path: C:\Windows\system32\wbem\WMIADAP.exe
  • Description: WMI Reverse Performance Adapter Maintenance Utility

Hashes

Type Hash
MD5 48D2B54B729DB3AACDD181BA3BD16DFF
SHA1 0B7F22CC31E3CA24EA60F2422D37571F91442238
SHA256 E2BA31E0F13310FC4BECBECEFC0253C4F7A7F76463A774EF3B434D46BF559291
SHA384 A695AEA9FCA5D22F7E3ACDF160471A6FDFC97B169F40AEFB5B4ECFFF62211FFAE343CD2CF95AAF7BE88A284E14048880
SHA512 221ECA48CB37E5252DBD387E415E1E39DF33A17FCCEDF84D57A88F0181E6527ED77B509CB17E8B52611D7899D05F5C3AA7EBDDED5B7F5F22317F362779D53F59
SSDEEP 1536:32cS5vyDlERp1EgLXL1luMiVHoGYsHJWD6xWTv+cIA+Y6hQay7kqJF0TMQ/Smcf0:S5vjoQhkMeoFI9AjdIRb6m2tishkX
IMP 4F983A9ED8F3DD91C6E9C506B9B53863
PESHA1 B8EC6BD7CF38C2ADFA0EB913D313B08ECF67DE81
PE256 0DC314D6F673E3C7D6F390594490373E0A4291AF0DB7B0713AD13F0EB0E8E8F3

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: wmicookr.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.17763.1 (WinBuild.160101.0800)
  • Product Version: 10.0.17763.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/66
  • VirusTotal Link: https://www.virustotal.com/gui/file/e2ba31e0f13310fc4becbecefc0253c4f7a7f76463a774ef3b434d46bf559291/detection/

Possible Misuse

The following table contains possible examples of WMIADAP.exe being misused. While WMIADAP.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_wmi_module_load.yml - '\windows\system32\wbem\WMIADAP.exe' # https://github.com/SigmaHQ/sigma/issues/1871 DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.