WMIADAP.exe
- File Path:
C:\Windows\system32\wbem\WMIADAP.exe
- Description: WMI Reverse Performance Adapter Maintenance Utility
Hashes
Type | Hash |
---|---|
MD5 | 48D2B54B729DB3AACDD181BA3BD16DFF |
SHA1 | 0B7F22CC31E3CA24EA60F2422D37571F91442238 |
SHA256 | E2BA31E0F13310FC4BECBECEFC0253C4F7A7F76463A774EF3B434D46BF559291 |
SHA384 | A695AEA9FCA5D22F7E3ACDF160471A6FDFC97B169F40AEFB5B4ECFFF62211FFAE343CD2CF95AAF7BE88A284E14048880 |
SHA512 | 221ECA48CB37E5252DBD387E415E1E39DF33A17FCCEDF84D57A88F0181E6527ED77B509CB17E8B52611D7899D05F5C3AA7EBDDED5B7F5F22317F362779D53F59 |
SSDEEP | 1536:32cS5vyDlERp1EgLXL1luMiVHoGYsHJWD6xWTv+cIA+Y6hQay7kqJF0TMQ/Smcf0:S5vjoQhkMeoFI9AjdIRb6m2tishkX |
IMP | 4F983A9ED8F3DD91C6E9C506B9B53863 |
PESHA1 | B8EC6BD7CF38C2ADFA0EB913D313B08ECF67DE81 |
PE256 | 0DC314D6F673E3C7D6F390594490373E0A4291AF0DB7B0713AD13F0EB0E8E8F3 |
Signature
- Status: Signature verified.
- Serial:
3300000266BD1580EFA75CD6D3000000000266
- Thumbprint:
A4341B9FD50FB9964283220A36A1EF6F6FAA7840
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: wmicookr.dll
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.17763.1 (WinBuild.160101.0800)
- Product Version: 10.0.17763.1
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
- Machine Type: 64-bit
File Scan
- VirusTotal Detections: 0/66
- VirusTotal Link: https://www.virustotal.com/gui/file/e2ba31e0f13310fc4becbecefc0253c4f7a7f76463a774ef3b434d46bf559291/detection/
Possible Misuse
The following table contains possible examples of WMIADAP.exe
being misused. While WMIADAP.exe
is not inherently malicious, its legitimate functionality can be abused for malicious purposes.
Source | Source File | Example | License |
---|---|---|---|
sigma | image_load_wmi_module_load.yml | - '\windows\system32\wbem\WMIADAP.exe' # https://github.com/SigmaHQ/sigma/issues/1871 |
DRL 1.0 |
MIT License. Copyright (c) 2020-2021 Strontic.