WsmWmiPl.dll

  • File Path: C:\Windows\system32\WsmWmiPl.dll
  • Description: WSMAN WMI Provider

Hashes

Type Hash
MD5 364C0B8CB15BF30EAB4332BD774C9F81
SHA1 2676B5255FEACF48BEDDF4BC13FFAD6C4FB06BBC
SHA256 FC888B88B9994031ACD5409650D43E3D175CD88D3C8ED47FC99ED252D19B21D8
SHA384 EE68DD4960E7D50A34C3CF22925E23FD73A30E9E76E3B0EF62A351F6C11EB434D0BA15C311C94E2D883DB831FC153531
SHA512 3DDF02A769545DBF6FEC0E33E519191D284D324EF5706825A0F05047DCEFF07AAB1FA72DA419143DB0C616224AEF36E974F877F22812AC8CF0F9B54E28DA578D
SSDEEP 6144:uUDj4uXqJm2B6S6wiEdKvYaSvxmKKoOsxLp4yDRzA4/It:PXDqJm2B6NnyKvY/vUtrs9ayNn
IMP 82469943932CC96D7FE159FB18B1A039
PESHA1 76FA86DA16FDEED661922652145993CA826A6DBD
PE256 E8BF4EC67A9AEC0412387FF19D570F02F03B20838F4FB9E799F2C3421E571373

DLL Exports:

Function Name Ordinal Type
Locale::Key 11 Exported Function
Locale::Key 26 Exported Function
WSManPluginStartup 29 Exported Function
WSManPluginShutdown 28 Exported Function
Locale::Key 25 Exported Function
CWmiPtrCache::Mapping 9 Exported Function
Locale::Key 21 Exported Function
Locale::Key 10 Exported Function
CWmiPtrCache::Mapping 24 Exported Function
WSManProvCreate 30 Exported Function
WSManProvPut 37 Exported Function
WSManProvPullEvents 36 Exported Function
WSManProvUnsubscribe 39 Exported Function
WSManProvSubscribe 38 Exported Function
WSManProvInvoke 35 Exported Function
WSManProvEnumerate 32 Exported Function
WSManProvDelete 31 Exported Function
WSManProvIdentify 34 Exported Function
WSManProvGet 33 Exported Function
Locale::Key 16 Exported Function
Locale::Key 2 Exported Function
Locale::Key 4 Exported Function
Locale::Key 3 Exported Function
Locale::Key 5 Exported Function
Locale::Key 1 Exported Function
Locale::Key 14 Exported Function
Locale::Key 8 Exported Function
public: __cdecl CWSManCriticalSectionWithConditionVar::~CWSManCriticalSectionWithConditionVar(void) __ptr64 7 Exported Function
Locale::Key 27 Exported Function
Locale::Key 6 Exported Function
CWSManCriticalSection::GetInitError 17 Exported Function
Locale::Key 19 Exported Function
CWmiPtrCache::Mapping 20 Exported Function
CWmiPtrCache::Mapping 15 Exported Function
Locale::Key 18 Exported Function
Locale::Key 23 Exported Function
CWmiPtrCache::Mapping 22 Exported Function
Locale::Key 13 Exported Function
Locale::Key 12 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 330000026551AE1BBD005CBFBD000000000265
  • Thumbprint: E168609353F30FF2373157B4EB8CD519D07A2BFF
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: WsmWmiPl.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.488 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.488
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/66
  • VirusTotal Link: https://www.virustotal.com/gui/file/fc888b88b9994031acd5409650d43e3d175cd88d3c8ed47fc99ed252d19b21d8/detection/

Possible Misuse

The following table contains possible examples of WsmWmiPl.dll being misused. While WsmWmiPl.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_wsman_provider_image_load.yml OriginalFileName: 'WsmWmiPl.dll' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.