WsmWmiPl.dll

  • File Path: C:\Windows\SysWOW64\WsmWmiPl.dll
  • Description: WSMAN WMI Provider

Hashes

Type Hash
MD5 C6D6D2AD8A7B263F210DA129FB18349B
SHA1 A863236DD7E05406DB3910BF0323EE16A53E1C4D
SHA256 19EA233228CF8966969B90C6249CEAF61C634F37B28BC44BBD7757BFD4A68200
SHA384 730F42C35E14ABF05CA5567E94916D9D57FF7C076793A7BADB816B53289941DFE8A142516B96658A9A9759A33FC9A664
SHA512 0E66900C84E35BAC523D94C59D1230764296F2EB8C3CE51345A8E5A9FEF100B64183175A9B6C9C2646F081E9E0F19026C519F526D241EE75D1B501440D64F20D
SSDEEP 3072:6G3+By044iTnhb74owmYizF1L4crHqxhxEugiUXymGlIbQPWqEwX/uc99FU2e3Rt:j3Uy0MhhFkxjfq0oQP5LX2oA3R
IMP EC2CD5333EF53D1DC1FB4D267DF836FA
PESHA1 586645C903684F7F2AF84082A4FD8A64BCD43C20
PE256 AFD41D6F694F154107EF819ED7F70E5A6E7A89AD079D921D20BFC98A27FA09BD

DLL Exports:

Function Name Ordinal Type
Locale::Key 11 Exported Function
Locale::Key 26 Exported Function
WSManPluginStartup 29 Exported Function
WSManPluginShutdown 28 Exported Function
Locale::Key 25 Exported Function
CWmiPtrCache::Mapping 9 Exported Function
Locale::Key 21 Exported Function
Locale::Key 10 Exported Function
CWmiPtrCache::Mapping 24 Exported Function
WSManProvCreate 30 Exported Function
WSManProvPut 37 Exported Function
WSManProvPullEvents 36 Exported Function
WSManProvUnsubscribe 39 Exported Function
WSManProvSubscribe 38 Exported Function
WSManProvInvoke 35 Exported Function
WSManProvEnumerate 32 Exported Function
WSManProvDelete 31 Exported Function
WSManProvIdentify 34 Exported Function
WSManProvGet 33 Exported Function
Locale::Key 16 Exported Function
Locale::Key 2 Exported Function
Locale::Key 4 Exported Function
Locale::Key 3 Exported Function
Locale::Key 5 Exported Function
Locale::Key 1 Exported Function
Locale::Key 14 Exported Function
Locale::Key 8 Exported Function
public: __thiscall CWSManCriticalSectionWithConditionVar::~CWSManCriticalSectionWithConditionVar(void) 7 Exported Function
Locale::Key 27 Exported Function
Locale::Key 6 Exported Function
CWSManCriticalSection::GetInitError 17 Exported Function
Locale::Key 19 Exported Function
CWmiPtrCache::Mapping 20 Exported Function
CWmiPtrCache::Mapping 15 Exported Function
Locale::Key 18 Exported Function
Locale::Key 23 Exported Function
CWmiPtrCache::Mapping 22 Exported Function
Locale::Key 13 Exported Function
Locale::Key 12 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: WsmWmiPl.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.488 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.488
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/70
  • VirusTotal Link: https://www.virustotal.com/gui/file/19ea233228cf8966969b90c6249ceaf61c634f37b28bc44bbd7757bfd4a68200/detection/

Possible Misuse

The following table contains possible examples of WsmWmiPl.dll being misused. While WsmWmiPl.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_wsman_provider_image_load.yml OriginalFileName: 'WsmWmiPl.dll' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.