unsecapp.exe

  • File Path: C:\Windows\system32\wbem\unsecapp.exe
  • Description: Sink to receive asynchronous callbacks for WMI client application

Hashes

Type Hash
MD5 2E49BB6C9F6599F518FE30BE2F000247
SHA1 1112D74CDCDB95243F22619703C216E293BB96C2
SHA256 20F499D581CF4AF331D8EC8B1E07A32CC1A695EF6790B51DA5EE223C5867154F
SHA384 C0437FCB6D6AB410FC04155434EF11723DD898B12A2006E1F9EDE850A2A29F0088EF4628C57EFF6404A2E8915393BE6C
SHA512 6CE443732A9FBCB928AF0CAD1BE7A60BBB2503004C582F09F586DE5591ED7115C60A20C346C43E9395031AD1ED4E28827788EAFF1B1DCDC00B0408B611C194C5
SSDEEP 768:IIhcv/LC1nUcEGg5X93oVEpWv+wIvZDYbPq1BI4o78SDBIx+4eT/x+QPWPSVT:I6cOqcEVXaapWvhmWTq1BFO8S15VT

Runtime Data

Usage (stdout):

Cannot run standalone

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: unsecapp.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.14393.2515 (rs1_release_1.180830-1044)
  • Product Version: 10.0.14393.2515
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

Possible Misuse

The following table contains possible examples of unsecapp.exe being misused. While unsecapp.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_wmi_module_load.yml - 'C:\Windows\System32\wbem\unsecapp.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.