unsecapp.exe

  • File Path: C:\Windows\system32\wbem\unsecapp.exe
  • Description: Sink to receive asynchronous callbacks for WMI client application

Hashes

Type Hash
MD5 4D379F091962CAF391CA99AEACC7203B
SHA1 865DB36C6B99968A207D3914117F5196E212AAFB
SHA256 1279842635C51D65672931D0ACEDEB2E3B54D2A4B9E77568BDF2ED380CA40AE8
SHA384 01CB087D7B4D2FFBDAD5E600EC0D6267CFB223D85229456D4EFCBEDA85225661D9F5258C748F6480462414C645FF99CF
SHA512 7BEE28CA1A1A375369AD3B5C86E0B468D26041830E60636C21F9382E981E6D9E1039A5C4CD4E09C6868502FADB6BACF0F27A7585CD3797956D61EB12AD24A273
SSDEEP 1536:FzAje3eVm2whnlaErDGa32TklXtK6bD+Bzn1RyfSfcQQZ:Fz8UFgErDGa32TklXk6bD+Bz1Y6M
IMP 87E54E3D04D772F26002D8B564B2426C
PESHA1 F1560AC1DE125D688EAA596CF1ADAA5CD6886EA9
PE256 0E2D0CE48449447A99B9948D0C0AE133584074D2D99F1A1A5E2D82D296721259

Runtime Data

Usage (stdout):

Cannot run standalone

Loaded Modules:

Path
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\system32\wbem\unsecapp.exe

Signature

  • Status: Signature verified.
  • Serial: 330000026551AE1BBD005CBFBD000000000265
  • Thumbprint: E168609353F30FF2373157B4EB8CD519D07A2BFF
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: unsecapp.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/68
  • VirusTotal Link: https://www.virustotal.com/gui/file/1279842635c51d65672931d0acedeb2e3b54d2a4b9e77568bdf2ed380ca40ae8/detection/

Possible Misuse

The following table contains possible examples of unsecapp.exe being misused. While unsecapp.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_wmi_module_load.yml - 'C:\Windows\System32\wbem\unsecapp.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.