wbengine.exe

  • File Path: C:\WINDOWS\system32\wbengine.exe
  • Description: Microsoft Block Level Backup Engine Service EXE

Hashes

Type Hash
MD5 CB22B64FE34CF8CF21DECA597AC89754
SHA1 8226CE6C2940AF1DED47269158BD1EA264EC610C
SHA256 9279F0A909C8E1A950F82918B09AE0C0FF7E8FF9F8A0EDBEAE62D44D869642AB
SHA384 B2C5F59F250ECCE12E8745347C0AD729C4026F49B91E3D516A5B07ECEB19F4EC1B637E32B484BBC041DBCE8E00C54CB5
SHA512 5987A8B39440E0A00FE4148BCB3627700658A70B90C462838D95EA3A8F5BC810998CC3025DE28A0BD6548916431A79DD2F9C9CEE82E2B184AB028E196C514F60
SSDEEP 24576:Xsvjl6i34G1ZgyZorgw1EN8QbPio3kd8sM74ssLpEGofj0Y2VtDRY640VU2Iv:8vZ6i34G1ZgCordEN8Qzju6EpE6VtD+R

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: wbengine.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.18362.1 (WinBuild.160101.0800)
  • Product Version: 10.0.18362.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

Possible Misuse

The following table contains possible examples of wbengine.exe being misused. While wbengine.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma file_event_win_creation_system_file.yml Image: 'C:\Windows\system32\wbengine.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.