wkspbroker.exe

  • File Path: C:\Windows\system32\wkspbroker.exe
  • Description: RemoteApp and Desktop Connection Runtime Broker

Hashes

Type Hash
MD5 11F8ED8D1C948A6ADC6A1A485A54946B
SHA1 839EBA54370927C33F6EC39B47A4569EF6084C7F
SHA256 88BE8968BFE5CCC7CE7A62EBAF83E3D41189E7B0BC0A374BF06885FC834982F1
SHA384 6A9425A6F3038EAEE4F7C7B9119AFDE979D9CA7828BD1159C0888CB2BA406CA23C9F67C5AF702DCB076A24397B81453C
SHA512 526D821F8754A1BBCD3C5D930FD29E28C0DA99EE16D954ECF5E361F686C6C7366A2CEE704DB4B446611BE4FD05722281095A62701E5CD7EA304BF4D4C128C608
SSDEEP 6144:7KqkTDzsMrStsM182CQ9L0kIE9bvkQw+1MAhIByWTHbPAPY:GqMzsMrStsM1Mkh9ja+1MRyWTMw
IMP E8BB23BDC005F28C00672133530047CC
PESHA1 371B3361AD87EDEF1B3BF63605DE13B3F406B7E6
PE256 0D5793D2971607A63CE95C29A4109B79F41123F734CFA705873379DFCD7A2736

Runtime Data

Loaded Modules:

Path
C:\Windows\System32\ADVAPI32.dll
C:\Windows\System32\GDI32.dll
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\sechost.dll
C:\Windows\System32\USER32.dll
C:\Windows\System32\win32u.dll
C:\Windows\system32\wkspbroker.exe

Signature

  • Status: Signature verified.
  • Serial: 33000002EC6579AD1E670890130000000002EC
  • Thumbprint: F7C2F2C96A328C13CDA8CDB57B715BDEA2CBD1D9
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: wkspbroker.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1151 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1151
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/72
  • VirusTotal Link: https://www.virustotal.com/gui/file/88be8968bfe5ccc7ce7a62ebaf83e3d41189e7b0bc0a374bf06885fc834982f1/detection

MIT License. Copyright (c) 2020-2021 Strontic.