Could you please confirm that the following binaries are Windows built-ins or malicious ws operating systems

ADGP SCRB 10 Reputation points
2024-07-31T06:54:34.2633333+00:00

Dear Team

Please verify the legitimacy of the following files if discovered on an IIS web server, and provide an explanation of their standard functions within Windows operating systems:

Could you please confirm that the following binaries are Windows built-ins or malicious

\Windows\System32\CoreEvent.exe

\Windows\System32\inetsrv\cachsess.dll (or sess_cache.dll, or similarly named files)

\Windows\SysWOW64\inetsrv\cachsess.dll (or sess_cache.dll, or similarly named files)

Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,508 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Yanhong Liu 9,830 Reputation points Microsoft Vendor
    2024-08-01T03:18:35.75+00:00

    Hello,

    Thank you for posting in Q&A forum.

    1. \Windows\System32\CoreEvent.exe

    The CoreEvent.exe file name is not a standard Windows OS built-in process or service name. In a normal Windows installation, you should not see such a file in the System32 folder.

    If this file is present on the system, it is likely malware or installed by a third-party application. Therefore, if this file is found on your server, it is recommended to immediately conduct further investigation and scan it with anti-virus software.

    1. \Windows\System32\inetsrv\cachsess.dll (or sess_cache.dll)

    cachsess.dll and the similarly named sess_cache.dll are files related to IIS (Internet Information Services). These DLL files may be part of IIS and are used to cache session state data. However, please note that the standard DLL file name used by IIS may be different from this, so it is necessary to verify the file version and signature to confirm its authenticity.

    If these DLLs are legitimate IIS components, they will be used to manage HTTP session data, such as the user's login status or other session-related data. Make sure these DLL files have the correct digital signature and that the file version matches your IIS version.

    1. \Windows\SysWOW64\inetsrv\cachsess.dll (or sess_cache.dll)

    For 64-bit versions of Windows operating systems, the 32-bit version of the DLL file is placed in the SysWOW64 folder. If your system is 64-bit and you are running 32-bit IIS, there may be corresponding DLL files here. Again, you need to check the digital signature and version information of these files to confirm their legitimacy.

    The function of these DLL files is the same as mentioned above, that is, managing HTTP session data. Please ensure that these files are from the correct source.

    Note that final verification should be done by a security professional and antivirus software. You can use the Sigcheck tool to help verify the digital signature of your files, which is very useful for determining whether the file is from a trusted publisher. Sigcheck is a command-line utility that shows file version number, timestamp information, and digital signature details, including certificate chains. https://learn.microsoft.com/en-us/sysinternals/downloads/sigcheck

    Generally, if the file is not signed or the signature is invalid, it is recommended that you scan it with antivirus software and further investigate the source of these files. If the file signature is valid and the signer is trusted (such as Microsoft Corporation), then you can consider these files legitimate.

    Best Regards,

    Yanhong Liu

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.