makecab.exe

by Microsoft
System UtilityLOLBinmedium risk

Sources: 300M+ executions observed in the wild.

Summary

Windows Cabinet File creation utility - compresses files into .cab archives. Signed Microsoft binary that can be abused for data staging.

makecab.exe is the 542nd most commonly executed Windows program in EchoTrail's dataset, observed 9,816 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by TiWorker.exe.

Get this in your tools

The same record for makecab.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/makecab.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

542nd
most commonly executed Windows program
9,816
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\System3299.95%
  • C:\Windows\winsxs\amd64_microsoft-windows-makecab_31bf3856ad364e35_6.1.7600.16385_none_4cc4738d82efdf850.04%
  • C:\Windows\SysWOW640.01%

Top Hashes (SHA256)

  • f9ebaa95c93aa8ce217a4ad8715ccf2b7a3fc7a951da44b78a9bb2c53b9bcace24.85%
  • ba31ad8eca19c5fe03f6a5c64c8e0adfc7bd8d04b1f4e1c11d167467fd5261e920.15%
  • 6992e53ab2d927d6131142e328ba5d6d985c2a7eb64dc5cea4d8980dcf03e76815.95%
  • 8fab793da23798edbcce3c3ca73e8b62587ed6fcba28b73076ade3f610580bc18.25%
  • 925b31c2516090f291e78dbd285173a32f0d70bee5efabfa4e1145b9f85465638.17%
  • c55818c51e4a42dd2f9194ce754596a23f1ec3186092b1546b2409b1b3577c7e7.97%
  • 68b25a55eeafddc00e2b9aa52be0e7ab36cfc96f8c8de82ddf2ce888e557f08b3.05%
  • 59a1045b66ba8b8435df20c72b9c3aadcffb0553d98d0f0f46529589b9001a122.54%
  • 10a7e57d7ca6c9c41b2bb4c32a892e5d79b23a46ebd9f5d9f7e8c683e7bbd3c52.28%
  • 12d1e818c64d02f48c0a8a1094390329b8a65248e53e43d21ccf94e9a97015561.69%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Security Analysis

What does makecab.exe normally do?

Used by Windows Update, driver packaging, and SCCM for cabinet file creation. Common in software packaging workflows.

When is makecab.exe suspicious?

Compressing user data directories. Creating cab files in temp or staging directories. Execution by non-admin users on endpoints that do not perform software packaging.

How do attackers abuse makecab.exe?

Attackers use makecab to compress data before exfiltration. As a signed Microsoft binary, it bypasses application whitelisting. Can also be used to encode/decode files using the cabinet format.

Detection guidance

Monitor for makecab targeting sensitive directories. Alert on cabinet creation in unusual locations. Correlate with subsequent network transfer activity.

False positive notes

Windows Update, SCCM, and software packaging tools commonly use makecab.

MITRE ATT&CK techniques

References

Related Processes

expand.exeextrac32.exe

Ask Rocky about makecab.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for makecab.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.