msdtc.exe

by Microsoft
Operating Systemmedium risk

Sources: 300M+ executions observed in the wild.

Summary

Microsoft Distributed Transaction Coordinator - coordinates transactions spanning multiple resource managers (databases, message queues) across networked systems.

msdtc.exe is the 1026th most commonly executed Windows program in EchoTrail's dataset, observed 1,917 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by services.exe.

Get this in your tools

The same record for msdtc.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/msdtc.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

1026th
most commonly executed Windows program
1,917
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\System32100%

Top Hashes (SHA256)

  • 8a335c28fe1ef96dd71485877f2e86155d24b5614ace05468f4b07e2acd5633119.09%
  • 72db45ca11fe635df9f8273c38cbefb8df5362ada0cbf6d2b1e570365dc700c016.13%
  • ee84158da9a863daa633092f691761952de7888af01fd8020761cfd232e3bc8811.45%
  • 8ddc6d67a14b549946d103f2a5e7b1eb23c68bb6e7b8ecbc192365c7323ec4588.44%
  • 73c0829f641f62cbfc0523ed54d94121e3a694eccf148dbf4a5743631badb7147.37%
  • edfe71025c352d0dabec7b9506c5945bb0ec11f8db540db8cb1116c2ea1648a87.1%
  • 2fbbec4cacb5161f68d7c2935852a5888945ca0f107cf8a1c01f4528ce407de36.45%
  • 1eab4b9691e9efa1da02bdcb84035f65eda4b525e5aee925a6e1e4107f8e4f315.59%
  • 30b22ca09018d865a09efce286150072ebba5ad52b587e50404101d8db090c1e4.57%
  • 4cafce804d9135be9cbf80307d570f24e4a102890dab504e3deff3b335c9b80e4.41%

Process Ancestry

Top Grandparents

Top Parents

Security Analysis

What does msdtc.exe normally do?

Runs as a service on systems using distributed transactions (SQL Server, COM+, BizTalk). Coordinates two-phase commit across multiple databases.

When is msdtc.exe suspicious?

DLL loading from non-standard paths. Running on systems that do not use distributed transactions. Spawning unexpected child processes.

How do attackers abuse msdtc.exe?

MSDTC loads DLLs from a configurable path and has been used for DLL side-loading attacks. Attackers can place malicious DLLs in the MSDTC working directory for persistence and execution as SYSTEM.

Detection guidance

Monitor DLLs loaded by msdtc.exe. Alert on non-standard DLL paths. Detect modifications to the MSDTC service configuration.

False positive notes

Normal on SQL Server and application servers using distributed transactions.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about msdtc.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for msdtc.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.