ROUTE.EXE
by Microsoft
System Utility
Summary
Windows Route command - displays and modifies the IP routing table.
ROUTE.EXE is the 309th most commonly executed Windows program in EchoTrail's dataset, observed 31,433 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by spoolsv.exe.
309th
most commonly executed Windows program
31,433
observed executions
medium
statistical confidence
Behavior
Top Paths
- C:\Windows\System3296.93%
- C:\Windows\SysWOW643.07%
Top Hashes (SHA256)
- 85443a1256324c56aab48883c7097c9fdf81625aff5da4f4bfa4219dbd08368473.5%
- 9ac48831c17d1a46c48577e63a0a27604ed3e39761068e33ad867a77b865acc523.02%
- e51e2710a2ab52bcbb29717b4a6c4c58778f0aeaf58bdab9dfab791ff767e9561.78%
- 4dc7309d559c0a4d8e655127a26aafc2e942a272ad3965fd796aef022c5a1dd31.01%
- 9e9c7696859b94b1c33a532fa4d5c648226cf3361121dd899e502b8949fb11a60.24%
- 24970ca288e3c7a2cba348461def8912e90a5ca7fb11e7e16205111c8c0db8690.07%
- b8a28aeb6345ca88b04ff3d9fadf30eacf26958c991bd8e4fb1df12a68f60eae0.06%
- 3eeb168f75126e2dc62746e5231399e9b0f71e8b910195931189ddfc5edf88c60.05%
- b2797d230b7c5f7a9079d9c1dbe633a2b7ac4b72509f8ba237d84c7824d0d46a0.05%
- faa82727dd1a6fbc990a724e609b3f864b27f103088e89239d609cc208835ab20.05%
Process Ancestry
Top Grandparents
- services.exe95.67%
- wgsslvpnsrc.exe1.64%
- NETSTAT.EXE0.88%
- explorer.exe0.81%
- svchost.exe0.63%
- spoolsv.exe0.01%
- runonce.exe0.01%
- userinit.exe0.01%
Top Parents
- spoolsv.exe93.25%
- cmd.exe2.22%
- openvpn.exe1.23%
- sdiagnhost.exe0.36%
- openvpn-nordvpn.exe0.22%
- powershell.exe0.04%
- PanGPA.exe0.01%
- explorer.exe<0.01%
- vpnui.exe<0.01%
Top Children
- conhost.exe100%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Ask Rocky about ROUTE.EXE
Rocky answers questions about ROUTE.EXE grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.