DeviceCensus.exe

  • File Path: C:\Windows\system32\DeviceCensus.exe
  • Description: Device Census

Hashes

Type Hash
MD5 ABA7E7513886979AF8A3B68A1F4E591D
SHA1 A94E7B939A8A1007F6719503BE54A09F64801AC7
SHA256 AFD0D80A782E9392664CA32811055B958BD4D373F4F2BA52BFA8F7FE9C893190
SHA384 C17CC639144ADFCF68DEE0B8E98F82AFAC4F94E71651838090E22B4D87050D0F190E6F4107B17385DEB7FADD8F37EA51
SHA512 009BC8CC1F65585642813222884D2BE1882C0A09981DC4CC947925FEDEDAB9F8368DC19A1E9BF012477C68826B961134E96B90AE01DED6535A1F3F8AB1AC42DA
SSDEEP 384:1hbaEPVaYmPw5gyLjuCrHGOl2R3qj37nec/gWJXn7fRUWbgWPc32Kr6wDDBRJNSk:LmEsxwGPcrl08Cc/giXn7nSdr6wD1PSA
IMP 69755EB5A4F06F0B816F7B23B33E44E8
PESHA1 6522AD1A8757A9F38761C7E46AFCE10B8A2FF8F2
PE256 FAE15D42944FDAE6A68B1E5A83CCB5055F781C909009C3F44CAA668D4BA36E23

Runtime Data

Loaded Modules:

Path
C:\Windows\System32\bcryptPrimitives.dll
C:\Windows\System32\combase.dll
C:\Windows\system32\dcntel.dll
C:\Windows\system32\DeviceCensus.exe
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\shcore.dll
C:\Windows\System32\ucrtbase.dll

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: DeviceCensus.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19645.1016 (WinBuild.160101.0800)
  • Product Version: 10.0.19645.1016
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/69
  • VirusTotal Link: https://www.virustotal.com/gui/file/afd0d80a782e9392664ca32811055b958bd4d373f4f2ba52bfa8f7fe9c893190/detection/

File Similarity (ssdeep match)

File Score
C:\Windows\system32\6bea57fb-8dfb-4177-9ae8-42e8b3529933_RuntimeDeviceInstall.dll 32
C:\Windows\system32\DeviceCensus.exe 80
C:\Windows\system32\DeviceCensus.exe 86
C:\Windows\system32\LocationFrameworkPS.dll 32
C:\Windows\system32\migwiz\migres.dll 25
C:\Windows\system32\ResetEngine.exe 27
C:\Windows\system32\ResetEngine.exe 33
C:\Windows\system32\ScriptRunner.exe 32
C:\Windows\system32\ScriptRunner.exe 29
C:\Windows\system32\WerEnc.dll 30
C:\Windows\SystemApps\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\UndockedDevKit.exe 29
C:\Windows\SysWOW64\backgroundTaskHost.exe 29
C:\Windows\SysWOW64\dllhost.exe 32
C:\Windows\SysWOW64\ResourcePolicyClient.dll 36
C:\Windows\SysWOW64\WerEnc.dll 29

Possible Misuse

The following table contains possible examples of DeviceCensus.exe being misused. While DeviceCensus.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_wmi_module_load.yml - '\DeviceCensus.exe' DRL 1.0
sigma registry_event_asep_reg_keys_modification_currentversion.yml - 'C:\WINDOWS\system32\devicecensus.exe' DRL 1.0
sigma registry_event_telemetry_persistence.yml - '\system32\DeviceCensus.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.