poqexec.exe

  • File Path: C:\Windows\SysWOW64\poqexec.exe
  • Description: Primitive Operations Queue Executor

Hashes

Type Hash
MD5 B505097DB4014E68D258D1FC1B0E7CC6
SHA1 DDE49E247FEBFA9E3F608CE4759C11FB3C0AEE06
SHA256 38DD837216199F9B58A55B52F6D96B7EB8602036ACB2FE888988E69CF1E8A033
SHA384 3E77044A1F60F84228D164EE7284DC109A45F2950D8BDEF4A34158425575D77F106BE3C5976FEEAAB2F4060B05883524
SHA512 6FDF52945287FBDEF9F5D5C89F4BB56D2F359EEC79A7712B4B4D44738D3391B839FF7DA51826402D3698E78DEB50F923EB9DE92E476A938062CEC9AD64C4A2CD
SSDEEP 6144:AW5uKmKkeyy33PInY24RQHMt/N+MP7ikF4e1a9ZpHBufqnPCOjvCa4aOnUWkQokT:AW5seyy339WsJN+MP7ikD1c3BufqnPCl
IMP 49D7FAB9D4B1A98A8BD1BC23B4876852
PESHA1 F66B3BE3CF816CC352ABA9DE8FE1845358479C31
PE256 B0FC63096AEF17934AF6592F675C31687F70CBA673312A3B157E77A4B9711DE2

Signature

  • Status: The file C:\Windows\SysWOW64\poqexec.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170
  • Serial: ``
  • Thumbprint: ``
  • Issuer:
  • Subject:

File Metadata

  • Original Filename: poqexec.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1310 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1310
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/68
  • VirusTotal Link: https://www.virustotal.com/gui/file/38dd837216199f9b58a55b52f6d96b7eb8602036acb2fe888988e69cf1e8a033/detection

File Similarity (ssdeep match)

File Score
C:\Windows\SysWOW64\poqexec.exe 93
C:\Windows\SysWOW64\poqexec.exe 93
C:\Windows\SysWOW64\poqexec.exe 93
C:\Windows\SysWOW64\poqexec.exe 93

Possible Misuse

The following table contains possible examples of poqexec.exe being misused. While poqexec.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma registry_event_asep_reg_keys_modification_common.yml - 'C:\Windows\System32\poqexec.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.