poqexec.exe

  • File Path: C:\Windows\SysWOW64\poqexec.exe
  • Description: Primitive Operations Queue Executor

Hashes

Type Hash
MD5 321A3CCA44AD6CA3F23572E3BFA14E58
SHA1 9134708F75C9C39EF2C9272DCB0806AA3B72E173
SHA256 15D8B726FD2371C094AF15D320421EF061D53EF6869AE27C7E9575F06BBB192F
SHA384 8A24FD94EA86246F1DE8848921758EC57B86BEC717F07C8D72879A1D8066DB8EE7930FEB2EFF4480B5A1F45723AA55BD
SHA512 5ACC31FCB60D2F3DB6F0DB95B573574BEE3450B76103A5906A4C1D96F8628E409AF6A8AE4C93CFA6B485500FB9B71DBC55885D2672926D555F46F1B2D12DDF96
SSDEEP 6144:MW5uKmK3eyy33PInY24RQHMt/N+MP7ikFvm1a9ZpHBufqnPCOjvCa4aOnUWkQok5:MW5feyy339WsJN+MP7ikc1c3BufqnPC3

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: poqexec.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.329 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.329
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\Windows\SysWOW64\poqexec.exe 99
C:\Windows\SysWOW64\poqexec.exe 93
C:\Windows\SysWOW64\poqexec.exe 99
C:\Windows\SysWOW64\poqexec.exe 97

Possible Misuse

The following table contains possible examples of poqexec.exe being misused. While poqexec.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma registry_event_asep_reg_keys_modification_common.yml - 'C:\Windows\System32\poqexec.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.