poqexec.exe

  • File Path: C:\Windows\SysWOW64\poqexec.exe
  • Description: Primitive Operations Queue Executor

Hashes

Type Hash
MD5 3C14CEA2018AEB67B71627D8CFA07656
SHA1 5014AAE4492FD83FADB48D29BB1C5CAE51207DA9
SHA256 ED38D575D3CE8E16710182C17AFC86181FFA23B9023156938C2C14141279867F
SHA384 A0591D1F36A25439AB42908DE5A664F06BD6BD29F2A87DE453F18583293DA4C245E4545965F4C26F5A4117143C3D9F7C
SHA512 D9EA11AC1DF1683D42039F685343A72461577B7E423CFA02551BEBF4D9C9DB51B317950F3933BE089AF0F877DE32063B672813AD98F783DE634E86851DBB33E1
SSDEEP 3072:PbaVDo9SW3a81e6EmAwGqeXK1RfzRf9xSPCI2DAP:Pb8aSW3a81u/qe61RbR2qi
IMP 19FE0F206F9F2BBD963A860D56552FBB
PESHA1 027E387210927B592C6C979BF4AC695093E8069A
PE256 C2A17CAF87E6B7C603F7B203BFDD469692D65DD718FCB23FABEE28B3FBDE765E

Signature

  • Status: Signature verified.
  • Serial: 33000001C422B2F79B793DACB20000000001C4
  • Thumbprint: AE9C1AE54763822EEC42474983D8B635116C8452
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: poqexec.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.17763.1 (WinBuild.160101.0800)
  • Product Version: 10.0.17763.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/69
  • VirusTotal Link: https://www.virustotal.com/gui/file/ed38d575d3ce8e16710182c17afc86181ffa23b9023156938c2c14141279867f/detection/

Possible Misuse

The following table contains possible examples of poqexec.exe being misused. While poqexec.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma registry_event_asep_reg_keys_modification_common.yml - 'C:\Windows\System32\poqexec.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.