poqexec.exe

  • File Path: C:\Windows\system32\poqexec.exe
  • Description: Primitive Operations Queue Executor

Hashes

Type Hash
MD5 4895143A779A1B4A9465C7BF36BAEC29
SHA1 6AAB6FB59EA87DC2842825CE5737D3571208BC54
SHA256 164BC59090DC8FC229EB3F62D1C549C8F2496F31C3499A36A7359D1CD9768AE9
SHA384 4C21788298D56A5B503A0EA85204BCC571481353FD2B343CF0713DDEE9E925FF094795802F590F28CA9E143018EF9CE8
SHA512 266FAE8335CEFCA881046C035997CC9240FA8D7A24C5F7871D7990A35C3C6080E97E5E696FC6A9AF3819E85A2A89580D06CF1083ECF9976CEDD1BF414FA7B009
SSDEEP 3072:CvlYeTJue2RjE3vOB5C2o6gBMpZ4Nbso508IxFkfh:CvlYgJ+RjE/OB5Vo6vqNYw08I4f
IMP CF34294C2236A14E04714F40E66019C6
PESHA1 8F3DE05A109175ABEA746598D66137E715D0CC1D
PE256 4EC49FC9981D847F28916E53299DF3A102AF9D32AC1C0E19DF2AE5BBCCB61739

Signature

  • Status: Signature verified.
  • Serial: 33000001C422B2F79B793DACB20000000001C4
  • Thumbprint: AE9C1AE54763822EEC42474983D8B635116C8452
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: poqexec.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.17763.1 (WinBuild.160101.0800)
  • Product Version: 10.0.17763.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/70
  • VirusTotal Link: https://www.virustotal.com/gui/file/164bc59090dc8fc229eb3f62d1c549c8f2496f31c3499a36a7359d1cd9768ae9/detection/

Possible Misuse

The following table contains possible examples of poqexec.exe being misused. While poqexec.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma registry_event_asep_reg_keys_modification_common.yml - 'C:\Windows\System32\poqexec.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.