poqexec.exe

  • File Path: C:\Windows\SysWOW64\poqexec.exe
  • Description: Primitive Operations Queue Executor

Hashes

Type Hash
MD5 74530CC0F5149D38B1F9D694C99CA1A2
SHA1 146887DAC2D6973C2F5F26E0593003D49805240A
SHA256 5679910005C1A1DF6705BDF6FD034A9EC023CD73981333C0F1CC621175A1F1E5
SHA384 C288C4F20C9E857C60201B6E61766712FF123E1B2D217A0E5FD77F0ADF63BD34460666D98B47D146BBC1DFBF8C4A0E60
SHA512 91F019B78D9B34BDAF3A0937EBA5DA9F2D6F058D83F344C1427588CE81882CC99E4782D0CDC9AD170B21D7968A025A0B09BD191C4310CFC6C56BF7816F92C2DC
SSDEEP 6144:lW5uKmK3eyy33PInY24RQHMt/N+MP7ikFvm1a9ZpHBufqnPCOjvCa4aOnUWkQok5:lW5feyy339WsJN+MP7ikc1c3BufqnPC/
IMP 49D7FAB9D4B1A98A8BD1BC23B4876852
PESHA1 53DAABE415A7E3D57380DE0BE09B2A372B767B38
PE256 882A457B46EC28F168E96BE5082FE2395B3561D03DC2C03D2D2400C4336C82CA

Signature

  • Status: The file C:\Windows\SysWOW64\poqexec.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170
  • Serial: ``
  • Thumbprint: ``
  • Issuer:
  • Subject:

File Metadata

  • Original Filename: poqexec.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.504 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.504
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/74
  • VirusTotal Link: https://www.virustotal.com/gui/file/5679910005c1a1df6705bdf6fd034a9ec023cd73981333c0f1cc621175a1f1e5/detection

File Similarity (ssdeep match)

File Score
C:\Windows\SysWOW64\poqexec.exe 99
C:\Windows\SysWOW64\poqexec.exe 93
C:\Windows\SysWOW64\poqexec.exe 99
C:\Windows\SysWOW64\poqexec.exe 97

Possible Misuse

The following table contains possible examples of poqexec.exe being misused. While poqexec.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma registry_event_asep_reg_keys_modification_common.yml - 'C:\Windows\System32\poqexec.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.