poqexec.exe

  • File Path: C:\WINDOWS\SysWOW64\poqexec.exe
  • Description: Primitive Operations Queue Executor

Hashes

Type Hash
MD5 C1DD43EEFC432256B56D9714789947EF
SHA1 E3AB724C1A18C05698B5F2DD321D7E14B89486CC
SHA256 44C2533656F31E342FBE8E6B0DF8098F85BC227CB72B6267A56D189F2C93AE66
SHA384 9837A5DE9F2A39B4572B03B24F5A7A466FC5CBF50272F1BDE24A4354F3B8FF3CD61F28E35D56EAB873CAB8717E5DCBBA
SHA512 03ED902F27E4CA80978AB1961F9312FDEFB6A5ED59E5E173C949A419E851BD9CD99AF94C0B7BD9662B7976DA3E0703AB6F38B47CE158C4BF8C95F7495FE0F5B5
SSDEEP 12288:Znl5CaYfLqUJD5hlrmlW5b4qvySZSUsItWIIyA6t:Zl5CaYfLqUJ1hlrmlWVeGlA6
IMP 6E192652B9CECAB0D1D4D4627F5F6369
PESHA1 2C1794276270F74B7FF5C2884AB669DF7F7047F8
PE256 F17F8B7FA6C4C7B831B6395380E7F6938E0B60A8DA0BE0E3C85AB00FB894EF1C

Signature

  • Status: Signature verified.
  • Serial: 33000002ED2C45E4C145CF48440000000002ED
  • Thumbprint: 312860D2047EB81F8F58C29FF19ECDB4C634CF6A
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: poqexec.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.22000.280 (WinBuild.160101.0800)
  • Product Version: 10.0.22000.280
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/72
  • VirusTotal Link: https://www.virustotal.com/gui/file/44c2533656f31e342fbe8e6b0df8098f85bc227cb72b6267a56d189f2c93ae66/detection

Possible Misuse

The following table contains possible examples of poqexec.exe being misused. While poqexec.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma registry_event_asep_reg_keys_modification_common.yml - 'C:\Windows\System32\poqexec.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.