poqexec.exe

  • File Path: C:\WINDOWS\system32\poqexec.exe
  • Description: Primitive Operations Queue Executor

Hashes

Type Hash
MD5 EFDC7B4304DABF8AD08D7938CD1EB5C7
SHA1 7A1EC627ACF68F966AC3DD61B6229631DB23799A
SHA256 6B40DE3E54FD9E7595A390FC4F53797A37C8F483A931767DBCA4920A43278EF8
SHA384 142B23FABF4E7C688BE3719CE7AB42E31D40398C0E30BBA0D65D664D28C972578F8E88377E541B99C1B273676D59B1F2
SHA512 085319BCFE4B589659BB2EE5BC8839F73BC62B632F5F9136C05DBA3FD1661078A3F8789902FEB883C785FD6A2ABA60DEF5E99930132A86114C64576B57B2E1CB
SSDEEP 12288:hEFb+1YlEXY+4x+vG1s7239Qloat/HTS/69935l:hEFa1QEs6qX32FGyj5l
IMP 66848B325ADFC0D611995C02A6F63317
PESHA1 88F8176F918E8A9815E79F77BAD190202CFA77B7
PE256 461779DC0BE5344880433E5790BBF7C7287B8F4B9C968A1B6AECD79938B40692

Signature

  • Status: Signature verified.
  • Serial: 33000002ED2C45E4C145CF48440000000002ED
  • Thumbprint: 312860D2047EB81F8F58C29FF19ECDB4C634CF6A
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: poqexec.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.22000.1 (WinBuild.160101.0800)
  • Product Version: 10.0.22000.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/72
  • VirusTotal Link: https://www.virustotal.com/gui/file/6b40de3e54fd9e7595a390fc4f53797a37c8f483a931767dbca4920a43278ef8/detection

Possible Misuse

The following table contains possible examples of poqexec.exe being misused. While poqexec.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma registry_event_asep_reg_keys_modification_common.yml - 'C:\Windows\System32\poqexec.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.