poqexec.exe
- File Path:
C:\WINDOWS\system32\poqexec.exe
- Description: Primitive Operations Queue Executor
Hashes
Type | Hash |
---|---|
MD5 | EFDC7B4304DABF8AD08D7938CD1EB5C7 |
SHA1 | 7A1EC627ACF68F966AC3DD61B6229631DB23799A |
SHA256 | 6B40DE3E54FD9E7595A390FC4F53797A37C8F483A931767DBCA4920A43278EF8 |
SHA384 | 142B23FABF4E7C688BE3719CE7AB42E31D40398C0E30BBA0D65D664D28C972578F8E88377E541B99C1B273676D59B1F2 |
SHA512 | 085319BCFE4B589659BB2EE5BC8839F73BC62B632F5F9136C05DBA3FD1661078A3F8789902FEB883C785FD6A2ABA60DEF5E99930132A86114C64576B57B2E1CB |
SSDEEP | 12288:hEFb+1YlEXY+4x+vG1s7239Qloat/HTS/69935l:hEFa1QEs6qX32FGyj5l |
IMP | 66848B325ADFC0D611995C02A6F63317 |
PESHA1 | 88F8176F918E8A9815E79F77BAD190202CFA77B7 |
PE256 | 461779DC0BE5344880433E5790BBF7C7287B8F4B9C968A1B6AECD79938B40692 |
Signature
- Status: Signature verified.
- Serial:
33000002ED2C45E4C145CF48440000000002ED
- Thumbprint:
312860D2047EB81F8F58C29FF19ECDB4C634CF6A
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: poqexec.exe.mui
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.22000.1 (WinBuild.160101.0800)
- Product Version: 10.0.22000.1
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
- Machine Type: 64-bit
File Scan
- VirusTotal Detections: 0/72
- VirusTotal Link: https://www.virustotal.com/gui/file/6b40de3e54fd9e7595a390fc4f53797a37c8f483a931767dbca4920a43278ef8/detection
Possible Misuse
The following table contains possible examples of poqexec.exe
being misused. While poqexec.exe
is not inherently malicious, its legitimate functionality can be abused for malicious purposes.
Source | Source File | Example | License |
---|---|---|---|
sigma | registry_event_asep_reg_keys_modification_common.yml | - 'C:\Windows\System32\poqexec.exe' |
DRL 1.0 |
MIT License. Copyright (c) 2020-2021 Strontic.