sdiagnhost.exe
- File Path:
C:\WINDOWS\system32\sdiagnhost.exe
- Description: Scripted Diagnostics Native Host
Hashes
Type | Hash |
---|---|
MD5 | 6458634E67F8AE415A0A871953C04F06 |
SHA1 | 10F9F0BBB4B45D62E065451667FC4193F9ACB143 |
SHA256 | DE77562E0BDD86A685D0C930122481F69E6A9EF9F2CB023BCA0DCFEC05D245E5 |
SHA384 | 8BE0E7E787AFA73303E75CCA89E59CB99A35C8CB12C9F48191D6379A97D74FBD09E806F688EC9F175A6192124C0693B2 |
SHA512 | AA814494ED1D6DAFDECCF9A1DDD4E47DB471F0AB19B0F652FB42EF5818C306278AF86536A2839485BF62E02F2ECDF5D273E49386207C2172AD62DAF9D04594C5 |
SSDEEP | 384:yNaPLsFWEjuhHKkTy8YBFMQgkIBMyeL1McHGcMXgvaflllsd/OUxKilcWA7DW:IsL0W7gkz1+2xflTsMYKiw |
Runtime Data
Child Processes:
conhost.exe
Signature
- Status: Signature verified.
- Serial:
330000023241FB59996DCC4DFF000000000232
- Thumbprint:
FF82BC38E1DA5E596DF374C53E3617F7EDA36B06
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: sdiagnhost.exe.mui
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.18362.1 (WinBuild.160101.0800)
- Product Version: 10.0.18362.1
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
File Similarity (ssdeep match)
File | Score |
---|---|
C:\windows\system32\sdiagnhost.exe | 29 |
C:\Windows\system32\sdiagnhost.exe | 35 |
C:\Windows\system32\sdiagnhost.exe | 74 |
Possible Misuse
The following table contains possible examples of sdiagnhost.exe
being misused. While sdiagnhost.exe
is not inherently malicious, its legitimate functionality can be abused for malicious purposes.
Source | Source File | Example | License |
---|---|---|---|
sigma | image_load_in_memory_powershell.yml | - '\WINDOWS\System32\sdiagnhost.exe' |
DRL 1.0 |
sigma | image_load_wmi_module_load.yml | - '\sdiagnhost.exe' |
DRL 1.0 |
sigma | image_load_wsman_provider_image_load.yml | - 'C:\Windows\System32\sdiagnhost.exe' |
DRL 1.0 |
sigma | pipe_created_alternate_powershell_hosts_pipe.yml | - '\WINDOWS\System32\sdiagnhost.exe' |
DRL 1.0 |
sigma | proc_access_win_in_memory_assembly_execution.yml | - '\Windows\System32\sdiagnhost.exe' |
DRL 1.0 |
sigma | proc_creation_win_susp_csc_folder.yml | - '\sdiagnhost.exe' # https://twitter.com/gN3mes1s/status/1206874118282448897 |
DRL 1.0 |
MIT License. Copyright (c) 2020-2021 Strontic.