sdiagnhost.exe

  • File Path: C:\WINDOWS\system32\sdiagnhost.exe
  • Description: Scripted Diagnostics Native Host

Hashes

Type Hash
MD5 6458634E67F8AE415A0A871953C04F06
SHA1 10F9F0BBB4B45D62E065451667FC4193F9ACB143
SHA256 DE77562E0BDD86A685D0C930122481F69E6A9EF9F2CB023BCA0DCFEC05D245E5
SHA384 8BE0E7E787AFA73303E75CCA89E59CB99A35C8CB12C9F48191D6379A97D74FBD09E806F688EC9F175A6192124C0693B2
SHA512 AA814494ED1D6DAFDECCF9A1DDD4E47DB471F0AB19B0F652FB42EF5818C306278AF86536A2839485BF62E02F2ECDF5D273E49386207C2172AD62DAF9D04594C5
SSDEEP 384:yNaPLsFWEjuhHKkTy8YBFMQgkIBMyeL1McHGcMXgvaflllsd/OUxKilcWA7DW:IsL0W7gkz1+2xflTsMYKiw

Runtime Data

Child Processes:

conhost.exe

Signature

  • Status: Signature verified.
  • Serial: 330000023241FB59996DCC4DFF000000000232
  • Thumbprint: FF82BC38E1DA5E596DF374C53E3617F7EDA36B06
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: sdiagnhost.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.18362.1 (WinBuild.160101.0800)
  • Product Version: 10.0.18362.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\windows\system32\sdiagnhost.exe 29
C:\Windows\system32\sdiagnhost.exe 35
C:\Windows\system32\sdiagnhost.exe 74

Possible Misuse

The following table contains possible examples of sdiagnhost.exe being misused. While sdiagnhost.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_in_memory_powershell.yml - '\WINDOWS\System32\sdiagnhost.exe' DRL 1.0
sigma image_load_wmi_module_load.yml - '\sdiagnhost.exe' DRL 1.0
sigma image_load_wsman_provider_image_load.yml - 'C:\Windows\System32\sdiagnhost.exe' DRL 1.0
sigma pipe_created_alternate_powershell_hosts_pipe.yml - '\WINDOWS\System32\sdiagnhost.exe' DRL 1.0
sigma proc_access_win_in_memory_assembly_execution.yml - '\Windows\System32\sdiagnhost.exe' DRL 1.0
sigma proc_creation_win_susp_csc_folder.yml - '\sdiagnhost.exe' # https://twitter.com/gN3mes1s/status/1206874118282448897 DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.