sdiagnhost.exe
- File Path:
C:\WINDOWS\system32\sdiagnhost.exe - Description: Scripted Diagnostics Native Host
Hashes
| Type | Hash |
|---|---|
| MD5 | 6458634E67F8AE415A0A871953C04F06 |
| SHA1 | 10F9F0BBB4B45D62E065451667FC4193F9ACB143 |
| SHA256 | DE77562E0BDD86A685D0C930122481F69E6A9EF9F2CB023BCA0DCFEC05D245E5 |
| SHA384 | 8BE0E7E787AFA73303E75CCA89E59CB99A35C8CB12C9F48191D6379A97D74FBD09E806F688EC9F175A6192124C0693B2 |
| SHA512 | AA814494ED1D6DAFDECCF9A1DDD4E47DB471F0AB19B0F652FB42EF5818C306278AF86536A2839485BF62E02F2ECDF5D273E49386207C2172AD62DAF9D04594C5 |
| SSDEEP | 384:yNaPLsFWEjuhHKkTy8YBFMQgkIBMyeL1McHGcMXgvaflllsd/OUxKilcWA7DW:IsL0W7gkz1+2xflTsMYKiw |
Runtime Data
Child Processes:
conhost.exe
Signature
- Status: Signature verified.
- Serial:
330000023241FB59996DCC4DFF000000000232 - Thumbprint:
FF82BC38E1DA5E596DF374C53E3617F7EDA36B06 - Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: sdiagnhost.exe.mui
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.18362.1 (WinBuild.160101.0800)
- Product Version: 10.0.18362.1
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
File Similarity (ssdeep match)
| File | Score |
|---|---|
| C:\windows\system32\sdiagnhost.exe | 29 |
| C:\Windows\system32\sdiagnhost.exe | 35 |
| C:\Windows\system32\sdiagnhost.exe | 74 |
Possible Misuse
The following table contains possible examples of sdiagnhost.exe being misused. While sdiagnhost.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.
| Source | Source File | Example | License |
|---|---|---|---|
| sigma | image_load_in_memory_powershell.yml | - '\WINDOWS\System32\sdiagnhost.exe' |
DRL 1.0 |
| sigma | image_load_wmi_module_load.yml | - '\sdiagnhost.exe' |
DRL 1.0 |
| sigma | image_load_wsman_provider_image_load.yml | - 'C:\Windows\System32\sdiagnhost.exe' |
DRL 1.0 |
| sigma | pipe_created_alternate_powershell_hosts_pipe.yml | - '\WINDOWS\System32\sdiagnhost.exe' |
DRL 1.0 |
| sigma | proc_access_win_in_memory_assembly_execution.yml | - '\Windows\System32\sdiagnhost.exe' |
DRL 1.0 |
| sigma | proc_creation_win_susp_csc_folder.yml | - '\sdiagnhost.exe' # https://twitter.com/gN3mes1s/status/1206874118282448897 |
DRL 1.0 |
MIT License. Copyright (c) 2020-2021 Strontic.