sync64.exe

  • File Path: C:\SysinternalsSuite\sync64.exe
  • Description: Flush cached data to disk.

Hashes

Type Hash
MD5 45F3D0B8841CE1A52D81B3FB4222D17E
SHA1 2F2080350821E8A0D53A194DBE4C8D17BFF1AAC1
SHA256 27038CB10080D92915C08D08F3EC37A85BED87BDB05D47B90425917B00F4654F
SHA384 A68D20A24F77C2F40BAC9F097FA31086A007A39A618AF984041A4A27A0D3701E740D5E726EDBABED78452D8D8310FBFF
SHA512 87F402884C53FDB55FD140F3BB53D07065B5F8AC2CD8B49DE66475387607CC2E89D8EE12D3D27543B416D97F761BDEE6F832E63BC31EF7DC5D19A55520E7E4B9
SSDEEP 12288:T73/gVt4Gsd8O8/kIH46+jHd3JUSSkxJEWz:fStdBO8/kIH46+jHd3JURkxr
IMP 99197F3296550481A848EA8D4E097487
PESHA1 2B5D6A36224D60E4E1208399E9DEE83FBD0AFA9F
PE256 85C0EAA7891609337ECB697E41C5E454F73FD2BAE1FFA46D15BC39FAAFEAB323

Runtime Data

Usage (stdout):


Sync v2.2 - Flush cached data to disk.
Copyright (C) 2016 Mark Russinovich
Sysinternals - www.sysinternals.com


usage: sync [-r | drive letters]
   -r   Flush removeable media.
   -e   Eject removeable media.
   -nobanner
       Do not display the startup banner and copyright message.

Specifying explicit drive letters will flush only those drives.


Loaded Modules:

Path
C:\SysinternalsSuite\sync64.exe
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\ntdll.dll

Signature

  • Status: Signature verified.
  • Serial: 3300000187721772155940C709000000000187
  • Thumbprint: 2485A7AFA98E178CB8F30C9838346B514AEA4769
  • Issuer: CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: Sync.exe
  • Product Name: Sysinternals Sync
  • Company Name: Sysinternals - www.sysinternals.com
  • File Version: 2.2
  • Product Version: 2.2
  • Language: English (United States)
  • Legal Copyright: Copyright (C) 2016 Mark Russinovich
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/68
  • VirusTotal Link: https://www.virustotal.com/gui/file/27038cb10080d92915c08d08f3ec37a85bed87bdb05d47b90425917b00f4654f/detection/

Possible Misuse

The following table contains possible examples of sync64.exe being misused. While sync64.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_false_sysinternalsuite.yml - '\sync64.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.