wsqmcons.exe

  • File Path: C:\WINDOWS\system32\wsqmcons.exe
  • Description: Windows SQM Consolidator

Hashes

Type Hash
MD5 3198C8F020BC60931404167EEC51E2BF
SHA1 159BDCCD0831FE43E067DEE61F2C9F158C8FB3B5
SHA256 AF15B949D7D153536C56C396AE66D318BC3B18A09CFE1FD74E2BCF2BE3504AE5
SHA384 4EB824D97BDAC2B16649B8FEBC230EFCB310D60F63D96819322ACA95BA67426F510B2860782C2127BA5F5EC0C8204147
SHA512 B9077F05312078ED5A3849F104B17FAB9E1CE9EA6BA461AFB4AF91E4CD7A1494B6973E5F6DBF2B223CB4E55C123E82E665E87153E4A1D52B773C21C15125FC1E
SSDEEP 1536:RWLApNMLQn1YnotjyPrhFWe7H+E+PSZJHnGQumre2q6E:n09otOPV/3ZJHGQuCe28

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: wsqmcons.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.18362.1 (WinBuild.160101.0800)
  • Product Version: 10.0.18362.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\Windows\system32\wsqmcons.exe 35
C:\Windows\system32\wsqmcons.exe 40
C:\Windows\system32\wsqmcons.exe 32
C:\Windows\system32\wsqmcons.exe 40
C:\Windows\system32\wsqmcons.exe 36
C:\Windows\system32\wsqmcons.exe 38
C:\Windows\system32\wsqmcons.exe 40
C:\WINDOWS\system32\wsqmcons.exe 35

Possible Misuse

The following table contains possible examples of wsqmcons.exe being misused. While wsqmcons.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_apt_turla_comrat_may20.yml - '.WSqmCons))\|iex;' DRL 1.0
malware-ioc misp-turla-comrat-v4-event.json "value": "HKLM\\SOFTWARE\\Microsoft\\SQMClient\\Windows.WSqmCons", © ESET 2014-2018
malware-ioc turla * ++HKLM\SOFTWARE\Microsoft\SQMClient\Windows.WSqmCons++``{:.highlight .language-cmhg} © ESET 2014-2018

MIT License. Copyright (c) 2020-2021 Strontic.