Windows Analysis Report
548IrCt4hj

Overview

General Information

Sample Name: 548IrCt4hj (renamed file extension from none to dll)
Analysis ID: 672062
MD5: 7301880b88f87cd3a593f7106d5743cc
SHA1: c8a2b0ae061b612f4d4a4cfc4ee3e1f7079b4240
SHA256: c409ad4f64a1ad925ffbfdb88f57dd9177123364a1875caf6cbb6f5ba3970cc3
Tags: exeOpenCTIBRSandboxed
Infos:

Detection

Emotet
Score: 96
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
Yara detected Emotet
System process connects to network (likely due to code injection or exploit)
Antivirus detection for URL or domain
Snort IDS alert for network traffic
C2 URLs / IPs found in malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Queries the volume information (name, serial number etc) of a device
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
Deletes files inside the Windows folder
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Creates files inside the system directory
PE file contains sections with non-standard names
Internet Provider seen in connection with other malware
Detected potential crypto function
Found potential string decryption / allocating functions
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Program does not show much activity (idle)
IP address seen in connection with other malware
PE file contains an invalid checksum
Tries to load missing DLLs
Drops PE files to the windows directory (C:\Windows)
Detected TCP or UDP traffic on non-standard ports
Checks if the current process is being debugged
Connects to several IPs in different countries
Registers a DLL
Queries disk information (often used to detect virtual machines)
Found large amount of non-executed APIs
Creates a process in suspended mode (likely to inject code)

Classification

AV Detection

barindex
Source: 548IrCt4hj.dll Virustotal: Detection: 70% Perma Link
Source: 548IrCt4hj.dll Metadefender: Detection: 45% Perma Link
Source: 548IrCt4hj.dll ReversingLabs: Detection: 88%
Source: https://174.138.33.49/Z Avira URL Cloud: Label: malware
Source: https://174.138.33.49:7080/F Avira URL Cloud: Label: malware
Source: https://174.138.33.49:7080/Only Avira URL Cloud: Label: malware
Source: https://174.138.33.49:7080/r Avira URL Cloud: Label: malware
Source: https://174.138.33.49:7080/p Avira URL Cloud: Label: malware
Source: 0000000A.00000002.940180760.0000000000AEB000.00000004.00000020.00020000.00000000.sdmp Malware Configuration Extractor: Emotet {"C2 list": ["139.59.80.108:8080", "83.229.80.93:8080", "190.107.19.179:443", "202.134.4.210:7080", "165.232.185.110:8080", "104.244.79.94:443", "198.199.70.22:8080", "37.44.244.177:8080", "195.77.239.39:8080", "103.85.95.4:8080", "85.214.67.203:8080", "103.41.204.169:8080", "78.47.204.80:443", "190.145.8.4:443", "139.196.72.155:8080", "87.106.97.83:7080", "202.29.239.162:443", "202.28.34.99:8080", "54.37.106.167:8080", "103.224.241.74:8080", "103.254.12.236:7080", "188.165.79.151:443", "43.129.209.178:443", "37.187.114.15:8080", "5.253.30.17:7080", "54.37.228.122:443", "157.230.99.206:8080", "103.56.149.105:8080", "157.245.111.0:8080", "128.199.242.164:8080", "104.248.225.227:8080", "88.217.172.165:8080", "175.126.176.79:8080", "85.25.120.45:8080", "178.62.112.199:8080", "178.238.225.252:8080", "93.104.209.107:8080", "210.57.209.142:8080", "128.199.217.206:443", "103.71.99.57:8080", "64.227.55.231:8080"], "Public Key": ["RUNTMSAAAAD0LxqDNhonUYwk8sqo7IWuUllRdUiUBnACc6romsQoe1YJD7wIe4AheqYofpZFucPDXCZ0z9i+ooUffqeoLZU0EZiWsQAQAIg=", "RUNLMSAAAADYNZPXY4tQxd/N4Wn5sTYAm5tUOxY2ol1ELrI4MNhHNi640vSLasjYTHpFRBoG+o84vtr7AJachCzOHjaAJFCW45gAsQAmAIg="]}
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018006680C FindFirstFileExW,FindNextFileW,FindClose,FindClose, 5_2_000000018006680C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800671B0 FindFirstFileExW, 5_2_00000001800671B0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800677BC FindFirstFileExW,FindNextFileW,FindClose,FindClose, 5_2_00000001800677BC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CC9F0 FindFirstFileW,FindNextFileW, 10_2_024CC9F0

Networking

barindex
Source: C:\Windows\System32\regsvr32.exe Network Connect: 174.138.33.49 7080 Jump to behavior
Source: Traffic Snort IDS: 2404316 ET CNC Feodo Tracker Reported CnC Server TCP group 9 192.168.2.5:49768 -> 174.138.33.49:7080
Source: Malware configuration extractor IPs: 139.59.80.108:8080
Source: Malware configuration extractor IPs: 83.229.80.93:8080
Source: Malware configuration extractor IPs: 190.107.19.179:443
Source: Malware configuration extractor IPs: 202.134.4.210:7080
Source: Malware configuration extractor IPs: 165.232.185.110:8080
Source: Malware configuration extractor IPs: 104.244.79.94:443
Source: Malware configuration extractor IPs: 198.199.70.22:8080
Source: Malware configuration extractor IPs: 37.44.244.177:8080
Source: Malware configuration extractor IPs: 195.77.239.39:8080
Source: Malware configuration extractor IPs: 103.85.95.4:8080
Source: Malware configuration extractor IPs: 85.214.67.203:8080
Source: Malware configuration extractor IPs: 103.41.204.169:8080
Source: Malware configuration extractor IPs: 78.47.204.80:443
Source: Malware configuration extractor IPs: 190.145.8.4:443
Source: Malware configuration extractor IPs: 139.196.72.155:8080
Source: Malware configuration extractor IPs: 87.106.97.83:7080
Source: Malware configuration extractor IPs: 202.29.239.162:443
Source: Malware configuration extractor IPs: 202.28.34.99:8080
Source: Malware configuration extractor IPs: 54.37.106.167:8080
Source: Malware configuration extractor IPs: 103.224.241.74:8080
Source: Malware configuration extractor IPs: 103.254.12.236:7080
Source: Malware configuration extractor IPs: 188.165.79.151:443
Source: Malware configuration extractor IPs: 43.129.209.178:443
Source: Malware configuration extractor IPs: 37.187.114.15:8080
Source: Malware configuration extractor IPs: 5.253.30.17:7080
Source: Malware configuration extractor IPs: 54.37.228.122:443
Source: Malware configuration extractor IPs: 157.230.99.206:8080
Source: Malware configuration extractor IPs: 103.56.149.105:8080
Source: Malware configuration extractor IPs: 157.245.111.0:8080
Source: Malware configuration extractor IPs: 128.199.242.164:8080
Source: Malware configuration extractor IPs: 104.248.225.227:8080
Source: Malware configuration extractor IPs: 88.217.172.165:8080
Source: Malware configuration extractor IPs: 175.126.176.79:8080
Source: Malware configuration extractor IPs: 85.25.120.45:8080
Source: Malware configuration extractor IPs: 178.62.112.199:8080
Source: Malware configuration extractor IPs: 178.238.225.252:8080
Source: Malware configuration extractor IPs: 93.104.209.107:8080
Source: Malware configuration extractor IPs: 210.57.209.142:8080
Source: Malware configuration extractor IPs: 128.199.217.206:443
Source: Malware configuration extractor IPs: 103.71.99.57:8080
Source: Malware configuration extractor IPs: 64.227.55.231:8080
Source: Joe Sandbox View ASN Name: DIGITALOCEAN-ASNUS DIGITALOCEAN-ASNUS
Source: Joe Sandbox View ASN Name: DIGITALOCEAN-ASNUS DIGITALOCEAN-ASNUS
Source: Joe Sandbox View IP Address: 157.230.99.206 157.230.99.206
Source: Joe Sandbox View IP Address: 157.245.111.0 157.245.111.0
Source: global traffic TCP traffic: 192.168.2.5:49768 -> 174.138.33.49:7080
Source: unknown Network traffic detected: IP country count 17
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: svchost.exe, 00000019.00000003.551262839.0000015F2D570000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: Try it free for 30 days, no strings attached\r\n\r\nLike us on Facebook: http://www.facebook.com/spotify \r\nFollow us on Twitter: http://twitter.com/spotify","ProductTitle":"Spotify - Music and Podcasts","SearchTitles":[{"SearchTitleString":"Spotify","SearchTitleType":"SearchHint"},{"SearchTitleString":"Music","SearchTitleType":"SearchHint"},{"SearchTitleString":"music apps","SearchTitleType":"SearchHint"},{"SearchTitleString":"free music","SearchTitleType":"SearchHint"},{"SearchTitleString":"podcasts","SearchTitleType":"SearchHint"},{"SearchTitleString":"streaming","SearchTitleType":"SearchHint"},{"SearchTitleString":"soundcloud","SearchTitleType":"SearchHint"}],"Language":"en-us","Markets":["US","DZ","AR","AU","AT","BH","BD","BE","BR","BG","CA","CL","CN","CO","CR","HR","CY","CZ","DK","EG","EE","FI","FR","DE","GR","GT","HK","HU","IS","IN","ID","IQ","IE","IL","IT","JP","JO","KZ","KE","KW","LV","LB","LI","LT","LU","MY","MT","MR","MX","MA","NL","NZ","NG","NO","OM","PK","PE","PH","PL","PT","QA","RO","RU","SA","RS","SG","SK","SI","ZA","KR","ES","SE","CH","TW","TH","TT","TN","TR","UA","AE","GB","VN","YE","LY","LK","UY","VE","AF","AX","AL","AS","AO","AI","AQ","AG","AM","AW","BO","BQ","BA","BW","BV","IO","BN","BF","BI","KH","CM","CV","KY","CF","TD","TL","DJ","DM","DO","EC","SV","GQ","ER","ET","FK","FO","FJ","GF","PF","TF","GA","GM","GE","GH","GI","GL","GD","GP","GU","GG","GN","GW","GY","HT","HM","HN","AZ","BS","BB","BY","BZ","BJ","BM","BT","KM","CG","CD","CK","CX","CC","CI","CW","JM","SJ","JE","KI","KG","LA","LS","LR","MO","MK","MG","MW","IM","MH","MQ","MU","YT","FM","MD","MN","MS","MZ","MM","NA","NR","NP","MV","ML","NC","NI","NE","NU","NF","PW","PS","PA","PG","PY","RE","RW","BL","MF","WS","ST","SN","MP","PN","SX","SB","SO","SC","SL","GS","SH","KN","LC","PM","VC","TJ","TZ","TG","TK","TO","TM","TC","TV","UM","UG", equals www.facebook.com (Facebook)
Source: svchost.exe, 00000019.00000003.551262839.0000015F2D570000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: Try it free for 30 days, no strings attached\r\n\r\nLike us on Facebook: http://www.facebook.com/spotify \r\nFollow us on Twitter: http://twitter.com/spotify","ProductTitle":"Spotify - Music and Podcasts","SearchTitles":[{"SearchTitleString":"Spotify","SearchTitleType":"SearchHint"},{"SearchTitleString":"Music","SearchTitleType":"SearchHint"},{"SearchTitleString":"music apps","SearchTitleType":"SearchHint"},{"SearchTitleString":"free music","SearchTitleType":"SearchHint"},{"SearchTitleString":"podcasts","SearchTitleType":"SearchHint"},{"SearchTitleString":"streaming","SearchTitleType":"SearchHint"},{"SearchTitleString":"soundcloud","SearchTitleType":"SearchHint"}],"Language":"en-us","Markets":["US","DZ","AR","AU","AT","BH","BD","BE","BR","BG","CA","CL","CN","CO","CR","HR","CY","CZ","DK","EG","EE","FI","FR","DE","GR","GT","HK","HU","IS","IN","ID","IQ","IE","IL","IT","JP","JO","KZ","KE","KW","LV","LB","LI","LT","LU","MY","MT","MR","MX","MA","NL","NZ","NG","NO","OM","PK","PE","PH","PL","PT","QA","RO","RU","SA","RS","SG","SK","SI","ZA","KR","ES","SE","CH","TW","TH","TT","TN","TR","UA","AE","GB","VN","YE","LY","LK","UY","VE","AF","AX","AL","AS","AO","AI","AQ","AG","AM","AW","BO","BQ","BA","BW","BV","IO","BN","BF","BI","KH","CM","CV","KY","CF","TD","TL","DJ","DM","DO","EC","SV","GQ","ER","ET","FK","FO","FJ","GF","PF","TF","GA","GM","GE","GH","GI","GL","GD","GP","GU","GG","GN","GW","GY","HT","HM","HN","AZ","BS","BB","BY","BZ","BJ","BM","BT","KM","CG","CD","CK","CX","CC","CI","CW","JM","SJ","JE","KI","KG","LA","LS","LR","MO","MK","MG","MW","IM","MH","MQ","MU","YT","FM","MD","MN","MS","MZ","MM","NA","NR","NP","MV","ML","NC","NI","NE","NU","NF","PW","PS","PA","PG","PY","RE","RW","BL","MF","WS","ST","SN","MP","PN","SX","SB","SO","SC","SL","GS","SH","KN","LC","PM","VC","TJ","TZ","TG","TK","TO","TM","TC","TV","UM","UG", equals www.twitter.com (Twitter)
Source: svchost.exe, 00000019.00000003.551262839.0000015F2D570000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.550189528.0000015F2D582000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: Try it free for 30 days, no strings attached\r\n\r\nLike us on Facebook: http://www.facebook.com/spotify \r\nFollow us on Twitter: http://twitter.com/spotify","ProductTitle":"Spotify - Music and Podcasts","SearchTitles":[{"SearchTitleString":"Spotify","SearchTitleType":"SearchHint"},{"SearchTitleString":"Music","SearchTitleType":"SearchHint"},{"SearchTitleString":"music apps","SearchTitleType":"SearchHint"},{"SearchTitleString":"free music","SearchTitleType":"SearchHint"},{"SearchTitleString":"podcasts","SearchTitleType":"SearchHint"},{"SearchTitleString":"streaming","SearchTitleType":"SearchHint"},{"SearchTitleString":"soundcloud","SearchTitleType":"SearchHint"}],"Language":"en-us","Markets":["US","DZ","AR","AU","AT","BH","BD","BE","BR","BG","CA","CL","CN","CO","CR","HR","CY","CZ","DK","EG","EE","FI","FR","DE","GR","GT","HK","HU","IS","IN","ID","IQ","IE","IL","IT","JP","JO","KZ","KE","KW","LV","LB","LI","LT","LU","MY","MT","MR","MX","MA","NL","NZ","NG","NO","OM","PK","PE","PH","PL","PT","QA","RO","RU","SA","RS","SG","SK","SI","ZA","KR","ES","SE","CH","TW","TH","TT","TN","TR","UA","AE","GB","VN","YE","LY","LK","UY","VE","AF","AX","AL","AS","AO","AI","AQ","AG","AM","AW","BO","BQ","BA","BW","BV","IO","BN","BF","BI","KH","CM","CV","KY","CF","TD","TL","DJ","DM","DO","EC","SV","GQ","ER","ET","FK","FO","FJ","GF","PF","TF","GA","GM","GE","GH","GI","GL","GD","GP","GU","GG","GN","GW","GY","HT","HM","HN","AZ","BS","BB","BY","BZ","BJ","BM","BT","KM","CG","CD","CK","CX","CC","CI","CW","JM","SJ","JE","KI","KG","LA","LS","LR","MO","MK","MG","MW","IM","MH","MQ","MU","YT","FM","MD","MN","MS","MZ","MM","NA","NR","NP","MV","ML","NC","NI","NE","NU","NF","PW","PS","PA","PG","PY","RE","RW","BL","MF","WS","ST","SN","MP","PN","SX","SB","SO","SC","SL","GS","SH","KN","LC","PM","VC","TJ","TZ","TG","TK","TO","TM","TC","TV","UM","UG","VI","VG","WF","EH","ZM","ZW","UZ","VU","SR","SZ","AD","MC","SM","ME","VA","NEUTRAL"]}],"MarketProperties":[{"RelatedProducts":[],"Markets":["US"]}],"ProductASchema":"Product;3","ProductBSchema":"ProductUnifiedApp;3","ProductId":"9NCBCSZSJRSB","Properties":{"PackageFamilyName":"SpotifyAB.SpotifyMusic_zpdnekdrzrea0","PackageIdentityName":"SpotifyAB.SpotifyMusic","PublisherCertificateName":"CN=453637B3-4E12-4CDF-B0D3-2A3C863BF6EF","XboxCrossGenSetId":null,"XboxConsoleGenOptimized":null,"XboxConsoleGenCompatible":null},"AlternateIds":[{"IdType":"LegacyWindowsStoreProductId","Value":"ceac5d3f-8a4f-40e1-9a67-76d9108c7cb5"},{"IdType":"LegacyWindowsPhoneProductId","Value":"caac1b9d-621b-4f96-b143-e10e1397740a"},{"IdType":"XboxTitleId","Value":"1681279293"}],"IngestionSource":"DCE","IsMicrosoftProduct":false,"PreferredSkuId":"0010","ProductType":"Application","ValidationData":{"PassedValidation":false,"RevisionId":"2022-07-22T07:55:01.8237416Z||.||b7e2ac48-308b-4ab0-ad70-c01dd95863e0||1152921505695074449||Null||fullrelease","ValidationResultUri":""},"MerchandizingTags":[],"PartD":"","ProductFamily":"Apps","ProductKind":"Application","DisplaySkuAvailab
Source: svchost.exe, 00000019.00000003.551262839.0000015F2D570000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.550189528.0000015F2D582000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: Try it free for 30 days, no strings attached\r\n\r\nLike us on Facebook: http://www.facebook.com/spotify \r\nFollow us on Twitter: http://twitter.com/spotify","ProductTitle":"Spotify - Music and Podcasts","SearchTitles":[{"SearchTitleString":"Spotify","SearchTitleType":"SearchHint"},{"SearchTitleString":"Music","SearchTitleType":"SearchHint"},{"SearchTitleString":"music apps","SearchTitleType":"SearchHint"},{"SearchTitleString":"free music","SearchTitleType":"SearchHint"},{"SearchTitleString":"podcasts","SearchTitleType":"SearchHint"},{"SearchTitleString":"streaming","SearchTitleType":"SearchHint"},{"SearchTitleString":"soundcloud","SearchTitleType":"SearchHint"}],"Language":"en-us","Markets":["US","DZ","AR","AU","AT","BH","BD","BE","BR","BG","CA","CL","CN","CO","CR","HR","CY","CZ","DK","EG","EE","FI","FR","DE","GR","GT","HK","HU","IS","IN","ID","IQ","IE","IL","IT","JP","JO","KZ","KE","KW","LV","LB","LI","LT","LU","MY","MT","MR","MX","MA","NL","NZ","NG","NO","OM","PK","PE","PH","PL","PT","QA","RO","RU","SA","RS","SG","SK","SI","ZA","KR","ES","SE","CH","TW","TH","TT","TN","TR","UA","AE","GB","VN","YE","LY","LK","UY","VE","AF","AX","AL","AS","AO","AI","AQ","AG","AM","AW","BO","BQ","BA","BW","BV","IO","BN","BF","BI","KH","CM","CV","KY","CF","TD","TL","DJ","DM","DO","EC","SV","GQ","ER","ET","FK","FO","FJ","GF","PF","TF","GA","GM","GE","GH","GI","GL","GD","GP","GU","GG","GN","GW","GY","HT","HM","HN","AZ","BS","BB","BY","BZ","BJ","BM","BT","KM","CG","CD","CK","CX","CC","CI","CW","JM","SJ","JE","KI","KG","LA","LS","LR","MO","MK","MG","MW","IM","MH","MQ","MU","YT","FM","MD","MN","MS","MZ","MM","NA","NR","NP","MV","ML","NC","NI","NE","NU","NF","PW","PS","PA","PG","PY","RE","RW","BL","MF","WS","ST","SN","MP","PN","SX","SB","SO","SC","SL","GS","SH","KN","LC","PM","VC","TJ","TZ","TG","TK","TO","TM","TC","TV","UM","UG","VI","VG","WF","EH","ZM","ZW","UZ","VU","SR","SZ","AD","MC","SM","ME","VA","NEUTRAL"]}],"MarketProperties":[{"RelatedProducts":[],"Markets":["US"]}],"ProductASchema":"Product;3","ProductBSchema":"ProductUnifiedApp;3","ProductId":"9NCBCSZSJRSB","Properties":{"PackageFamilyName":"SpotifyAB.SpotifyMusic_zpdnekdrzrea0","PackageIdentityName":"SpotifyAB.SpotifyMusic","PublisherCertificateName":"CN=453637B3-4E12-4CDF-B0D3-2A3C863BF6EF","XboxCrossGenSetId":null,"XboxConsoleGenOptimized":null,"XboxConsoleGenCompatible":null},"AlternateIds":[{"IdType":"LegacyWindowsStoreProductId","Value":"ceac5d3f-8a4f-40e1-9a67-76d9108c7cb5"},{"IdType":"LegacyWindowsPhoneProductId","Value":"caac1b9d-621b-4f96-b143-e10e1397740a"},{"IdType":"XboxTitleId","Value":"1681279293"}],"IngestionSource":"DCE","IsMicrosoftProduct":false,"PreferredSkuId":"0010","ProductType":"Application","ValidationData":{"PassedValidation":false,"RevisionId":"2022-07-22T07:55:01.8237416Z||.||b7e2ac48-308b-4ab0-ad70-c01dd95863e0||1152921505695074449||Null||fullrelease","ValidationResultUri":""},"MerchandizingTags":[],"PartD":"","ProductFamily":"Apps","ProductKind":"Application","DisplaySkuAvailab
Source: regsvr32.exe, 0000000A.00000002.940537855.0000000000B80000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.480115635.0000000000B80000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000013.00000002.836628963.0000018894A9D000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000002.595043128.0000015F2CCE9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: svchost.exe, 00000013.00000002.836139820.00000188934BB000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000013.00000003.835512145.00000188934BB000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000002.595043128.0000015F2CCE9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.ver)
Source: regsvr32.exe, 0000000A.00000003.480159823.0000000000BA9000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.940603447.0000000000BA9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabV&V
Source: regsvr32.exe, 0000000A.00000003.480288771.0000000000B4B000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.480216789.0000000000B21000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.940449077.0000000000B4D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/enf
Source: svchost.exe, 00000019.00000003.568619378.0000015F2D586000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.568197795.0000015F2D598000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://help.disneyplus.com.
Source: regsvr32.exe, 0000000A.00000002.940330437.0000000000B21000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.480216789.0000000000B21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://174.138.33.49/
Source: regsvr32.exe, 0000000A.00000002.940330437.0000000000B21000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.480216789.0000000000B21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://174.138.33.49/Z
Source: regsvr32.exe, 0000000A.00000002.940330437.0000000000B21000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.480216789.0000000000B21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://174.138.33.49:7080/
Source: regsvr32.exe, 0000000A.00000002.940330437.0000000000B21000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.480216789.0000000000B21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://174.138.33.49:7080/F
Source: regsvr32.exe, 0000000A.00000002.940330437.0000000000B21000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.480216789.0000000000B21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://174.138.33.49:7080/Only
Source: regsvr32.exe, 0000000A.00000002.940330437.0000000000B21000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.480216789.0000000000B21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://174.138.33.49:7080/p
Source: regsvr32.exe, 0000000A.00000002.940330437.0000000000B21000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.480216789.0000000000B21000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://174.138.33.49:7080/r
Source: svchost.exe, 00000019.00000003.568619378.0000015F2D586000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.568197795.0000015F2D598000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://disneyplus.com/legal.
Source: svchost.exe, 00000019.00000003.563618298.0000015F2D599000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563853374.0000015F2D5A9000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563634572.0000015F2D5A9000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563884423.0000015F2DA19000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563734310.0000015F2D587000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563691195.0000015F2DA03000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563660153.0000015F2DA02000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://support.hotspotshield.com/
Source: svchost.exe, 00000019.00000003.568619378.0000015F2D586000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.568197795.0000015F2D598000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.disneyplus.com/legal/privacy-policy
Source: svchost.exe, 00000019.00000003.568619378.0000015F2D586000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.568197795.0000015F2D598000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.disneyplus.com/legal/your-california-privacy-rights
Source: svchost.exe, 00000019.00000003.563618298.0000015F2D599000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563853374.0000015F2D5A9000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563634572.0000015F2D5A9000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563884423.0000015F2DA19000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563734310.0000015F2D587000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563691195.0000015F2DA03000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563660153.0000015F2DA02000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.hotspotshield.com/terms/
Source: svchost.exe, 00000019.00000003.563618298.0000015F2D599000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563853374.0000015F2D5A9000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563634572.0000015F2D5A9000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563884423.0000015F2DA19000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563734310.0000015F2D587000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563691195.0000015F2DA03000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.563660153.0000015F2DA02000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.pango.co/privacy
Source: svchost.exe, 00000019.00000003.572982528.0000015F2D59A000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.572906706.0000015F2D5B0000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.572968023.0000015F2D589000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.573008527.0000015F2DA02000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000003.572949834.0000015F2D5B0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.tiktok.com/legal/report/feedback

E-Banking Fraud

barindex
Source: Yara match File source: 0000000A.00000002.940180760.0000000000AEB000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 7.2.rundll32.exe.1e034440000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.rundll32.exe.1f33eb00000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.regsvr32.exe.1120000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.rundll32.exe.1e034440000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.regsvr32.exe.c20000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.regsvr32.exe.c20000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.rundll32.exe.1f33eb00000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.regsvr32.exe.1120000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.424123479.000001E034440000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.940693332.0000000000C20000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.427012616.0000000001120000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.422757747.000001F33EB00000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.940812969.00000000024B1000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.422895400.000001F33EC51000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.424307117.000001E034471000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.427064425.0000000001151000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: C:\Windows\System32\regsvr32.exe File deleted: C:\Windows\System32\ZPLPsNKH\eFntQ.dll:Zone.Identifier Jump to behavior
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\system32\ZPLPsNKH\ Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180003026 5_2_0000000180003026
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180001D57 5_2_0000000180001D57
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800640D0 5_2_00000001800640D0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180034174 5_2_0000000180034174
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800019B5 5_2_00000001800019B5
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800013F7 5_2_00000001800013F7
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800011D6 5_2_00000001800011D6
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800018B6 5_2_00000001800018B6
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003442C 5_2_000000018003442C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180034574 5_2_0000000180034574
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018000427D 5_2_000000018000427D
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800346BC 5_2_00000001800346BC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003C6D4 5_2_000000018003C6D4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800013F7 5_2_00000001800013F7
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800013F7 5_2_00000001800013F7
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180034808 5_2_0000000180034808
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800039EA 5_2_00000001800039EA
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002C61 5_2_0000000180002C61
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800349B4 5_2_00000001800349B4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180060A88 5_2_0000000180060A88
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018004CAEC 5_2_000000018004CAEC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180034AFC 5_2_0000000180034AFC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180060A88 5_2_0000000180060A88
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002F5E 5_2_0000000180002F5E
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180001041 5_2_0000000180001041
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800026CB 5_2_00000001800026CB
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180034D8C 5_2_0000000180034D8C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800034EF 5_2_00000001800034EF
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180060F1C 5_2_0000000180060F1C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180034F34 5_2_0000000180034F34
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002C11 5_2_0000000180002C11
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002FCC 5_2_0000000180002FCC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800011DB 5_2_00000001800011DB
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180003C83 5_2_0000000180003C83
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003507C 5_2_000000018003507C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003D0B0 5_2_000000018003D0B0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018000285B 5_2_000000018000285B
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180003C33 5_2_0000000180003C33
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800351C4 5_2_00000001800351C4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002F72 5_2_0000000180002F72
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003530C 5_2_000000018003530C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800019E2 5_2_00000001800019E2
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800021C6 5_2_00000001800021C6
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180001DE3 5_2_0000000180001DE3
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800394B0 5_2_00000001800394B0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800354B4 5_2_00000001800354B4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002103 5_2_0000000180002103
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018004D588 5_2_000000018004D588
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180071584 5_2_0000000180071584
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003D5C4 5_2_000000018003D5C4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800029E1 5_2_00000001800029E1
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002900 5_2_0000000180002900
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180039710 5_2_0000000180039710
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800016AE 5_2_00000001800016AE
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800029AA 5_2_00000001800029AA
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002BE4 5_2_0000000180002BE4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018000321A 5_2_000000018000321A
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180001AC3 5_2_0000000180001AC3
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018000322E 5_2_000000018000322E
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180001302 5_2_0000000180001302
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180045B0C 5_2_0000000180045B0C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180001721 5_2_0000000180001721
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800019D8 5_2_00000001800019D8
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002E00 5_2_0000000180002E00
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003DD48 5_2_000000018003DD48
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180035D6C 5_2_0000000180035D6C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180001721 5_2_0000000180001721
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180003D8C 5_2_0000000180003D8C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002095 5_2_0000000180002095
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180035EFC 5_2_0000000180035EFC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002AA9 5_2_0000000180002AA9
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800025BD 5_2_00000001800025BD
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180001F87 5_2_0000000180001F87
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018005E068 5_2_000000018005E068
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180036074 5_2_0000000180036074
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003A148 5_2_000000018003A148
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800361BC 5_2_00000001800361BC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003E218 5_2_000000018003E218
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180036304 5_2_0000000180036304
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003A3B0 5_2_000000018003A3B0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800034F9 5_2_00000001800034F9
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180003634 5_2_0000000180003634
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800464AC 5_2_00000001800464AC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180003459 5_2_0000000180003459
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018006A5B0 5_2_000000018006A5B0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800365F4 5_2_00000001800365F4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003A618 5_2_000000018003A618
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800042AF 5_2_00000001800042AF
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018006680C 5_2_000000018006680C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002CDE 5_2_0000000180002CDE
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180001721 5_2_0000000180001721
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002F7C 5_2_0000000180002F7C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180046920 5_2_0000000180046920
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018004E924 5_2_000000018004E924
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002D1F 5_2_0000000180002D1F
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180003CB0 5_2_0000000180003CB0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180036B84 5_2_0000000180036B84
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180036CCC 5_2_0000000180036CCC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180003206 5_2_0000000180003206
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180036E14 5_2_0000000180036E14
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180046E30 5_2_0000000180046E30
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180003297 5_2_0000000180003297
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180036F5C 5_2_0000000180036F5C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002DE2 5_2_0000000180002DE2
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180004142 5_2_0000000180004142
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800330BC 5_2_00000001800330BC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180037104 5_2_0000000180037104
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180073160 5_2_0000000180073160
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800671B0 5_2_00000001800671B0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800631C4 5_2_00000001800631C4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180033204 5_2_0000000180033204
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003724C 5_2_000000018003724C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180001023 5_2_0000000180001023
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003334C 5_2_000000018003334C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180037394 5_2_0000000180037394
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180033498 5_2_0000000180033498
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800374DC 5_2_00000001800374DC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003B510 5_2_000000018003B510
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180003477 5_2_0000000180003477
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180033654 5_2_0000000180033654
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180037684 5_2_0000000180037684
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002829 5_2_0000000180002829
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018003379C 5_2_000000018003379C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800637A4 5_2_00000001800637A4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180001D2F 5_2_0000000180001D2F
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002C93 5_2_0000000180002C93
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800338E4 5_2_00000001800338E4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180037914 5_2_0000000180037914
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180004200 5_2_0000000180004200
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800043DB 5_2_00000001800043DB
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180001280 5_2_0000000180001280
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800012DF 5_2_00000001800012DF
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018000269E 5_2_000000018000269E
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180033BDC 5_2_0000000180033BDC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800019A6 5_2_00000001800019A6
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180033D24 5_2_0000000180033D24
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180033E6C 5_2_0000000180033E6C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800013F7 5_2_00000001800013F7
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002586 5_2_0000000180002586
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180033FB8 5_2_0000000180033FB8
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00E60000 5_2_00E60000
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116A804 5_2_0116A804
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116C8C0 5_2_0116C8C0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116EB08 5_2_0116EB08
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01168B3C 5_2_01168B3C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115CCC8 5_2_0115CCC8
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01167414 5_2_01167414
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0117B6BC 5_2_0117B6BC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01155B18 5_2_01155B18
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01161B88 5_2_01161B88
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116BD64 5_2_0116BD64
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01177E28 5_2_01177E28
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01166110 5_2_01166110
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116A130 5_2_0116A130
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011541A8 5_2_011541A8
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01174020 5_2_01174020
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01154078 5_2_01154078
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116406C 5_2_0116406C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0117A088 5_2_0117A088
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0117A304 5_2_0117A304
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01174330 5_2_01174330
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0117632C 5_2_0117632C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01164368 5_2_01164368
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115E254 5_2_0115E254
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01176520 5_2_01176520
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01160578 5_2_01160578
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01164594 5_2_01164594
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01166594 5_2_01166594
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116C5AC 5_2_0116C5AC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011525D8 5_2_011525D8
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01166418 5_2_01166418
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116A408 5_2_0116A408
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115C458 5_2_0115C458
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116E4A8 5_2_0116E4A8
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011784DC 5_2_011784DC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011624E4 5_2_011624E4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01152708 5_2_01152708
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116C720 5_2_0116C720
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116E7A4 5_2_0116E7A4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011627A4 5_2_011627A4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011707D0 5_2_011707D0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01172638 5_2_01172638
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01156698 5_2_01156698
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01160680 5_2_01160680
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011646B4 5_2_011646B4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01174918 5_2_01174918
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0117093C 5_2_0117093C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01154948 5_2_01154948
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01166978 5_2_01166978
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01178990 5_2_01178990
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011629BC 5_2_011629BC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116C9F0 5_2_0116C9F0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01152820 5_2_01152820
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116484C 5_2_0116484C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01154848 5_2_01154848
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01178B28 5_2_01178B28
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01176B40 5_2_01176B40
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01160B60 5_2_01160B60
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115CB6C 5_2_0115CB6C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116ABD8 5_2_0116ABD8
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01170AC4 5_2_01170AC4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01172AFC 5_2_01172AFC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01152AE4 5_2_01152AE4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115ED84 5_2_0115ED84
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01170DBC 5_2_01170DBC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01152DC0 5_2_01152DC0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01172C48 5_2_01172C48
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01154C64 5_2_01154C64
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01160C68 5_2_01160C68
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01170C68 5_2_01170C68
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01158CE0 5_2_01158CE0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116ACEC 5_2_0116ACEC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01172F3C 5_2_01172F3C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01176F3C 5_2_01176F3C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01158F5C 5_2_01158F5C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01162F94 5_2_01162F94
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116EFAC 5_2_0116EFAC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115EFCC 5_2_0115EFCC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115AFE4 5_2_0115AFE4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01172E04 5_2_01172E04
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116EE5C 5_2_0116EE5C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01174EF4 5_2_01174EF4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01178EE8 5_2_01178EE8
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01167144 5_2_01167144
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01155198 5_2_01155198
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115B1A8 5_2_0115B1A8
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011531F0 5_2_011531F0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01151014 5_2_01151014
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116B028 5_2_0116B028
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011530BC 5_2_011530BC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011590D4 5_2_011590D4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115B0F8 5_2_0115B0F8
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0117B0EC 5_2_0117B0EC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01173304 5_2_01173304
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115D300 5_2_0115D300
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01151368 5_2_01151368
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011593AC 5_2_011593AC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011713FC 5_2_011713FC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115B3E4 5_2_0115B3E4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011693E0 5_2_011693E0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01163210 5_2_01163210
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116F238 5_2_0116F238
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116D254 5_2_0116D254
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115F290 5_2_0115F290
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115B2BC 5_2_0115B2BC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011712FC 5_2_011712FC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011572E0 5_2_011572E0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0117155C 5_2_0117155C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116B558 5_2_0116B558
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0117B570 5_2_0117B570
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115F580 5_2_0115F580
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0117344C 5_2_0117344C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01155484 5_2_01155484
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011614A0 5_2_011614A0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116D4D0 5_2_0116D4D0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01163724 5_2_01163724
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01169720 5_2_01169720
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116F764 5_2_0116F764
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01163610 5_2_01163610
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116F61C 5_2_0116F61C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116D620 5_2_0116D620
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116762C 5_2_0116762C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0117369C 5_2_0117369C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115B698 5_2_0115B698
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011776A4 5_2_011776A4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011716A8 5_2_011716A8
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011536E0 5_2_011536E0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115D92C 5_2_0115D92C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0117796C 5_2_0117796C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116D9C4 5_2_0116D9C4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011699F4 5_2_011699F4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115F850 5_2_0115F850
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01173894 5_2_01173894
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_011678C4 5_2_011678C4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01167B24 5_2_01167B24
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115DB74 5_2_0115DB74
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01157BB4 5_2_01157BB4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01163BB4 5_2_01163BB4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01179A40 5_2_01179A40
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01153A9C 5_2_01153A9C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115FAD0 5_2_0115FAD0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01171AE0 5_2_01171AE0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01163D1C 5_2_01163D1C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115BD24 5_2_0115BD24
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0117BD20 5_2_0117BD20
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01171D2C 5_2_01171D2C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01169D5C 5_2_01169D5C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01167DB0 5_2_01167DB0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01179DA8 5_2_01179DA8
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01173DD4 5_2_01173DD4
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115BC08 5_2_0115BC08
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01167C30 5_2_01167C30
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01165C50 5_2_01165C50
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116FC70 5_2_0116FC70
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01157CAC 5_2_01157CAC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01153CE8 5_2_01153CE8
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01153F40 5_2_01153F40
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115DFCC 5_2_0115DFCC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01163E18 5_2_01163E18
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01175E30 5_2_01175E30
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0115FE58 5_2_0115FE58
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0117BE90 5_2_0117BE90
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01169EC0 5_2_01169EC0
Source: C:\Windows\System32\rundll32.exe Code function: 6_2_000001F33EAF0000 6_2_000001F33EAF0000
Source: C:\Windows\System32\rundll32.exe Code function: 7_2_000001E034430000 7_2_000001E034430000
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00C10000 10_2_00C10000
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CA804 10_2_024CA804
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D7E28 10_2_024D7E28
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CC8C0 10_2_024CC8C0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D3894 10_2_024D3894
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B7CAC 10_2_024B7CAC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024DB6BC 10_2_024DB6BC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B1368 10_2_024B1368
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C4368 10_2_024C4368
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CBD64 10_2_024CBD64
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024DA304 10_2_024DA304
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B5B18 10_2_024B5B18
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C8B3C 10_2_024C8B3C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D2F3C 10_2_024D2F3C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C7FEC 10_2_024C7FEC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CC9F0 10_2_024CC9F0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B41A8 10_2_024B41A8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C484C 10_2_024C484C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D344C 10_2_024D344C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B4848 10_2_024B4848
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D2C48 10_2_024D2C48
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D9A40 10_2_024D9A40
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CEE5C 10_2_024CEE5C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BFE58 10_2_024BFE58
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BC458 10_2_024BC458
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CD254 10_2_024CD254
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BF850 10_2_024BF850
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C5C50 10_2_024C5C50
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BE254 10_2_024BE254
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C406C 10_2_024C406C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C0C68 10_2_024C0C68
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D0C68 10_2_024D0C68
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B4C64 10_2_024B4C64
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B4078 10_2_024B4078
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CFC70 10_2_024CFC70
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BBC08 10_2_024BBC08
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CA408 10_2_024CA408
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D2E04 10_2_024D2E04
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CF61C 10_2_024CF61C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C6418 10_2_024C6418
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C3E18 10_2_024C3E18
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C7414 10_2_024C7414
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C3210 10_2_024C3210
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C3610 10_2_024C3610
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B1014 10_2_024B1014
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C762C 10_2_024C762C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CB028 10_2_024CB028
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B2820 10_2_024B2820
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CD620 10_2_024CD620
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D4020 10_2_024D4020
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CF238 10_2_024CF238
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D2638 10_2_024D2638
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C7C30 10_2_024C7C30
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D5E30 10_2_024D5E30
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BCCC8 10_2_024BCCC8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C78C4 10_2_024C78C4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D0AC4 10_2_024D0AC4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C9EC0 10_2_024C9EC0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D84DC 10_2_024D84DC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BFAD0 10_2_024BFAD0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CD4D0 10_2_024CD4D0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B90D4 10_2_024B90D4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CACEC 10_2_024CACEC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024DB0EC 10_2_024DB0EC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B3CE8 10_2_024B3CE8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D8EE8 10_2_024D8EE8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C24E4 10_2_024C24E4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B36E0 10_2_024B36E0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B72E0 10_2_024B72E0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B8CE0 10_2_024B8CE0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D1AE0 10_2_024D1AE0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B2AE4 10_2_024B2AE4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D12FC 10_2_024D12FC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D2AFC 10_2_024D2AFC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BB0F8 10_2_024BB0F8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D4EF4 10_2_024D4EF4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024DA088 10_2_024DA088
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C0680 10_2_024C0680
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B5484 10_2_024B5484
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D369C 10_2_024D369C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B6698 10_2_024B6698
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BB698 10_2_024BB698
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B3A9C 10_2_024B3A9C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BF290 10_2_024BF290
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024DBE90 10_2_024DBE90
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CE4A8 10_2_024CE4A8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D16A8 10_2_024D16A8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D76A4 10_2_024D76A4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C14A0 10_2_024C14A0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B30BC 10_2_024B30BC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BB2BC 10_2_024BB2BC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C46B4 10_2_024C46B4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B4948 10_2_024B4948
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C7144 10_2_024C7144
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B3F40 10_2_024B3F40
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D6B40 10_2_024D6B40
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C9D5C 10_2_024C9D5C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D155C 10_2_024D155C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CB558 10_2_024CB558
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B8F5C 10_2_024B8F5C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D796C 10_2_024D796C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BCB6C 10_2_024BCB6C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CF764 10_2_024CF764
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C0B60 10_2_024C0B60
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C6978 10_2_024C6978
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C0578 10_2_024C0578
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024DB570 10_2_024DB570
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BDB74 10_2_024BDB74
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B2708 10_2_024B2708
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CEB08 10_2_024CEB08
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D3304 10_2_024D3304
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BD300 10_2_024BD300
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C3D1C 10_2_024C3D1C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D4918 10_2_024D4918
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C6110 10_2_024C6110
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D1D2C 10_2_024D1D2C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D632C 10_2_024D632C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D8B28 10_2_024D8B28
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BD92C 10_2_024BD92C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C3724 10_2_024C3724
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C7B24 10_2_024C7B24
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CC720 10_2_024CC720
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C9720 10_2_024C9720
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024DBD20 10_2_024DBD20
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D6520 10_2_024D6520
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BBD24 10_2_024BBD24
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D093C 10_2_024D093C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D6F3C 10_2_024D6F3C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CA130 10_2_024CA130
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D4330 10_2_024D4330
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BDFCC 10_2_024BDFCC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BEFCC 10_2_024BEFCC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CD9C4 10_2_024CD9C4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B2DC0 10_2_024B2DC0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B25D8 10_2_024B25D8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CABD8 10_2_024CABD8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D3DD4 10_2_024D3DD4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D07D0 10_2_024D07D0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C93E0 10_2_024C93E0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BAFE4 10_2_024BAFE4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BB3E4 10_2_024BB3E4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D13FC 10_2_024D13FC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C99F4 10_2_024C99F4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B31F0 10_2_024B31F0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C1B88 10_2_024C1B88
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BF580 10_2_024BF580
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BED84 10_2_024BED84
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B5198 10_2_024B5198
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C2F94 10_2_024C2F94
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C4594 10_2_024C4594
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C6594 10_2_024C6594
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D8990 10_2_024D8990
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CC5AC 10_2_024CC5AC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CEFAC 10_2_024CEFAC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024BB1A8 10_2_024BB1A8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D9DA8 10_2_024D9DA8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B93AC 10_2_024B93AC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CE7A4 10_2_024CE7A4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C27A4 10_2_024C27A4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C29BC 10_2_024C29BC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024D0DBC 10_2_024D0DBC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C3BB4 10_2_024C3BB4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024C7DB0 10_2_024C7DB0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024B7BB4 10_2_024B7BB4
Source: C:\Windows\System32\regsvr32.exe Code function: String function: 000000018006BC48 appears 58 times
Source: C:\Windows\System32\regsvr32.exe Code function: String function: 00000001800019CE appears 79 times
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: 548IrCt4hj.dll Virustotal: Detection: 70%
Source: 548IrCt4hj.dll Metadefender: Detection: 45%
Source: 548IrCt4hj.dll ReversingLabs: Detection: 88%
Source: 548IrCt4hj.dll Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Windows\System32\loaddll64.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\548IrCt4hj.dll"
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\548IrCt4hj.dll",#1
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\548IrCt4hj.dll
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\548IrCt4hj.dll",#1
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\548IrCt4hj.dll,DllCanUnloadNow
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\ZPLPsNKH\eFntQ.dll"
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\548IrCt4hj.dll,DllGetClassObject
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\548IrCt4hj.dll,DllRegisterServer
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\548IrCt4hj.dll",#1 Jump to behavior
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\548IrCt4hj.dll Jump to behavior
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\548IrCt4hj.dll,DllCanUnloadNow Jump to behavior
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\548IrCt4hj.dll,DllGetClassObject Jump to behavior
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\548IrCt4hj.dll,DllRegisterServer Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\548IrCt4hj.dll",#1 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\ZPLPsNKH\eFntQ.dll" Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D105A4D4-344C-48EB-9866-EE378D90658B}\InProcServer32 Jump to behavior
Source: classification engine Classification label: mal96.troj.evad.winDLL@21/5@0/44
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800013F7 GetModuleFileNameW,CharNextW,LoadTypeLib,LoadTypeLib,SysAllocString,CoCreateInstance,StringFromGUID2,RegOpenKeyExW,RegQueryInfoKeyW,RegCloseKey,RegDeleteKeyW,RegOpenKeyExW,RegCloseKey,RegQueryInfoKeyW,RegCloseKey,RegDeleteKeyW,RegCloseKey,RegCloseKey,GetModuleHandleW,GetProcAddress,UnRegisterTypeLib,UnRegisterTypeLib,SysFreeString, 5_2_00000001800013F7
Source: C:\Windows\System32\regsvr32.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0116A804 Process32FirstW,CreateToolhelp32Snapshot,Process32NextW,FindCloseChangeNotification, 5_2_0116A804
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\548IrCt4hj.dll",#1
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180001721 LoadLibraryExW,LoadLibraryExW,FindResourceW,LoadResource,SizeofResource,MultiByteToWideChar,FreeLibrary,lstrcmpiW,lstrcmpiW,CharNextW,lstrcmpiW,lstrcmpiW,lstrcmpiW,RegOpenKeyExW,RegDeleteValueW,RegCloseKey,CharNextW,RegOpenKeyExW,RegCloseKey,RegOpenKeyExW,RegCloseKey,RegCreateKeyExW,RegCloseKey,RegCloseKey,RegOpenKeyExW,RegCloseKey,RegQueryInfoKeyW,lstrcmpiW,RegQueryInfoKeyW,RegCloseKey,RegDeleteKeyW,RegCloseKey,RegSetValueExW, 5_2_0000000180001721
Source: C:\Windows\System32\svchost.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Windows\System32\svchost.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Windows\System32\svchost.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Windows\System32\svchost.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Windows\System32\rundll32.exe Automated click: OK
Source: C:\Windows\System32\rundll32.exe Automated click: OK
Source: 548IrCt4hj.dll Static PE information: Image base 0x180000000 > 0x60000000
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_01158C72 push ebp; ret 5_2_01158C7D
Source: 548IrCt4hj.dll Static PE information: section name: .00cfg
Source: 548IrCt4hj.dll Static PE information: section name: _RDATA
Source: 548IrCt4hj.dll Static PE information: real checksum: 0xf69e3 should be: 0xf8045
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\548IrCt4hj.dll
Source: C:\Windows\System32\regsvr32.exe PE file moved: C:\Windows\System32\ZPLPsNKH\eFntQ.dll Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\System32\regsvr32.exe File opened: C:\Windows\system32\ZPLPsNKH\eFntQ.dll:Zone.Identifier read attributes | delete Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\svchost.exe TID: 5220 Thread sleep time: -30000s >= -30000s Jump to behavior
Source: C:\Windows\System32\svchost.exe TID: 6620 Thread sleep time: -30000s >= -30000s Jump to behavior
Source: C:\Windows\System32\svchost.exe TID: 6012 Thread sleep time: -90000s >= -30000s Jump to behavior
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\svchost.exe File opened: PhysicalDrive0 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe API coverage: 2.9 %
Source: C:\Windows\System32\regsvr32.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018006680C FindFirstFileExW,FindNextFileW,FindClose,FindClose, 5_2_000000018006680C
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800671B0 FindFirstFileExW, 5_2_00000001800671B0
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800677BC FindFirstFileExW,FindNextFileW,FindClose,FindClose, 5_2_00000001800677BC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_024CC9F0 FindFirstFileW,FindNextFileW, 10_2_024CC9F0
Source: C:\Windows\System32\regsvr32.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: svchost.exe, 00000013.00000002.836485099.0000018894A65000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000002.595056654.0000015F2CCF8000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: @Hyper-V RAW
Source: regsvr32.exe, 0000000A.00000003.480288771.0000000000B4B000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.480216789.0000000000B21000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.940449077.0000000000B4D000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000013.00000002.835848057.000001889342A000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000013.00000002.836463528.0000018894A54000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000002.595043128.0000015F2CCE9000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: svchost.exe, 00000015.00000002.940237565.000001D31EA02000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HvHostWdiSystemHostScDeviceEnumWiaRpctrkwksAudioEndpointBuilderhidservdot3svcDsSvcfhsvcWPDBusEnumsvsvcwlansvcEmbeddedModeirmonSensorServicevmicvssNgcSvcsysmainDevQueryBrokerStorSvcvmickvpexchangevmicshutdownvmicguestinterfacevmicvmsessionNcbServiceNetmanDeviceAssociationServiceTabletInputServicePcaSvcIPxlatCfgSvcCscServiceUmRdpService
Source: regsvr32.exe, 0000000A.00000002.940330437.0000000000B21000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.480216789.0000000000B21000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 00000019.00000002.594594939.0000015F2CC71000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW`
Source: svchost.exe, 00000015.00000002.940346278.000001D31EA28000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800041E7 GetLastError,IsDebuggerPresent,OutputDebugStringW, 5_2_00000001800041E7
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800041E7 GetLastError,IsDebuggerPresent,OutputDebugStringW, 5_2_00000001800041E7
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180002CD9 GetProcessHeap, 5_2_0000000180002CD9
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\loaddll64.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_000000018002BAEC RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 5_2_000000018002BAEC
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_0000000180003841 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 5_2_0000000180003841

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\System32\regsvr32.exe Network Connect: 174.138.33.49 7080 Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\548IrCt4hj.dll",#1 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation Jump to behavior
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW, 5_2_0000000180002B08
Source: C:\Windows\System32\regsvr32.exe Code function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW, 5_2_0000000180071D18
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 5_2_0000000180072138
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 5_2_00000001800721DC
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 5_2_00000001800722DC
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, 5_2_00000001800723C8
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW, 5_2_00000001800726A4
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, 5_2_0000000180072854
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW, 5_2_0000000180072960
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, 5_2_0000000180072AD8
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 5_2_000000018006B3D0
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 5_2_000000018006B534
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 5_2_000000018006B5DC
Source: C:\Windows\System32\regsvr32.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 5_2_00000001800031CA __security_init_cookie,GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, 5_2_00000001800031CA

Stealing of Sensitive Information

barindex
Source: Yara match File source: 0000000A.00000002.940180760.0000000000AEB000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 7.2.rundll32.exe.1e034440000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.rundll32.exe.1f33eb00000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.regsvr32.exe.1120000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.rundll32.exe.1e034440000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.regsvr32.exe.c20000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.regsvr32.exe.c20000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.rundll32.exe.1f33eb00000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.regsvr32.exe.1120000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.424123479.000001E034440000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.940693332.0000000000C20000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.427012616.0000000001120000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.422757747.000001F33EB00000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.940812969.00000000024B1000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.422895400.000001F33EC51000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.424307117.000001E034471000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.427064425.0000000001151000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs