Windows Analysis Report
UC2DFXQIBiE2kQ.dll

Overview

General Information

Sample Name: UC2DFXQIBiE2kQ.dll
Analysis ID: 747451
MD5: e2ec88ae31e147d1976368c6a8988d3c
SHA1: 937a21ced7f2663c923c9c614cbe06d95def511a
SHA256: ae7e655db35a71a3b2df96051d722d7995ec94feea3cbd59bec501042ab40847
Infos:

Detection

Emotet
Score: 84
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
Yara detected Emotet
System process connects to network (likely due to code injection or exploit)
Snort IDS alert for network traffic
Creates an autostart registry key pointing to binary in C:\Windows
C2 URLs / IPs found in malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Queries the volume information (name, serial number etc) of a device
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
Deletes files inside the Windows folder
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Creates files inside the system directory
PE file contains sections with non-standard names
Internet Provider seen in connection with other malware
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
Sample execution stops while process was sleeping (likely an evasion)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
IP address seen in connection with other malware
Tries to load missing DLLs
Drops PE files to the windows directory (C:\Windows)
Checks if the current process is being debugged
Connects to several IPs in different countries
Registers a DLL
Found large amount of non-executed APIs
Uses Microsoft's Enhanced Cryptographic Provider
Creates a process in suspended mode (likely to inject code)

Classification

AV Detection

barindex
Source: UC2DFXQIBiE2kQ.dll ReversingLabs: Detection: 80%
Source: 00000007.00000002.768477022.0000000001318000.00000004.00000020.00020000.00000000.sdmp Malware Configuration Extractor: Emotet {"C2 list": ["172.105.115.71:8080", "218.38.121.17:443", "186.250.48.5:443", "103.71.99.57:8080", "85.214.67.203:8080", "85.25.120.45:8080", "139.196.72.155:8080", "103.85.95.4:8080", "198.199.70.22:8080", "209.239.112.82:8080", "78.47.204.80:443", "36.67.23.59:443", "104.244.79.94:443", "62.171.178.147:8080", "195.77.239.39:8080", "103.56.149.105:8080", "80.211.107.116:8080", "93.104.209.107:8080", "174.138.33.49:7080", "202.28.34.99:8080", "178.62.112.199:8080", "114.79.130.68:443", "118.98.72.86:443", "103.41.204.169:8080", "178.238.225.252:8080", "83.229.80.93:8080", "46.101.98.60:8080", "82.98.180.154:7080", "87.106.97.83:7080", "196.44.98.190:8080", "139.59.80.108:8080", "103.224.241.74:8080", "103.254.12.236:7080", "185.148.169.10:8080", "165.22.254.236:8080", "37.44.244.177:8080", "54.37.228.122:443", "51.75.33.122:443", "128.199.217.206:443", "188.165.79.151:443", "210.57.209.142:8080", "160.16.143.191:8080", "175.126.176.79:8080", "202.134.4.210:7080", "103.126.216.86:443", "190.145.8.4:443", "128.199.242.164:8080", "64.227.55.231:8080"], "Public Key": ["RUNTMSAAAAD0LxqDNhonUYwk8sqo7IWuUllRdUiUBnACc6romsQoe1YJD7wIe4AheqYofpZFucPDXCZ0z9i+ooUffqeoLZU0IzjStTgSAJI=", "RUNLMSAAAADYNZPXY4tQxd/N4Wn5sTYAm5tUOxY2ol1ELrI4MNhHNi640vSLasjYTHpFRBoG+o84vtr7AJachCzOHjaAJFCW/zgWtVYeAJA="]}
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018004A020 CryptStringToBinaryA,CryptStringToBinaryA, 3_2_000000018004A020
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180029290 FindFirstFileExW, 3_2_0000000180029290
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002972C FindFirstFileExW,FindNextFileW,FindClose, 3_2_000000018002972C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180028B30 _invalid_parameter_noinfo,_invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,FindClose, 3_2_0000000180028B30
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180028B30 _invalid_parameter_noinfo,_invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,FindClose, 3_2_0000000180028B30

Networking

barindex
Source: C:\Windows\System32\regsvr32.exe Network Connect: 115.178.55.22 80 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 172.105.115.71 8080 Jump to behavior
Source: Traffic Snort IDS: 2404304 ET CNC Feodo Tracker Reported CnC Server TCP group 3 192.168.2.6:49714 -> 115.178.55.22:80
Source: Malware configuration extractor IPs: 172.105.115.71:8080
Source: Malware configuration extractor IPs: 218.38.121.17:443
Source: Malware configuration extractor IPs: 186.250.48.5:443
Source: Malware configuration extractor IPs: 103.71.99.57:8080
Source: Malware configuration extractor IPs: 85.214.67.203:8080
Source: Malware configuration extractor IPs: 85.25.120.45:8080
Source: Malware configuration extractor IPs: 139.196.72.155:8080
Source: Malware configuration extractor IPs: 103.85.95.4:8080
Source: Malware configuration extractor IPs: 198.199.70.22:8080
Source: Malware configuration extractor IPs: 209.239.112.82:8080
Source: Malware configuration extractor IPs: 78.47.204.80:443
Source: Malware configuration extractor IPs: 36.67.23.59:443
Source: Malware configuration extractor IPs: 104.244.79.94:443
Source: Malware configuration extractor IPs: 62.171.178.147:8080
Source: Malware configuration extractor IPs: 195.77.239.39:8080
Source: Malware configuration extractor IPs: 103.56.149.105:8080
Source: Malware configuration extractor IPs: 80.211.107.116:8080
Source: Malware configuration extractor IPs: 93.104.209.107:8080
Source: Malware configuration extractor IPs: 174.138.33.49:7080
Source: Malware configuration extractor IPs: 202.28.34.99:8080
Source: Malware configuration extractor IPs: 178.62.112.199:8080
Source: Malware configuration extractor IPs: 114.79.130.68:443
Source: Malware configuration extractor IPs: 118.98.72.86:443
Source: Malware configuration extractor IPs: 103.41.204.169:8080
Source: Malware configuration extractor IPs: 178.238.225.252:8080
Source: Malware configuration extractor IPs: 83.229.80.93:8080
Source: Malware configuration extractor IPs: 46.101.98.60:8080
Source: Malware configuration extractor IPs: 82.98.180.154:7080
Source: Malware configuration extractor IPs: 87.106.97.83:7080
Source: Malware configuration extractor IPs: 196.44.98.190:8080
Source: Malware configuration extractor IPs: 139.59.80.108:8080
Source: Malware configuration extractor IPs: 103.224.241.74:8080
Source: Malware configuration extractor IPs: 103.254.12.236:7080
Source: Malware configuration extractor IPs: 185.148.169.10:8080
Source: Malware configuration extractor IPs: 165.22.254.236:8080
Source: Malware configuration extractor IPs: 37.44.244.177:8080
Source: Malware configuration extractor IPs: 54.37.228.122:443
Source: Malware configuration extractor IPs: 51.75.33.122:443
Source: Malware configuration extractor IPs: 128.199.217.206:443
Source: Malware configuration extractor IPs: 188.165.79.151:443
Source: Malware configuration extractor IPs: 210.57.209.142:8080
Source: Malware configuration extractor IPs: 160.16.143.191:8080
Source: Malware configuration extractor IPs: 175.126.176.79:8080
Source: Malware configuration extractor IPs: 202.134.4.210:7080
Source: Malware configuration extractor IPs: 103.126.216.86:443
Source: Malware configuration extractor IPs: 190.145.8.4:443
Source: Malware configuration extractor IPs: 128.199.242.164:8080
Source: Malware configuration extractor IPs: 64.227.55.231:8080
Source: Joe Sandbox View ASN Name: LINODE-APLinodeLLCUS LINODE-APLinodeLLCUS
Source: Joe Sandbox View ASN Name: OVHFR OVHFR
Source: Joe Sandbox View IP Address: 172.105.115.71 172.105.115.71
Source: Joe Sandbox View IP Address: 188.165.79.151 188.165.79.151
Source: unknown Network traffic detected: IP country count 20
Source: unknown TCP traffic detected without corresponding DNS query: 115.178.55.22
Source: unknown TCP traffic detected without corresponding DNS query: 115.178.55.22
Source: unknown TCP traffic detected without corresponding DNS query: 115.178.55.22
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.115.71
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.115.71
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.115.71
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.115.71
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.115.71
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.115.71
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.115.71
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.115.71
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.115.71
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.115.71
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.115.71
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.115.71
Source: regsvr32.exe, 00000007.00000003.493404883.0000000001357000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000002.768679116.0000000001357000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: regsvr32.exe, 00000007.00000002.768740454.000000000136C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493786263.000000000136C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493440386.000000000136C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en
Source: regsvr32.exe, 00000007.00000002.768979503.00000000013A1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493501113.00000000013A1000.00000004.00000020.00020000.00000000.sdmp, 77EC63BDA74BD0D0E0426DC8F80085060.7.dr String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Source: regsvr32.exe, 00000007.00000002.768979503.00000000013A1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493501113.00000000013A1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabw
Source: regsvr32.exe, 00000007.00000003.493459160.000000000137D000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493884642.0000000001383000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000002.768834712.0000000001383000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493725445.0000000001380000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://112.105.115.71:8080/
Source: regsvr32.exe, 00000007.00000002.768740454.000000000136C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493786263.000000000136C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493440386.000000000136C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://172.105.115.71:8080/
Source: regsvr32.exe, 00000007.00000003.493459160.000000000137D000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000002.768740454.000000000136C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493786263.000000000136C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493884642.0000000001383000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000002.768834712.0000000001383000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493440386.000000000136C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493725445.0000000001380000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://172.105.115.71:8080/lskyxdliqorbrr/wjoazpr/kccttvfhu/
Source: regsvr32.exe, 00000007.00000002.768740454.000000000136C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493786263.000000000136C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493440386.000000000136C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://172.105.115.71:8080/lskyxdliqorbrr/wjoazpr/kccttvfhu/dll

E-Banking Fraud

barindex
Source: Yara match File source: 5.2.rundll32.exe.1fb00100000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.regsvr32.exe.960000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.rundll32.exe.1fb00100000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.rundll32.exe.1d676b30000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.rundll32.exe.1cc28be0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.rundll32.exe.1d676b30000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 16.2.regsvr32.exe.970000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.rundll32.exe.1cc28be0000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.regsvr32.exe.1540000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 16.2.regsvr32.exe.970000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.regsvr32.exe.1540000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.regsvr32.exe.960000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.769739205.0000000002E41000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.769387929.0000000001540000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000002.250855705.000001D676C81000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.251110585.000001FB00141000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.250957440.000001FB00100000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.258012521.0000000000C41000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.257855329.0000000000960000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.255048362.000001CC2A6A1000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000010.00000002.407582886.0000000000970000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000002.250572025.000001D676B30000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000010.00000002.408383126.0000000000B41000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.254840159.000001CC28BE0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: C:\Windows\System32\regsvr32.exe File deleted: C:\Windows\System32\IUvcffQnjRFArsrM\JZgYREHBQT.dll:Zone.Identifier Jump to behavior
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\system32\IUvcffQnjRFArsrM\ Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180044C30 3_2_0000000180044C30
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180031018 3_2_0000000180031018
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800391F8 3_2_00000001800391F8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180020204 3_2_0000000180020204
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001F22C 3_2_000000018001F22C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018003D23C 3_2_000000018003D23C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180029290 3_2_0000000180029290
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180024460 3_2_0000000180024460
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001F4B0 3_2_000000018001F4B0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800204D0 3_2_00000001800204D0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018003459C 3_2_000000018003459C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018003B5A0 3_2_000000018003B5A0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800305F8 3_2_00000001800305F8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180017604 3_2_0000000180017604
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001F74C 3_2_000000018001F74C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180032824 3_2_0000000180032824
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180037854 3_2_0000000180037854
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002B890 3_2_000000018002B890
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000A93C 3_2_000000018000A93C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018003A9A0 3_2_000000018003A9A0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001F9B4 3_2_000000018001F9B4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180026A0C 3_2_0000000180026A0C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180028B30 3_2_0000000180028B30
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002B890 3_2_000000018002B890
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001FC30 3_2_000000018001FC30
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180031C3C 3_2_0000000180031C3C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180028B30 3_2_0000000180028B30
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018003AE50 3_2_000000018003AE50
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001FF10 3_2_000000018001FF10
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180032F94 3_2_0000000180032F94
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00990000 3_2_00990000
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C648E0 3_2_00C648E0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C438A5 3_2_00C438A5
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4B1E0 3_2_00C4B1E0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C68C94 3_2_00C68C94
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C60454 3_2_00C60454
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C44DDC 3_2_00C44DDC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C45DB4 3_2_00C45DB4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C49E38 3_2_00C49E38
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4B8D0 3_2_00C4B8D0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C438DC 3_2_00C438DC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C598DC 3_2_00C598DC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C46880 3_2_00C46880
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5308C 3_2_00C5308C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5B898 3_2_00C5B898
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C64098 3_2_00C64098
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C510AC 3_2_00C510AC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C478B6 3_2_00C478B6
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C548B0 3_2_00C548B0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C6005C 3_2_00C6005C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C41000 3_2_00C41000
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4E828 3_2_00C4E828
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C42834 3_2_00C42834
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C469C0 3_2_00C469C0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4A1D4 3_2_00C4A1D4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5C1DC 3_2_00C5C1DC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C479D8 3_2_00C479D8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4D1E0 3_2_00C4D1E0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C499EC 3_2_00C499EC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C599E8 3_2_00C599E8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C57198 3_2_00C57198
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C559A0 3_2_00C559A0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4D1AC 3_2_00C4D1AC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C49144 3_2_00C49144
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C50954 3_2_00C50954
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4F174 3_2_00C4F174
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5C974 3_2_00C5C974
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C52110 3_2_00C52110
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C69124 3_2_00C69124
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C42128 3_2_00C42128
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C60930 3_2_00C60930
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4EAC4 3_2_00C4EAC4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C47AF0 3_2_00C47AF0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5B2F0 3_2_00C5B2F0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C62A84 3_2_00C62A84
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5629C 3_2_00C5629C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C6629C 3_2_00C6629C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C49298 3_2_00C49298
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C52244 3_2_00C52244
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5827C 3_2_00C5827C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C68A04 3_2_00C68A04
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5FA08 3_2_00C5FA08
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C41A1C 3_2_00C41A1C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4BA24 3_2_00C4BA24
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C61A2C 3_2_00C61A2C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C59230 3_2_00C59230
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4F3E0 3_2_00C4F3E0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C49BEC 3_2_00C49BEC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C43BE8 3_2_00C43BE8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C573F8 3_2_00C573F8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C57BF8 3_2_00C57BF8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4CB8D 3_2_00C4CB8D
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C62B8C 3_2_00C62B8C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5FB88 3_2_00C5FB88
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C53B88 3_2_00C53B88
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C44B4C 3_2_00C44B4C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C67348 3_2_00C67348
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C41B5C 3_2_00C41B5C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C46B5C 3_2_00C46B5C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C41364 3_2_00C41364
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4C364 3_2_00C4C364
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4E368 3_2_00C4E368
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C50310 3_2_00C50310
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C55B18 3_2_00C55B18
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5D32C 3_2_00C5D32C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C55334 3_2_00C55334
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C41CCC 3_2_00C41CCC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C484F8 3_2_00C484F8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C664F8 3_2_00C664F8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C6748C 3_2_00C6748C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4C498 3_2_00C4C498
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C44CA0 3_2_00C44CA0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C54C48 3_2_00C54C48
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C56464 3_2_00C56464
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C45478 3_2_00C45478
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C55400 3_2_00C55400
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4741C 3_2_00C4741C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C65D84 3_2_00C65D84
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C45590 3_2_00C45590
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C51DAC 3_2_00C51DAC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C60D54 3_2_00C60D54
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5F550 3_2_00C5F550
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C58560 3_2_00C58560
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4E570 3_2_00C4E570
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4BD00 3_2_00C4BD00
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C58D0C 3_2_00C58D0C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C55508 3_2_00C55508
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C49D24 3_2_00C49D24
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C53524 3_2_00C53524
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5B520 3_2_00C5B520
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C63D28 3_2_00C63D28
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C58ECC 3_2_00C58ECC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4AE84 3_2_00C4AE84
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C64680 3_2_00C64680
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C47694 3_2_00C47694
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C55694 3_2_00C55694
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C68690 3_2_00C68690
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4569C 3_2_00C4569C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C53698 3_2_00C53698
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C67EA4 3_2_00C67EA4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C496B8 3_2_00C496B8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C46650 3_2_00C46650
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C51664 3_2_00C51664
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C41660 3_2_00C41660
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5E614 3_2_00C5E614
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4BE34 3_2_00C4BE34
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C53FE0 3_2_00C53FE0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C52780 3_2_00C52780
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C54FA4 3_2_00C54FA4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C48FA0 3_2_00C48FA0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C597AC 3_2_00C597AC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C657B4 3_2_00C657B4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4FF64 3_2_00C4FF64
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5E76C 3_2_00C5E76C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C58778 3_2_00C58778
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4E708 3_2_00C4E708
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4871C 3_2_00C4871C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C61728 3_2_00C61728
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4A734 3_2_00C4A734
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5CF30 3_2_00C5CF30
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_000001D676B60000 4_2_000001D676B60000
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_000001FB00130000 5_2_000001FB00130000
Source: C:\Windows\System32\rundll32.exe Code function: 6_2_000001CC28C10000 6_2_000001CC28C10000
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_01420000 7_2_01420000
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E42A7C 7_2_02E42A7C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E49E38 7_2_02E49E38
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5FA08 7_2_02E5FA08
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E43BE8 7_2_02E43BE8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E573F8 7_2_02E573F8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5E76C 7_2_02E5E76C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5D718 7_2_02E5D718
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E648E0 7_2_02E648E0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E438DC 7_2_02E438DC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E62CBC 7_2_02E62CBC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4B1E0 7_2_02E4B1E0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E44DDC 7_2_02E44DDC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E45DB4 7_2_02E45DB4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E49144 7_2_02E49144
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E47AF0 7_2_02E47AF0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5B2F0 7_2_02E5B2F0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4EAC4 7_2_02E4EAC4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E58ECC 7_2_02E58ECC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E67EA4 7_2_02E67EA4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4C6A2 7_2_02E4C6A2
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E496B8 7_2_02E496B8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4AE84 7_2_02E4AE84
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E62A84 7_2_02E62A84
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E64680 7_2_02E64680
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E47694 7_2_02E47694
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E55694 7_2_02E55694
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E68690 7_2_02E68690
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4569C 7_2_02E4569C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5629C 7_2_02E5629C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E6629C 7_2_02E6629C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E49298 7_2_02E49298
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E53698 7_2_02E53698
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E51664 7_2_02E51664
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E41660 7_2_02E41660
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5827C 7_2_02E5827C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E52244 7_2_02E52244
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E46650 7_2_02E46650
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4BA24 7_2_02E4BA24
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E61A2C 7_2_02E61A2C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4BE34 7_2_02E4BE34
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E59230 7_2_02E59230
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E68A04 7_2_02E68A04
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5E614 7_2_02E5E614
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E41A1C 7_2_02E41A1C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4F3E0 7_2_02E4F3E0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E53FE0 7_2_02E53FE0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E49BEC 7_2_02E49BEC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E57BF8 7_2_02E57BF8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E54FA4 7_2_02E54FA4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E48FA0 7_2_02E48FA0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E597AC 7_2_02E597AC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E657B4 7_2_02E657B4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E647B0 7_2_02E647B0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E52780 7_2_02E52780
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E62B8C 7_2_02E62B8C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E53B88 7_2_02E53B88
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5FB88 7_2_02E5FB88
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E41364 7_2_02E41364
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4FF64 7_2_02E4FF64
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4C364 7_2_02E4C364
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4E368 7_2_02E4E368
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E58778 7_2_02E58778
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E44B4C 7_2_02E44B4C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E67348 7_2_02E67348
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E41B5C 7_2_02E41B5C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E46B5C 7_2_02E46B5C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5D32C 7_2_02E5D32C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E61728 7_2_02E61728
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E65B28 7_2_02E65B28
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4A734 7_2_02E4A734
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E55334 7_2_02E55334
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5CF30 7_2_02E5CF30
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4E708 7_2_02E4E708
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E50310 7_2_02E50310
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4871C 7_2_02E4871C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E55B18 7_2_02E55B18
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E484F8 7_2_02E484F8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E664F8 7_2_02E664F8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E41CCC 7_2_02E41CCC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4B8D0 7_2_02E4B8D0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E598DC 7_2_02E598DC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E44CA0 7_2_02E44CA0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E510AC 7_2_02E510AC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E478B6 7_2_02E478B6
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E548B0 7_2_02E548B0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E46880 7_2_02E46880
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5308C 7_2_02E5308C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E6748C 7_2_02E6748C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E68C94 7_2_02E68C94
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4C498 7_2_02E4C498
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5B898 7_2_02E5B898
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E64098 7_2_02E64098
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E56464 7_2_02E56464
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E45478 7_2_02E45478
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E54C48 7_2_02E54C48
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E60454 7_2_02E60454
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E6005C 7_2_02E6005C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4E828 7_2_02E4E828
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E42834 7_2_02E42834
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4CC06 7_2_02E4CC06
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E41000 7_2_02E41000
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E55400 7_2_02E55400
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E63C0C 7_2_02E63C0C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4741C 7_2_02E4741C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4D1E0 7_2_02E4D1E0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E499EC 7_2_02E499EC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E599E8 7_2_02E599E8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E469C0 7_2_02E469C0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4A1D4 7_2_02E4A1D4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5C1DC 7_2_02E5C1DC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E479D8 7_2_02E479D8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E559A0 7_2_02E559A0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4D1AC 7_2_02E4D1AC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E51DAC 7_2_02E51DAC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E65D84 7_2_02E65D84
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E45590 7_2_02E45590
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E57198 7_2_02E57198
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E58560 7_2_02E58560
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E69568 7_2_02E69568
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4F174 7_2_02E4F174
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5C974 7_2_02E5C974
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4E570 7_2_02E4E570
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E50954 7_2_02E50954
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E60D54 7_2_02E60D54
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5F550 7_2_02E5F550
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E49D24 7_2_02E49D24
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E53524 7_2_02E53524
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E69124 7_2_02E69124
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E5B520 7_2_02E5B520
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E42128 7_2_02E42128
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E63D28 7_2_02E63D28
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E60930 7_2_02E60930
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4BD00 7_2_02E4BD00
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E58D0C 7_2_02E58D0C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E55508 7_2_02E55508
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E52110 7_2_02E52110
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_009A0000 16_2_009A0000
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B438A5 16_2_00B438A5
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B68C94 16_2_00B68C94
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B648E0 16_2_00B648E0
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B60454 16_2_00B60454
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B45DB4 16_2_00B45DB4
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4B1E0 16_2_00B4B1E0
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B44DDC 16_2_00B44DDC
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B49E38 16_2_00B49E38
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B55B18 16_2_00B55B18
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B478B6 16_2_00B478B6
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B548B0 16_2_00B548B0
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B44CA0 16_2_00B44CA0
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B510AC 16_2_00B510AC
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4C498 16_2_00B4C498
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5B898 16_2_00B5B898
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B64098 16_2_00B64098
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B46880 16_2_00B46880
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5308C 16_2_00B5308C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B6748C 16_2_00B6748C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B484F8 16_2_00B484F8
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B664F8 16_2_00B664F8
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4B8D0 16_2_00B4B8D0
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B438DC 16_2_00B438DC
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B598DC 16_2_00B598DC
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B41CCC 16_2_00B41CCC
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B42834 16_2_00B42834
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4E828 16_2_00B4E828
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4741C 16_2_00B4741C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B41000 16_2_00B41000
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B55400 16_2_00B55400
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B63C0C 16_2_00B63C0C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B45478 16_2_00B45478
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4D864 16_2_00B4D864
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B56464 16_2_00B56464
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B6005C 16_2_00B6005C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B54C48 16_2_00B54C48
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B559A0 16_2_00B559A0
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4D1AC 16_2_00B4D1AC
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B51DAC 16_2_00B51DAC
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B45590 16_2_00B45590
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B57198 16_2_00B57198
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B65D84 16_2_00B65D84
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B499EC 16_2_00B499EC
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B599E8 16_2_00B599E8
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4A1D4 16_2_00B4A1D4
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5C1DC 16_2_00B5C1DC
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B479D8 16_2_00B479D8
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B469C0 16_2_00B469C0
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4D1CA 16_2_00B4D1CA
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B60930 16_2_00B60930
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B49D24 16_2_00B49D24
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B53524 16_2_00B53524
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B69124 16_2_00B69124
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5B520 16_2_00B5B520
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B42128 16_2_00B42128
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B63D28 16_2_00B63D28
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B52110 16_2_00B52110
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4BD00 16_2_00B4BD00
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B58D0C 16_2_00B58D0C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B55508 16_2_00B55508
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4F174 16_2_00B4F174
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5C974 16_2_00B5C974
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4E570 16_2_00B4E570
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B58560 16_2_00B58560
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B69568 16_2_00B69568
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B50954 16_2_00B50954
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B60D54 16_2_00B60D54
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5F550 16_2_00B5F550
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B49144 16_2_00B49144
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B496B8 16_2_00B496B8
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B67EA4 16_2_00B67EA4
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B47694 16_2_00B47694
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B55694 16_2_00B55694
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B68690 16_2_00B68690
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4569C 16_2_00B4569C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5629C 16_2_00B5629C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B6629C 16_2_00B6629C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B49298 16_2_00B49298
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B53698 16_2_00B53698
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4AE84 16_2_00B4AE84
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B62A84 16_2_00B62A84
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B64680 16_2_00B64680
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B47AF0 16_2_00B47AF0
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5B2F0 16_2_00B5B2F0
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4EAC4 16_2_00B4EAC4
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B58ECC 16_2_00B58ECC
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4BE34 16_2_00B4BE34
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B59230 16_2_00B59230
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4BA24 16_2_00B4BA24
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B61A2C 16_2_00B61A2C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5E614 16_2_00B5E614
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B41A1C 16_2_00B41A1C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B68A04 16_2_00B68A04
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5FA08 16_2_00B5FA08
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5827C 16_2_00B5827C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B51664 16_2_00B51664
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B41660 16_2_00B41660
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B46650 16_2_00B46650
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B52244 16_2_00B52244
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B657B4 16_2_00B657B4
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B647B0 16_2_00B647B0
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B54FA4 16_2_00B54FA4
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B48FA0 16_2_00B48FA0
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B597AC 16_2_00B597AC
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B52780 16_2_00B52780
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4CB8D 16_2_00B4CB8D
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B62B8C 16_2_00B62B8C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5FB88 16_2_00B5FB88
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B53B88 16_2_00B53B88
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B573F8 16_2_00B573F8
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B57BF8 16_2_00B57BF8
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4F3E0 16_2_00B4F3E0
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B53FE0 16_2_00B53FE0
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B49BEC 16_2_00B49BEC
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B43BE8 16_2_00B43BE8
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4A734 16_2_00B4A734
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B55334 16_2_00B55334
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5CF30 16_2_00B5CF30
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5D32C 16_2_00B5D32C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B61728 16_2_00B61728
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B65B28 16_2_00B65B28
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B50310 16_2_00B50310
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4871C 16_2_00B4871C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4E708 16_2_00B4E708
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B58778 16_2_00B58778
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B41364 16_2_00B41364
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4FF64 16_2_00B4FF64
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4C364 16_2_00B4C364
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5E76C 16_2_00B5E76C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4E368 16_2_00B4E368
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B46B5C 16_2_00B46B5C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B41B5C 16_2_00B41B5C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B44B4C 16_2_00B44B4C
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B67348 16_2_00B67348
Source: C:\Windows\System32\regsvr32.exe Code function: String function: 000000018002CA30 appears 48 times
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: UC2DFXQIBiE2kQ.dll ReversingLabs: Detection: 80%
Source: UC2DFXQIBiE2kQ.dll Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Windows\System32\loaddll64.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll"
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll",#1
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll",#1
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll,ACeujVZMknFDjv
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll,AHuDGMflBfPryOEYjuTfbzJdEM
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\IUvcffQnjRFArsrM\JZgYREHBQT.dll"
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll,ATjQPkInxPUGuUu
Source: unknown Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe" "C:\Windows\system32\IUvcffQnjRFArsrM\JZgYREHBQT.dll
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Users\user\AppData\Local\ZamKJmwegN\JeCOx.dll"
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll",#1 Jump to behavior
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll Jump to behavior
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll,ACeujVZMknFDjv Jump to behavior
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll,AHuDGMflBfPryOEYjuTfbzJdEM Jump to behavior
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll,ATjQPkInxPUGuUu Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll",#1 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\IUvcffQnjRFArsrM\JZgYREHBQT.dll" Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Users\user\AppData\Local\ZamKJmwegN\JeCOx.dll" Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe File created: C:\Users\user\AppData\Local\ZamKJmwegN\ Jump to behavior
Source: classification engine Classification label: mal84.troj.evad.winDLL@19/2@0/49
Source: C:\Windows\System32\regsvr32.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C45DB4 FindCloseChangeNotification,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW, 3_2_00C45DB4
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll",#1
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6088:120:WilError_01
Source: C:\Windows\System32\regsvr32.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Windows\System32\rundll32.exe Automated click: OK
Source: C:\Windows\System32\regsvr32.exe Automated click: OK
Source: Window Recorder Window detected: More than 3 window changes detected
Source: UC2DFXQIBiE2kQ.dll Static PE information: More than 250 > 100 exports found
Source: UC2DFXQIBiE2kQ.dll Static PE information: Image base 0x180000000 > 0x60000000
Source: UC2DFXQIBiE2kQ.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: UC2DFXQIBiE2kQ.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: UC2DFXQIBiE2kQ.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: UC2DFXQIBiE2kQ.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: UC2DFXQIBiE2kQ.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: UC2DFXQIBiE2kQ.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: UC2DFXQIBiE2kQ.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: UC2DFXQIBiE2kQ.dll Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: UC2DFXQIBiE2kQ.dll Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: UC2DFXQIBiE2kQ.dll Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: UC2DFXQIBiE2kQ.dll Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: UC2DFXQIBiE2kQ.dll Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800131BD push rdi; ret 3_2_00000001800131C4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180013749 push rdi; ret 3_2_0000000180013752
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5E0D3 push 09B8E1F7h; retf 3_2_00C5E0DD
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5E0E9 push 8B48E1F7h; retf 3_2_00C5E0F1
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C63127 push ebp; ret 3_2_00C63128
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C63A7E push ebp; ret 3_2_00C63A86
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C4838C push eax; ret 3_2_00C4838E
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C5E5C5 pushad ; ret 3_2_00C5E5C7
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C62E55 push ebp; retf 3_2_00C62E56
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C62F5E push ebp; ret 3_2_00C62F64
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_02E4838C push eax; ret 7_2_02E4838E
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5E0E9 push 8B48E1F7h; retf 16_2_00B5E0F1
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5E0D3 push 09B8E1F7h; retf 16_2_00B5E0DD
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B5E5C5 pushad ; ret 16_2_00B5E5C7
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B63127 push ebp; ret 16_2_00B63128
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B63A7E push ebp; ret 16_2_00B63A86
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B62E55 push ebp; retf 16_2_00B62E56
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B4838C push eax; ret 16_2_00B4838E
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B63BE1 push ebp; ret 16_2_00B63BE4
Source: C:\Windows\System32\regsvr32.exe Code function: 16_2_00B62F5E push ebp; ret 16_2_00B62F64
Source: UC2DFXQIBiE2kQ.dll Static PE information: section name: _RDATA
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll
Source: C:\Windows\System32\regsvr32.exe PE file moved: C:\Windows\System32\IUvcffQnjRFArsrM\JZgYREHBQT.dll Jump to behavior

Boot Survival

barindex
Source: C:\Windows\System32\regsvr32.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run JZgYREHBQT.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run JZgYREHBQT.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run JZgYREHBQT.dll Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\System32\regsvr32.exe File opened: C:\Windows\system32\IUvcffQnjRFArsrM\JZgYREHBQT.dll:Zone.Identifier read attributes | delete Jump to behavior
Source: C:\Windows\System32\regsvr32.exe File opened: C:\Users\user\AppData\Local\ZamKJmwegN\JeCOx.dll:Zone.Identifier read attributes | delete Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe TID: 4824 Thread sleep time: -60000s >= -30000s Jump to behavior
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\regsvr32.exe API coverage: 7.5 %
Source: C:\Windows\System32\regsvr32.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180029290 FindFirstFileExW, 3_2_0000000180029290
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002972C FindFirstFileExW,FindNextFileW,FindClose, 3_2_000000018002972C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180028B30 _invalid_parameter_noinfo,_invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,FindClose, 3_2_0000000180028B30
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180028B30 _invalid_parameter_noinfo,_invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,FindClose, 3_2_0000000180028B30
Source: C:\Windows\System32\regsvr32.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: regsvr32.exe, 00000007.00000003.493938602.0000000001394000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493459160.000000000137D000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000002.768933726.0000000001398000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493884642.0000000001383000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000002.768632966.000000000134F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493390937.000000000134F000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493725445.0000000001380000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: regsvr32.exe, 00000007.00000003.493938602.0000000001394000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493459160.000000000137D000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000002.768933726.0000000001398000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493884642.0000000001383000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000007.00000003.493725445.0000000001380000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180003460 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 3_2_0000000180003460
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002DE88 GetProcessHeap, 3_2_000000018002DE88
Source: C:\Windows\System32\loaddll64.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180003460 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 3_2_0000000180003460
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180003648 SetUnhandledExceptionFilter, 3_2_0000000180003648
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800156F8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 3_2_00000001800156F8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180002E94 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 3_2_0000000180002E94

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\System32\regsvr32.exe Network Connect: 115.178.55.22 80 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 172.105.115.71 8080 Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\UC2DFXQIBiE2kQ.dll",#1 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 3_2_0000000180035058
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, 3_2_0000000180035118
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 3_2_000000018002C360
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW, 3_2_0000000180035364
Source: C:\Windows\System32\regsvr32.exe Code function: try_get_function,GetLocaleInfoW, 3_2_000000018002D3CC
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 3_2_000000018002C40C
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 3_2_000000018002C488
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, 3_2_00000001800354BC
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW, 3_2_0000000180035590
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, 3_2_00000001800356BC
Source: C:\Windows\System32\regsvr32.exe Code function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW, 3_2_0000000180034BB8
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 3_2_0000000180034F04
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 3_2_0000000180034F88
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800243D0 cpuid 3_2_00000001800243D0
Source: C:\Windows\System32\regsvr32.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002D450 try_get_function,GetSystemTimeAsFileTime, 3_2_000000018002D450

Stealing of Sensitive Information

barindex
Source: Yara match File source: 5.2.rundll32.exe.1fb00100000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.regsvr32.exe.960000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.rundll32.exe.1fb00100000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.rundll32.exe.1d676b30000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.rundll32.exe.1cc28be0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.rundll32.exe.1d676b30000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 16.2.regsvr32.exe.970000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.rundll32.exe.1cc28be0000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.regsvr32.exe.1540000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 16.2.regsvr32.exe.970000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.regsvr32.exe.1540000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.regsvr32.exe.960000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.769739205.0000000002E41000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.769387929.0000000001540000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000002.250855705.000001D676C81000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.251110585.000001FB00141000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.250957440.000001FB00100000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.258012521.0000000000C41000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.257855329.0000000000960000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.255048362.000001CC2A6A1000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000010.00000002.407582886.0000000000970000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000002.250572025.000001D676B30000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000010.00000002.408383126.0000000000B41000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.254840159.000001CC28BE0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs