Windows Analysis Report
f_00321b.dll

Overview

General Information

Sample Name: f_00321b.dll
(renamed file extension from none to dll, renamed because original name is a hash value)
Original Sample Name: f_00321b
Analysis ID: 829558
MD5: bfc060937dc90b273eccb6825145f298
SHA1: c156c00c7e918f0cb7363614fb1f177c90d8108a
SHA256: 2f39c2879989ddd7f9ecf52b6232598e5595f8bf367846ff188c9dfbf1251253
Infos:

Detection

Emotet
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Early bird code injection technique detected
Multi AV Scanner detection for submitted file
Yara detected Emotet
System process connects to network (likely due to code injection or exploit)
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Snort IDS alert for network traffic
Queues an APC in another process (thread injection)
C2 URLs / IPs found in malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Queries the volume information (name, serial number etc) of a device
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Deletes files inside the Windows folder
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Creates files inside the system directory
PE file contains sections with non-standard names
Internet Provider seen in connection with other malware
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Sample execution stops while process was sleeping (likely an evasion)
JA3 SSL client fingerprint seen in connection with other malware
Contains functionality to call native functions
HTTP GET or POST without a user agent
Contains functionality which may be used to detect a debugger (GetProcessHeap)
IP address seen in connection with other malware
Tries to load missing DLLs
Drops PE files to the windows directory (C:\Windows)
Detected TCP or UDP traffic on non-standard ports
Checks if the current process is being debugged
Connects to several IPs in different countries
Registers a DLL
Found large amount of non-executed APIs
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

AV Detection

barindex
Source: f_00321b.dll ReversingLabs: Detection: 79%
Source: f_00321b.dll Virustotal: Detection: 60% Perma Link
Source: https://164.90.222.65:443/igqovuqspgdf/wfealienuk/lkpf/f/ Avira URL Cloud: Label: malware
Source: https://107.170.39.149:8080/hHm Avira URL Cloud: Label: malware
Source: https://103.43.75.120/igqovuqspgdf/wfealienuk/lkpf/ Avira URL Cloud: Label: malware
Source: https://103.43.75.120:443/igqovuqspgdf/wfealienuk/lkpf/ Avira URL Cloud: Label: malware
Source: https://213.239.212.5/0/ Avira URL Cloud: Label: malware
Source: https://91.121.146.47:8080/igqovuqspgdf/wfealienuk/lkpf/T Avira URL Cloud: Label: malware
Source: https://164.90.222.65/igqovuqspgdf/wfealienuk/lkpf/ Avira URL Cloud: Label: malware
Source: https://104.168.155.143:8080/Y Avira URL Cloud: Label: malware
Source: https://213.239.212.5/ Avira URL Cloud: Label: malware
Source: https://82.223.21.224:8080/ Avira URL Cloud: Label: malware
Source: https://159.89.202.34:443/igqovuqspgdf/wfealienuk/lkpf/ Avira URL Cloud: Label: malware
Source: https://45.235.8.30:8080/igqovuqspgdf/wfealienuk/lkpf/PO Avira URL Cloud: Label: malware
Source: https://159.65.88.10:8080/igqovuqspgdf/wfealienuk/lkpf/ Avira URL Cloud: Label: malware
Source: https://213.239.212.5/igqovuqspgdf/wfealienuk/lkpf/ Avira URL Cloud: Label: malware
Source: https://91.121.146.47:8080/igqovuqspgdf/wfealienuk/lkpf/ Avira URL Cloud: Label: malware
Source: https://45.235.8.30:8080/f/ Avira URL Cloud: Label: malware
Source: https://91.121.146.47:8080/ Avira URL Cloud: Label: malware
Source: https://206.189.28.199:8080/igqovuqspgdf/wfealienuk/lkpf/ Avira URL Cloud: Label: malware
Source: https://107.170.39.149:8080/igqovuqspgdf/wfealienuk/lkpf/ Avira URL Cloud: Label: malware
Source: https://45.235.8.30:8080/ Avira URL Cloud: Label: malware
Source: https://107.170.39.149:8080/rue4m Avira URL Cloud: Label: malware
Source: https://164.90.222.65/wn Avira URL Cloud: Label: malware
Source: https://72.15.201.15:8080/igqovuqspgdf/wfealienuk/lkpf/ Avira URL Cloud: Label: malware
Source: https://45.235.8.30:8080/igqovuqspgdf/wfealienuk/lkpf/ Avira URL Cloud: Label: malware
Source: https://45.235.8.30:8080/igqovuqspgdf/wfealienuk/lkpf/s Avira URL Cloud: Label: malware
Source: https://104.168.155.143:8080/igqovuqspgdf/wfealienuk/lkpf/ Avira URL Cloud: Label: malware
Source: https://169.57.156.166:8080/igqovuqspgdf/wfealienuk/lkpf/ Avira URL Cloud: Label: malware
Source: https://82.223.21.224:8080/ Virustotal: Detection: 8% Perma Link
Source: 00000006.00000002.837764087.000000000095B000.00000004.00000020.00020000.00000000.sdmp Malware Configuration Extractor: Emotet {"C2 list": ["91.121.146.47:8080", "66.228.32.31:7080", "182.162.143.56:443", "187.63.160.88:80", "167.172.199.165:8080", "164.90.222.65:443", "104.168.155.143:8080", "163.44.196.120:8080", "160.16.142.56:8080", "159.89.202.34:443", "159.65.88.10:8080", "186.194.240.217:443", "149.56.131.28:8080", "72.15.201.15:8080", "1.234.2.232:8080", "82.223.21.224:8080", "206.189.28.199:8080", "169.57.156.166:8080", "107.170.39.149:8080", "103.43.75.120:443", "91.207.28.33:8080", "213.239.212.5:443", "45.235.8.30:8080", "119.59.103.152:8080", "164.68.99.3:8080", "95.217.221.146:8080", "153.126.146.25:7080", "197.242.150.244:8080", "202.129.205.3:8080", "103.132.242.26:8080", "139.59.126.41:443", "110.232.117.186:8080", "183.111.227.137:8080", "5.135.159.50:443", "201.94.166.162:443", "103.75.201.2:443", "79.137.35.198:8080", "172.105.226.75:8080", "94.23.45.86:4143", "115.68.227.76:8080", "153.92.5.27:8080", "167.172.253.162:8080", "188.44.20.25:443", "147.139.166.154:8080", "129.232.188.93:443", "173.212.193.249:8080", "185.4.135.165:8080", "45.176.232.124:443"], "Public Key": ["RUNTMSAAAABAX3S2xNjcDD0fBno33Ln5t71eii+mofIPoXkNFOX1MeiwCh48iz97kB0mJjGGZXwardnDXKxI8GCHGNl0PFj51CrH1gASAIg=", "RUNLMSAAAADzozW1Di4r9DVWzQpMKT588RDdy7BPILP6AiDOTLYMHkSWvrQO5slbmr1OvZ2Pz+AQWzRMggQmAtO6rPH7nyx23yr61gATAIo="]}
Source: unknown HTTPS traffic detected: 164.90.222.65:443 -> 192.168.2.4:49704 version: TLS 1.2
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180008D28 FindFirstFileExW, 3_2_0000000180008D28
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_0000000180008D28 FindFirstFileExW, 4_2_0000000180008D28

Networking

barindex
Source: C:\Windows\System32\regsvr32.exe Network Connect: 159.65.88.10 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 164.90.222.65 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 213.239.212.5 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 186.194.240.217 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 104.168.155.143 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 159.89.202.34 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 160.16.142.56 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 91.121.146.47 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 91.207.28.33 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 103.43.75.120 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 45.235.8.30 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 72.15.201.15 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 163.44.196.120 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 206.189.28.199 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 107.170.39.149 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 187.63.160.88 80 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 66.228.32.31 7080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 82.223.21.224 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 149.56.131.28 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 169.57.156.166 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 182.162.143.56 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 1.234.2.232 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 167.172.199.165 8080 Jump to behavior
Source: Traffic Snort IDS: 2404308 ET CNC Feodo Tracker Reported CnC Server TCP group 5 192.168.2.4:49704 -> 164.90.222.65:443
Source: Traffic Snort IDS: 2404344 ET CNC Feodo Tracker Reported CnC Server TCP group 23 192.168.2.4:49695 -> 91.121.146.47:8080
Source: Traffic Snort IDS: 2404330 ET CNC Feodo Tracker Reported CnC Server TCP group 16 192.168.2.4:49697 -> 66.228.32.31:7080
Source: Traffic Snort IDS: 2404312 ET CNC Feodo Tracker Reported CnC Server TCP group 7 192.168.2.4:49698 -> 182.162.143.56:443
Source: Traffic Snort IDS: 2404314 ET CNC Feodo Tracker Reported CnC Server TCP group 8 192.168.2.4:49702 -> 187.63.160.88:80
Source: Traffic Snort IDS: 2404310 ET CNC Feodo Tracker Reported CnC Server TCP group 6 192.168.2.4:49703 -> 167.172.199.165:8080
Source: Traffic Snort IDS: 2404302 ET CNC Feodo Tracker Reported CnC Server TCP group 2 192.168.2.4:49705 -> 104.168.155.143:8080
Source: Traffic Snort IDS: 2404304 ET CNC Feodo Tracker Reported CnC Server TCP group 3 192.168.2.4:49719 -> 1.234.2.232:8080
Source: Traffic Snort IDS: 2404318 ET CNC Feodo Tracker Reported CnC Server TCP group 10 192.168.2.4:49721 -> 206.189.28.199:8080
Source: Traffic Snort IDS: 2404320 ET CNC Feodo Tracker Reported CnC Server TCP group 11 192.168.2.4:49729 -> 213.239.212.5:443
Source: Traffic Snort IDS: 2404324 ET CNC Feodo Tracker Reported CnC Server TCP group 13 192.168.2.4:49733 -> 45.235.8.30:8080
Source: Malware configuration extractor IPs: 91.121.146.47:8080
Source: Malware configuration extractor IPs: 66.228.32.31:7080
Source: Malware configuration extractor IPs: 182.162.143.56:443
Source: Malware configuration extractor IPs: 187.63.160.88:80
Source: Malware configuration extractor IPs: 167.172.199.165:8080
Source: Malware configuration extractor IPs: 164.90.222.65:443
Source: Malware configuration extractor IPs: 104.168.155.143:8080
Source: Malware configuration extractor IPs: 163.44.196.120:8080
Source: Malware configuration extractor IPs: 160.16.142.56:8080
Source: Malware configuration extractor IPs: 159.89.202.34:443
Source: Malware configuration extractor IPs: 159.65.88.10:8080
Source: Malware configuration extractor IPs: 186.194.240.217:443
Source: Malware configuration extractor IPs: 149.56.131.28:8080
Source: Malware configuration extractor IPs: 72.15.201.15:8080
Source: Malware configuration extractor IPs: 1.234.2.232:8080
Source: Malware configuration extractor IPs: 82.223.21.224:8080
Source: Malware configuration extractor IPs: 206.189.28.199:8080
Source: Malware configuration extractor IPs: 169.57.156.166:8080
Source: Malware configuration extractor IPs: 107.170.39.149:8080
Source: Malware configuration extractor IPs: 103.43.75.120:443
Source: Malware configuration extractor IPs: 91.207.28.33:8080
Source: Malware configuration extractor IPs: 213.239.212.5:443
Source: Malware configuration extractor IPs: 45.235.8.30:8080
Source: Malware configuration extractor IPs: 119.59.103.152:8080
Source: Malware configuration extractor IPs: 164.68.99.3:8080
Source: Malware configuration extractor IPs: 95.217.221.146:8080
Source: Malware configuration extractor IPs: 153.126.146.25:7080
Source: Malware configuration extractor IPs: 197.242.150.244:8080
Source: Malware configuration extractor IPs: 202.129.205.3:8080
Source: Malware configuration extractor IPs: 103.132.242.26:8080
Source: Malware configuration extractor IPs: 139.59.126.41:443
Source: Malware configuration extractor IPs: 110.232.117.186:8080
Source: Malware configuration extractor IPs: 183.111.227.137:8080
Source: Malware configuration extractor IPs: 5.135.159.50:443
Source: Malware configuration extractor IPs: 201.94.166.162:443
Source: Malware configuration extractor IPs: 103.75.201.2:443
Source: Malware configuration extractor IPs: 79.137.35.198:8080
Source: Malware configuration extractor IPs: 172.105.226.75:8080
Source: Malware configuration extractor IPs: 94.23.45.86:4143
Source: Malware configuration extractor IPs: 115.68.227.76:8080
Source: Malware configuration extractor IPs: 153.92.5.27:8080
Source: Malware configuration extractor IPs: 167.172.253.162:8080
Source: Malware configuration extractor IPs: 188.44.20.25:443
Source: Malware configuration extractor IPs: 147.139.166.154:8080
Source: Malware configuration extractor IPs: 129.232.188.93:443
Source: Malware configuration extractor IPs: 173.212.193.249:8080
Source: Malware configuration extractor IPs: 185.4.135.165:8080
Source: Malware configuration extractor IPs: 45.176.232.124:443
Source: Joe Sandbox View ASN Name: DIGITALOCEAN-ASNUS DIGITALOCEAN-ASNUS
Source: Joe Sandbox View ASN Name: LINODE-APLinodeLLCUS LINODE-APLinodeLLCUS
Source: Joe Sandbox View JA3 fingerprint: 8916410db85077a5460817142dcbc8de
Source: global traffic HTTP traffic detected: POST /igqovuqspgdf/wfealienuk/lkpf/ HTTP/1.1Connection: Keep-AliveContent-Length: 0Host: 164.90.222.65
Source: Joe Sandbox View IP Address: 159.65.88.10 159.65.88.10
Source: global traffic TCP traffic: 192.168.2.4:49695 -> 91.121.146.47:8080
Source: global traffic TCP traffic: 192.168.2.4:49697 -> 66.228.32.31:7080
Source: global traffic TCP traffic: 192.168.2.4:49703 -> 167.172.199.165:8080
Source: global traffic TCP traffic: 192.168.2.4:49705 -> 104.168.155.143:8080
Source: global traffic TCP traffic: 192.168.2.4:49706 -> 163.44.196.120:8080
Source: global traffic TCP traffic: 192.168.2.4:49707 -> 160.16.142.56:8080
Source: global traffic TCP traffic: 192.168.2.4:49712 -> 159.65.88.10:8080
Source: global traffic TCP traffic: 192.168.2.4:49717 -> 149.56.131.28:8080
Source: global traffic TCP traffic: 192.168.2.4:49718 -> 72.15.201.15:8080
Source: global traffic TCP traffic: 192.168.2.4:49719 -> 1.234.2.232:8080
Source: global traffic TCP traffic: 192.168.2.4:49720 -> 82.223.21.224:8080
Source: global traffic TCP traffic: 192.168.2.4:49721 -> 206.189.28.199:8080
Source: global traffic TCP traffic: 192.168.2.4:49722 -> 169.57.156.166:8080
Source: global traffic TCP traffic: 192.168.2.4:49723 -> 107.170.39.149:8080
Source: global traffic TCP traffic: 192.168.2.4:49728 -> 91.207.28.33:8080
Source: global traffic TCP traffic: 192.168.2.4:49733 -> 45.235.8.30:8080
Source: unknown Network traffic detected: IP country count 17
Source: unknown Network traffic detected: HTTP traffic on port 49708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49700
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49699 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49704 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49701 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49713 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49713
Source: unknown Network traffic detected: HTTP traffic on port 49698 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49711
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49699
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49698
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49711 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49700 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49708
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49704
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49701
Source: unknown TCP traffic detected without corresponding DNS query: 91.121.146.47
Source: unknown TCP traffic detected without corresponding DNS query: 91.121.146.47
Source: unknown TCP traffic detected without corresponding DNS query: 91.121.146.47
Source: unknown TCP traffic detected without corresponding DNS query: 91.121.146.47
Source: unknown TCP traffic detected without corresponding DNS query: 91.121.146.47
Source: unknown TCP traffic detected without corresponding DNS query: 91.121.146.47
Source: unknown TCP traffic detected without corresponding DNS query: 91.121.146.47
Source: unknown TCP traffic detected without corresponding DNS query: 91.121.146.47
Source: unknown TCP traffic detected without corresponding DNS query: 91.121.146.47
Source: unknown TCP traffic detected without corresponding DNS query: 91.121.146.47
Source: unknown TCP traffic detected without corresponding DNS query: 91.121.146.47
Source: unknown TCP traffic detected without corresponding DNS query: 91.121.146.47
Source: unknown TCP traffic detected without corresponding DNS query: 66.228.32.31
Source: unknown TCP traffic detected without corresponding DNS query: 66.228.32.31
Source: unknown TCP traffic detected without corresponding DNS query: 66.228.32.31
Source: unknown TCP traffic detected without corresponding DNS query: 182.162.143.56
Source: unknown TCP traffic detected without corresponding DNS query: 182.162.143.56
Source: unknown TCP traffic detected without corresponding DNS query: 182.162.143.56
Source: unknown TCP traffic detected without corresponding DNS query: 182.162.143.56
Source: unknown TCP traffic detected without corresponding DNS query: 182.162.143.56
Source: unknown TCP traffic detected without corresponding DNS query: 182.162.143.56
Source: unknown TCP traffic detected without corresponding DNS query: 182.162.143.56
Source: unknown TCP traffic detected without corresponding DNS query: 182.162.143.56
Source: unknown TCP traffic detected without corresponding DNS query: 182.162.143.56
Source: unknown TCP traffic detected without corresponding DNS query: 182.162.143.56
Source: unknown TCP traffic detected without corresponding DNS query: 182.162.143.56
Source: unknown TCP traffic detected without corresponding DNS query: 182.162.143.56
Source: unknown TCP traffic detected without corresponding DNS query: 187.63.160.88
Source: unknown TCP traffic detected without corresponding DNS query: 187.63.160.88
Source: unknown TCP traffic detected without corresponding DNS query: 187.63.160.88
Source: unknown TCP traffic detected without corresponding DNS query: 167.172.199.165
Source: unknown TCP traffic detected without corresponding DNS query: 167.172.199.165
Source: unknown TCP traffic detected without corresponding DNS query: 167.172.199.165
Source: unknown TCP traffic detected without corresponding DNS query: 167.172.199.165
Source: unknown TCP traffic detected without corresponding DNS query: 167.172.199.165
Source: unknown TCP traffic detected without corresponding DNS query: 167.172.199.165
Source: unknown TCP traffic detected without corresponding DNS query: 167.172.199.165
Source: unknown TCP traffic detected without corresponding DNS query: 167.172.199.165
Source: unknown TCP traffic detected without corresponding DNS query: 167.172.199.165
Source: unknown TCP traffic detected without corresponding DNS query: 167.172.199.165
Source: unknown TCP traffic detected without corresponding DNS query: 164.90.222.65
Source: unknown TCP traffic detected without corresponding DNS query: 164.90.222.65
Source: unknown TCP traffic detected without corresponding DNS query: 164.90.222.65
Source: unknown TCP traffic detected without corresponding DNS query: 164.90.222.65
Source: unknown TCP traffic detected without corresponding DNS query: 164.90.222.65
Source: unknown TCP traffic detected without corresponding DNS query: 164.90.222.65
Source: unknown TCP traffic detected without corresponding DNS query: 164.90.222.65
Source: unknown TCP traffic detected without corresponding DNS query: 164.90.222.65
Source: unknown TCP traffic detected without corresponding DNS query: 164.90.222.65
Source: unknown TCP traffic detected without corresponding DNS query: 104.168.155.143
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494319079.00000000009F4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494204988.00000000009E8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.407309155.00000000009E8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494106768.00000000009E8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: regsvr32.exe, 00000006.00000003.494319079.00000000009F4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494204988.00000000009E8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.407309155.00000000009E8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494106768.00000000009E8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/
Source: regsvr32.exe, 00000006.00000003.494319079.00000000009F4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494204988.00000000009E8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.407309155.00000000009E8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494106768.00000000009E8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/OID
Source: regsvr32.exe, 00000006.00000003.405755577.0000000000A47000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/c
Source: regsvr32.exe, 00000006.00000003.407309155.00000000009B4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494297194.00000000009B6000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000002.837838850.00000000009B7000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494261913.00000000009B4000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en
Source: regsvr32.exe, 00000006.00000003.494106768.00000000009E8000.00000004.00000020.00020000.00000000.sdmp, 77EC63BDA74BD0D0E0426DC8F80085060.6.dr String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Source: regsvr32.exe, 00000006.00000003.407309155.00000000009E8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?3ae1e74b5e41b
Source: regsvr32.exe, 00000006.00000002.838188183.0000000002B83000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://10.235.8.30:8080/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://103.43.75.120/igqovuqspgdf/wfealienuk/lkpf/
Source: regsvr32.exe, 00000006.00000002.838188183.0000000002B6A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://103.43.75.120:443/igqovuqspgdf/wfealienuk/lkpf/
Source: regsvr32.exe, 00000006.00000002.837838850.00000000009E8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://103.44.196.120:8080/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://104.168.155.143:8080/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://104.168.155.143:8080/Y
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://104.168.155.143:8080/igqovuqspgdf/wfealienuk/lkpf/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://107.170.39.149:8080/hHm
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000002.837838850.00000000009E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://107.170.39.149:8080/igqovuqspgdf/wfealienuk/lkpf/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://107.170.39.149:8080/rue4m
Source: regsvr32.exe, 00000006.00000002.838188183.0000000002B6A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://159.65.88.10:8080/igqovuqspgdf/wfealienuk/lkpf/
Source: regsvr32.exe, 00000006.00000002.838188183.0000000002B6A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://159.89.202.34:443/igqovuqspgdf/wfealienuk/lkpf/
Source: regsvr32.exe, 00000006.00000003.494106768.00000000009E8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://164.90.222.65/igqovuqspgdf/wfealienuk/lkpf/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494319079.00000000009F4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494204988.00000000009E8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494106768.00000000009E8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://164.90.222.65/wn
Source: regsvr32.exe, 00000006.00000003.493259582.0000000002B6A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://164.90.222.65:443/igqovuqspgdf/wfealienuk/lkpf/f/
Source: regsvr32.exe, 00000006.00000002.838188183.0000000002B6A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://169.57.156.166:8080/igqovuqspgdf/wfealienuk/lkpf/
Source: regsvr32.exe, 00000006.00000002.838188183.0000000002B6A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://206.189.28.199:8080/igqovuqspgdf/wfealienuk/lkpf/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://213.239.212.5/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://213.239.212.5/0/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://213.239.212.5/igqovuqspgdf/wfealienuk/lkpf/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://45.235.8.30:8080/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://45.235.8.30:8080/f/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000002.838188183.0000000002B6A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://45.235.8.30:8080/igqovuqspgdf/wfealienuk/lkpf/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://45.235.8.30:8080/igqovuqspgdf/wfealienuk/lkpf/PO
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://45.235.8.30:8080/igqovuqspgdf/wfealienuk/lkpf/s
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://72.15.201.15:8080/igqovuqspgdf/wfealienuk/lkpf/
Source: regsvr32.exe, 00000006.00000002.837938487.00000000009F5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://82.223.21.224:8080/
Source: regsvr32.exe, 00000006.00000002.837764087.000000000095B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://91.121.146.47:8080/
Source: regsvr32.exe, 00000006.00000002.837764087.000000000095B000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://91.121.146.47:8080/igqovuqspgdf/wfealienuk/lkpf/
Source: regsvr32.exe, 00000006.00000003.407505388.00000000009D2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://91.121.146.47:8080/igqovuqspgdf/wfealienuk/lkpf/T
Source: unknown HTTP traffic detected: POST /igqovuqspgdf/wfealienuk/lkpf/ HTTP/1.1Connection: Keep-AliveContent-Length: 0Host: 164.90.222.65
Source: unknown HTTPS traffic detected: 164.90.222.65:443 -> 192.168.2.4:49704 version: TLS 1.2

E-Banking Fraud

barindex
Source: Yara match File source: 00000006.00000002.837764087.000000000095B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 4.2.rundll32.exe.263a5e10000.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.regsvr32.exe.b20000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.rundll32.exe.263a5e10000.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.regsvr32.exe.c60000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.regsvr32.exe.c60000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.rundll32.exe.264e3c10000.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.rundll32.exe.264e3c10000.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.regsvr32.exe.b20000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000004.00000002.321671737.00000263A5E10000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.322224352.00000264E3C10000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.322307535.00000264E3C41000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.322806911.0000000000C60000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.323368547.0000000000E61000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000002.322501137.00000263A7711000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.837994080.0000000000B20000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.838029759.0000000000B51000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: C:\Windows\System32\regsvr32.exe File deleted: C:\Windows\System32\ChVCsX\ramMHRyb.dll:Zone.Identifier Jump to behavior
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\system32\ChVCsX\ Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180006818 3_2_0000000180006818
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000B878 3_2_000000018000B878
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180007110 3_2_0000000180007110
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180008D28 3_2_0000000180008D28
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180014555 3_2_0000000180014555
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00C50000 3_2_00C50000
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7709C 3_2_00E7709C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7A000 3_2_00E7A000
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6CC14 3_2_00E6CC14
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E67D6C 3_2_00E67D6C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6263C 3_2_00E6263C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E68BC8 3_2_00E68BC8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E78FC8 3_2_00E78FC8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E720E0 3_2_00E720E0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E63CF4 3_2_00E63CF4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E648FC 3_2_00E648FC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E690F8 3_2_00E690F8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6F8C4 3_2_00E6F8C4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E75CC4 3_2_00E75CC4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E680CC 3_2_00E680CC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E708CC 3_2_00E708CC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E614D4 3_2_00E614D4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E73CD4 3_2_00E73CD4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E618DC 3_2_00E618DC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E698AC 3_2_00E698AC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E894BC 3_2_00E894BC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7A8B0 3_2_00E7A8B0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6DCB8 3_2_00E6DCB8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E64C84 3_2_00E64C84
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7CC84 3_2_00E7CC84
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E75880 3_2_00E75880
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6AC94 3_2_00E6AC94
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7B460 3_2_00E7B460
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6D474 3_2_00E6D474
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E76C70 3_2_00E76C70
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6B07C 3_2_00E6B07C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E62C78 3_2_00E62C78
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6C078 3_2_00E6C078
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E67840 3_2_00E67840
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7C44C 3_2_00E7C44C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E85450 3_2_00E85450
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7C058 3_2_00E7C058
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E71030 3_2_00E71030
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7EC30 3_2_00E7EC30
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6B83C 3_2_00E6B83C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E61000 3_2_00E61000
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E69408 3_2_00E69408
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E67C08 3_2_00E67C08
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E8181C 3_2_00E8181C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7D5F0 3_2_00E7D5F0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E715C8 3_2_00E715C8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7BDA0 3_2_00E7BDA0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E695BC 3_2_00E695BC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E71924 3_2_00E71924
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E74D20 3_2_00E74D20
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7AD28 3_2_00E7AD28
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E67530 3_2_00E67530
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7B130 3_2_00E7B130
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E66138 3_2_00E66138
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E88500 3_2_00E88500
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7610C 3_2_00E7610C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E89910 3_2_00E89910
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E77518 3_2_00E77518
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E692F0 3_2_00E692F0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7EAC0 3_2_00E7EAC0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6D6CC 3_2_00E6D6CC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E796D4 3_2_00E796D4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E63ABC 3_2_00E63ABC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7A6BC 3_2_00E7A6BC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6AAB8 3_2_00E6AAB8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E64EB8 3_2_00E64EB8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E84E8C 3_2_00E84E8C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E68A8C 3_2_00E68A8C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6BE90 3_2_00E6BE90
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E74A90 3_2_00E74A90
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6A660 3_2_00E6A660
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E63274 3_2_00E63274
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E70A70 3_2_00E70A70
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7A244 3_2_00E7A244
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6F65C 3_2_00E6F65C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6B258 3_2_00E6B258
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6BA2C 3_2_00E6BA2C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E78A2C 3_2_00E78A2C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E70E2C 3_2_00E70E2C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7662C 3_2_00E7662C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E75A00 3_2_00E75A00
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E88A00 3_2_00E88A00
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E63E0C 3_2_00E63E0C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7020C 3_2_00E7020C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E78E08 3_2_00E78E08
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E64214 3_2_00E64214
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6461C 3_2_00E6461C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E827EC 3_2_00E827EC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6A7F0 3_2_00E6A7F0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E797CC 3_2_00E797CC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E62FD4 3_2_00E62FD4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E633D4 3_2_00E633D4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E73FD0 3_2_00E73FD0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6DBA0 3_2_00E6DBA0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E68FB0 3_2_00E68FB0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6FFB8 3_2_00E6FFB8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E78BB8 3_2_00E78BB8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E75384 3_2_00E75384
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E61B94 3_2_00E61B94
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7D770 3_2_00E7D770
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7CF70 3_2_00E7CF70
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6F77C 3_2_00E6F77C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E68378 3_2_00E68378
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7E750 3_2_00E7E750
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6975C 3_2_00E6975C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E64758 3_2_00E64758
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6D33C 3_2_00E6D33C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6EF14 3_2_00E6EF14
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E73B14 3_2_00E73B14
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7E310 3_2_00E7E310
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E74F18 3_2_00E74F18
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_0000000180006818 4_2_0000000180006818
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_000000018000B878 4_2_000000018000B878
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_0000000180007110 4_2_0000000180007110
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_0000000180008D28 4_2_0000000180008D28
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_0000000180014555 4_2_0000000180014555
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A5E00000 4_2_00000263A5E00000
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7717D6C 4_2_00000263A7717D6C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771CC14 4_2_00000263A771CC14
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772709C 4_2_00000263A772709C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772A000 4_2_00000263A772A000
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7718BC8 4_2_00000263A7718BC8
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7728FC8 4_2_00000263A7728FC8
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771263C 4_2_00000263A771263C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7716138 4_2_00000263A7716138
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7721924 4_2_00000263A7721924
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772AD28 4_2_00000263A772AD28
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7717530 4_2_00000263A7717530
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772B130 4_2_00000263A772B130
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7727518 4_2_00000263A7727518
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7724D20 4_2_00000263A7724D20
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772610C 4_2_00000263A772610C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7739910 4_2_00000263A7739910
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7738A00 4_2_00000263A7738A00
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7725A00 4_2_00000263A7725A00
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772D5F0 4_2_00000263A772D5F0
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77215C8 4_2_00000263A77215C8
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77195BC 4_2_00000263A77195BC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772BDA0 4_2_00000263A772BDA0
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771D474 4_2_00000263A771D474
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7712C78 4_2_00000263A7712C78
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771C078 4_2_00000263A771C078
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771B07C 4_2_00000263A771B07C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7725880 4_2_00000263A7725880
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7726C70 4_2_00000263A7726C70
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772C058 4_2_00000263A772C058
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772B460 4_2_00000263A772B460
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772C44C 4_2_00000263A772C44C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7735450 4_2_00000263A7735450
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771B83C 4_2_00000263A771B83C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7717840 4_2_00000263A7717840
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772EC30 4_2_00000263A772EC30
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7721030 4_2_00000263A7721030
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A773181C 4_2_00000263A773181C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7719408 4_2_00000263A7719408
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7717C08 4_2_00000263A7717C08
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7713CF4 4_2_00000263A7713CF4
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77190F8 4_2_00000263A77190F8
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77148FC 4_2_00000263A77148FC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7738500 4_2_00000263A7738500
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77114D4 4_2_00000263A77114D4
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7723CD4 4_2_00000263A7723CD4
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77118DC 4_2_00000263A77118DC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77220E0 4_2_00000263A77220E0
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7725CC4 4_2_00000263A7725CC4
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771F8C4 4_2_00000263A771F8C4
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77180CC 4_2_00000263A77180CC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77208CC 4_2_00000263A77208CC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771DCB8 4_2_00000263A771DCB8
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77394BC 4_2_00000263A77394BC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77198AC 4_2_00000263A77198AC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772A8B0 4_2_00000263A772A8B0
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771AC94 4_2_00000263A771AC94
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7714C84 4_2_00000263A7714C84
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772CC84 4_2_00000263A772CC84
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7718378 4_2_00000263A7718378
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771F77C 4_2_00000263A771F77C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772D770 4_2_00000263A772D770
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772CF70 4_2_00000263A772CF70
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7714758 4_2_00000263A7714758
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771975C 4_2_00000263A771975C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772E750 4_2_00000263A772E750
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771D33C 4_2_00000263A771D33C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771EF14 4_2_00000263A771EF14
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7723B14 4_2_00000263A7723B14
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7724F18 4_2_00000263A7724F18
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772E310 4_2_00000263A772E310
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7711000 4_2_00000263A7711000
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77327EC 4_2_00000263A77327EC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771A7F0 4_2_00000263A771A7F0
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7712FD4 4_2_00000263A7712FD4
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77133D4 4_2_00000263A77133D4
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77297CC 4_2_00000263A77297CC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7723FD0 4_2_00000263A7723FD0
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771FFB8 4_2_00000263A771FFB8
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7728BB8 4_2_00000263A7728BB8
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7718FB0 4_2_00000263A7718FB0
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7711B94 4_2_00000263A7711B94
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771DBA0 4_2_00000263A771DBA0
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7725384 4_2_00000263A7725384
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7713274 4_2_00000263A7713274
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7720A70 4_2_00000263A7720A70
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771B258 4_2_00000263A771B258
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771F65C 4_2_00000263A771F65C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771A660 4_2_00000263A771A660
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772A244 4_2_00000263A772A244
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7728A2C 4_2_00000263A7728A2C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771BA2C 4_2_00000263A771BA2C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7720E2C 4_2_00000263A7720E2C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772662C 4_2_00000263A772662C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7714214 4_2_00000263A7714214
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771461C 4_2_00000263A771461C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7728E08 4_2_00000263A7728E08
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7713E0C 4_2_00000263A7713E0C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772020C 4_2_00000263A772020C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77192F0 4_2_00000263A77192F0
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77296D4 4_2_00000263A77296D4
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771D6CC 4_2_00000263A771D6CC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771AAB8 4_2_00000263A771AAB8
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7714EB8 4_2_00000263A7714EB8
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7713ABC 4_2_00000263A7713ABC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772A6BC 4_2_00000263A772A6BC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772EAC0 4_2_00000263A772EAC0
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7718A8C 4_2_00000263A7718A8C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7734E8C 4_2_00000263A7734E8C
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771BE90 4_2_00000263A771BE90
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7724A90 4_2_00000263A7724A90
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C00000 5_2_00000264E3C00000
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C47D6C 5_2_00000264E3C47D6C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5709C 5_2_00000264E3C5709C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5A000 5_2_00000264E3C5A000
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4CC14 5_2_00000264E3C4CC14
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C48BC8 5_2_00000264E3C48BC8
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C58FC8 5_2_00000264E3C58FC8
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4263C 5_2_00000264E3C4263C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C495BC 5_2_00000264E3C495BC
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C515C8 5_2_00000264E3C515C8
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5BDA0 5_2_00000264E3C5BDA0
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5AD28 5_2_00000264E3C5AD28
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C51924 5_2_00000264E3C51924
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C47530 5_2_00000264E3C47530
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5B130 5_2_00000264E3C5B130
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C46138 5_2_00000264E3C46138
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C490F8 5_2_00000264E3C490F8
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C43CF4 5_2_00000264E3C43CF4
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C68500 5_2_00000264E3C68500
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C448FC 5_2_00000264E3C448FC
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C69910 5_2_00000264E3C69910
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5610C 5_2_00000264E3C5610C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C57518 5_2_00000264E3C57518
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C54D20 5_2_00000264E3C54D20
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5A8B0 5_2_00000264E3C5A8B0
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C498AC 5_2_00000264E3C498AC
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4DCB8 5_2_00000264E3C4DCB8
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C694BC 5_2_00000264E3C694BC
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C55CC4 5_2_00000264E3C55CC4
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4F8C4 5_2_00000264E3C4F8C4
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C480CC 5_2_00000264E3C480CC
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C508CC 5_2_00000264E3C508CC
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C414D4 5_2_00000264E3C414D4
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C53CD4 5_2_00000264E3C53CD4
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C520E0 5_2_00000264E3C520E0
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C418DC 5_2_00000264E3C418DC
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C56C70 5_2_00000264E3C56C70
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C42C78 5_2_00000264E3C42C78
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4C078 5_2_00000264E3C4C078
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4D474 5_2_00000264E3C4D474
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C55880 5_2_00000264E3C55880
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4B07C 5_2_00000264E3C4B07C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C44C84 5_2_00000264E3C44C84
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5CC84 5_2_00000264E3C5CC84
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4AC94 5_2_00000264E3C4AC94
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C51030 5_2_00000264E3C51030
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5EC30 5_2_00000264E3C5EC30
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C47840 5_2_00000264E3C47840
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4B83C 5_2_00000264E3C4B83C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C65450 5_2_00000264E3C65450
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5C44C 5_2_00000264E3C5C44C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5C058 5_2_00000264E3C5C058
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5B460 5_2_00000264E3C5B460
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4A7F0 5_2_00000264E3C4A7F0
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C627EC 5_2_00000264E3C627EC
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C41000 5_2_00000264E3C41000
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C49408 5_2_00000264E3C49408
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C47C08 5_2_00000264E3C47C08
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C6181C 5_2_00000264E3C6181C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C48FB0 5_2_00000264E3C48FB0
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4FFB8 5_2_00000264E3C4FFB8
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C58BB8 5_2_00000264E3C58BB8
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C53FD0 5_2_00000264E3C53FD0
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C597CC 5_2_00000264E3C597CC
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C42FD4 5_2_00000264E3C42FD4
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C433D4 5_2_00000264E3C433D4
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5D770 5_2_00000264E3C5D770
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5CF70 5_2_00000264E3C5CF70
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C48378 5_2_00000264E3C48378
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4F77C 5_2_00000264E3C4F77C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C55384 5_2_00000264E3C55384
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C41B94 5_2_00000264E3C41B94
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4DBA0 5_2_00000264E3C4DBA0
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4D33C 5_2_00000264E3C4D33C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5E750 5_2_00000264E3C5E750
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C44758 5_2_00000264E3C44758
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4975C 5_2_00000264E3C4975C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C492F0 5_2_00000264E3C492F0
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5E310 5_2_00000264E3C5E310
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C54F18 5_2_00000264E3C54F18
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4EF14 5_2_00000264E3C4EF14
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C53B14 5_2_00000264E3C53B14
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4AAB8 5_2_00000264E3C4AAB8
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C44EB8 5_2_00000264E3C44EB8
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5EAC0 5_2_00000264E3C5EAC0
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C43ABC 5_2_00000264E3C43ABC
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5A6BC 5_2_00000264E3C5A6BC
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4D6CC 5_2_00000264E3C4D6CC
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C596D4 5_2_00000264E3C596D4
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C50A70 5_2_00000264E3C50A70
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C43274 5_2_00000264E3C43274
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4BE90 5_2_00000264E3C4BE90
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C54A90 5_2_00000264E3C54A90
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C48A8C 5_2_00000264E3C48A8C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C64E8C 5_2_00000264E3C64E8C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C58A2C 5_2_00000264E3C58A2C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4BA2C 5_2_00000264E3C4BA2C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C50E2C 5_2_00000264E3C50E2C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5662C 5_2_00000264E3C5662C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5A244 5_2_00000264E3C5A244
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4B258 5_2_00000264E3C4B258
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4A660 5_2_00000264E3C4A660
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4F65C 5_2_00000264E3C4F65C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5D5F0 5_2_00000264E3C5D5F0
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C55A00 5_2_00000264E3C55A00
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C68A00 5_2_00000264E3C68A00
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C58E08 5_2_00000264E3C58E08
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C43E0C 5_2_00000264E3C43E0C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C5020C 5_2_00000264E3C5020C
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C44214 5_2_00000264E3C44214
Source: C:\Windows\System32\rundll32.exe Code function: 5_2_00000264E3C4461C 5_2_00000264E3C4461C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00940000 6_2_00940000
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B608CC 6_2_00B608CC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5CC14 6_2_00B5CC14
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6A000 6_2_00B6A000
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5640A 6_2_00B5640A
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B57D6C 6_2_00B57D6C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B676A8 6_2_00B676A8
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B70618 6_2_00B70618
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B56E42 6_2_00B56E42
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B773A4 6_2_00B773A4
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B563F4 6_2_00B563F4
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B63FD0 6_2_00B63FD0
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B58BC8 6_2_00B58BC8
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B68FC8 6_2_00B68FC8
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B59B79 6_2_00B59B79
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6A8B0 6_2_00B6A8B0
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B794BC 6_2_00B794BC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5DCB8 6_2_00B5DCB8
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B598AC 6_2_00B598AC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B744A8 6_2_00B744A8
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5AC94 6_2_00B5AC94
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B71494 6_2_00B71494
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6709C 6_2_00B6709C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B54C84 6_2_00B54C84
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6CC84 6_2_00B6CC84
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B65880 6_2_00B65880
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B7488C 6_2_00B7488C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B53CF4 6_2_00B53CF4
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B548FC 6_2_00B548FC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B590F8 6_2_00B590F8
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B620E0 6_2_00B620E0
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B514D4 6_2_00B514D4
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B63CD4 6_2_00B63CD4
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B71CD4 6_2_00B71CD4
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B518DC 6_2_00B518DC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5F8C4 6_2_00B5F8C4
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B65CC4 6_2_00B65CC4
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B580CC 6_2_00B580CC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B61030 6_2_00B61030
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6EC30 6_2_00B6EC30
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5B83C 6_2_00B5B83C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B57410 6_2_00B57410
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B7181C 6_2_00B7181C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B51000 6_2_00B51000
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B59408 6_2_00B59408
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B57C08 6_2_00B57C08
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5D474 6_2_00B5D474
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B66C70 6_2_00B66C70
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5B07C 6_2_00B5B07C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B52C78 6_2_00B52C78
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5C078 6_2_00B5C078
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6B460 6_2_00B6B460
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B75868 6_2_00B75868
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B75450 6_2_00B75450
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6C058 6_2_00B6C058
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B57840 6_2_00B57840
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6C44C 6_2_00B6C44C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B595BC 6_2_00B595BC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6BDA0 6_2_00B6BDA0
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6D5F0 6_2_00B6D5F0
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B615C8 6_2_00B615C8
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6B130 6_2_00B6B130
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B56138 6_2_00B56138
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B61924 6_2_00B61924
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B64D20 6_2_00B64D20
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6AD28 6_2_00B6AD28
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B79910 6_2_00B79910
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B67518 6_2_00B67518
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B78500 6_2_00B78500
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B72100 6_2_00B72100
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6610C 6_2_00B6610C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B74D64 6_2_00B74D64
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B72AB0 6_2_00B72AB0
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B53ABC 6_2_00B53ABC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6A6BC 6_2_00B6A6BC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5AAB8 6_2_00B5AAB8
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B54EB8 6_2_00B54EB8
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5BE90 6_2_00B5BE90
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B64A90 6_2_00B64A90
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B72E84 6_2_00B72E84
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B58A8C 6_2_00B58A8C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B74E8C 6_2_00B74E8C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B592F0 6_2_00B592F0
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B736FC 6_2_00B736FC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B696D4 6_2_00B696D4
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6EAC0 6_2_00B6EAC0
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5D6CC 6_2_00B5D6CC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5263C 6_2_00B5263C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5BA2C 6_2_00B5BA2C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B68A2C 6_2_00B68A2C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B60E2C 6_2_00B60E2C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6662C 6_2_00B6662C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B54214 6_2_00B54214
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5461C 6_2_00B5461C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B65A00 6_2_00B65A00
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B78A00 6_2_00B78A00
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B53E0C 6_2_00B53E0C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6020C 6_2_00B6020C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B68E08 6_2_00B68E08
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B53274 6_2_00B53274
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B60A70 6_2_00B60A70
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5A660 6_2_00B5A660
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5F65C 6_2_00B5F65C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5B258 6_2_00B5B258
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6A244 6_2_00B6A244
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B76E48 6_2_00B76E48
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B58FB0 6_2_00B58FB0
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5FFB8 6_2_00B5FFB8
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B68BB8 6_2_00B68BB8
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5DBA0 6_2_00B5DBA0
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B747A8 6_2_00B747A8
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B51B94 6_2_00B51B94
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B65384 6_2_00B65384
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5A7F0 6_2_00B5A7F0
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6FFFC 6_2_00B6FFFC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B727EC 6_2_00B727EC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B52FD4 6_2_00B52FD4
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B533D4 6_2_00B533D4
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B697CC 6_2_00B697CC
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5D33C 6_2_00B5D33C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5EF14 6_2_00B5EF14
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B63B14 6_2_00B63B14
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6E310 6_2_00B6E310
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B78310 6_2_00B78310
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B75B1C 6_2_00B75B1C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B64F18 6_2_00B64F18
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6D770 6_2_00B6D770
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6CF70 6_2_00B6CF70
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5F77C 6_2_00B5F77C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B58378 6_2_00B58378
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B78B68 6_2_00B78B68
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B6E750 6_2_00B6E750
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B5975C 6_2_00B5975C
Source: C:\Windows\System32\regsvr32.exe Code function: 6_2_00B54758 6_2_00B54758
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180010C10 LdrFindResource_U,LdrAccessResource,NtAllocateVirtualMemory, 3_2_0000000180010C10
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180010AC0 ExitProcess,RtlQueueApcWow64Thread,NtTestAlert, 3_2_0000000180010AC0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180010DB0 ZwOpenSymbolicLinkObject,ZwOpenSymbolicLinkObject, 3_2_0000000180010DB0
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_0000000180010C10 LdrFindResource_U,LdrAccessResource,NtAllocateVirtualMemory, 4_2_0000000180010C10
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_0000000180010AC0 ExitProcess,RtlQueueApcWow64Thread,NtTestAlert, 4_2_0000000180010AC0
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_0000000180010DB0 ZwOpenSymbolicLinkObject,ZwOpenSymbolicLinkObject, 4_2_0000000180010DB0
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: f_00321b.dll ReversingLabs: Detection: 79%
Source: f_00321b.dll Virustotal: Detection: 60%
Source: f_00321b.dll Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Windows\System32\loaddll64.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\f_00321b.dll"
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\f_00321b.dll",#1
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\f_00321b.dll
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\f_00321b.dll",#1
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\f_00321b.dll,DllRegisterServer
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\ChVCsX\ramMHRyb.dll"
Source: C:\Windows\System32\rundll32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\LwMWPX\mOtL.dll"
Source: C:\Windows\System32\rundll32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\WiCuwn\qvjh.dll"
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\f_00321b.dll",#1 Jump to behavior
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\f_00321b.dll Jump to behavior
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\f_00321b.dll,DllRegisterServer Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\f_00321b.dll",#1 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\ChVCsX\ramMHRyb.dll" Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\LwMWPX\mOtL.dll" Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\WiCuwn\qvjh.dll" Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32 Jump to behavior
Source: classification engine Classification label: mal100.troj.evad.winDLL@16/2@0/48
Source: C:\Windows\System32\regsvr32.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E68BC8 Process32NextW,Process32FirstW,CreateToolhelp32Snapshot,FindCloseChangeNotification, 3_2_00E68BC8
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\f_00321b.dll",#1
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4128:120:WilError_01
Source: C:\Windows\System32\regsvr32.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Automated click: OK
Source: C:\Windows\System32\regsvr32.exe Automated click: OK
Source: Window Recorder Window detected: More than 3 window changes detected
Source: f_00321b.dll Static PE information: Image base 0x180000000 > 0x60000000
Source: f_00321b.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: f_00321b.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: f_00321b.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: f_00321b.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: f_00321b.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: f_00321b.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: f_00321b.dll Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: f_00321b.dll Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: f_00321b.dll Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: f_00321b.dll Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: f_00321b.dll Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: f_00321b.dll Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180005C69 push rdi; ret 3_2_0000000180005C72
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800056DD push rdi; ret 3_2_00000001800056E4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6A0FC push ebp; iretd 3_2_00E6A0FD
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E780D7 push ebp; retf 3_2_00E780D8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E66CDE push esi; iretd 3_2_00E66CDF
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E66C9F pushad ; ret 3_2_00E66CAA
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6A1D2 push ebp; iretd 3_2_00E6A1D3
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E77987 push ebp; iretd 3_2_00E7798F
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E77D4E push ebp; iretd 3_2_00E77D4F
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E78157 push ebp; retf 3_2_00E78158
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E69D51 push ebp; retf 3_2_00E69D5A
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E77D25 push 4D8BFFFFh; retf 3_2_00E77D2A
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E77D3C push ebp; retf 3_2_00E77D3D
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E77EAF push 458BCC5Ah; retf 3_2_00E77EBC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E69E8B push eax; retf 3_2_00E69E8E
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E6A26E push ebp; ret 3_2_00E6A26F
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00E7C731 push esi; iretd 3_2_00E7C732
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_0000000180005C69 push rdi; ret 4_2_0000000180005C72
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000001800056DD push rdi; ret 4_2_00000001800056E4
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7728157 push ebp; retf 4_2_00000263A7728158
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7727D4E push ebp; iretd 4_2_00000263A7727D4F
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7719D51 push ebp; retf 4_2_00000263A7719D5A
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7727D3C push ebp; retf 4_2_00000263A7727D3D
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7727D25 push 4D8BFFFFh; retf 4_2_00000263A7727D2A
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771A1D2 push ebp; iretd 4_2_00000263A771A1D3
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7727987 push ebp; iretd 4_2_00000263A772798F
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A771A0FC push ebp; iretd 4_2_00000263A771A0FD
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A77280D7 push ebp; retf 4_2_00000263A77280D8
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7716CDE push esi; iretd 4_2_00000263A7716CDF
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A7716C9F pushad ; ret 4_2_00000263A7716CAA
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000263A772C731 push esi; iretd 4_2_00000263A772C732
Source: f_00321b.dll Static PE information: section name: _RDATA
Source: C:\Windows\System32\loaddll64.exe Process created: C:\Windows\System32\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\f_00321b.dll
Source: C:\Windows\System32\regsvr32.exe PE file moved: C:\Windows\System32\ChVCsX\ramMHRyb.dll Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\System32\regsvr32.exe File opened: C:\Windows\system32\ChVCsX\ramMHRyb.dll:Zone.Identifier read attributes | delete Jump to behavior
Source: C:\Windows\System32\rundll32.exe File opened: C:\Windows\system32\LwMWPX\mOtL.dll:Zone.Identifier read attributes | delete Jump to behavior
Source: C:\Windows\System32\rundll32.exe File opened: C:\Windows\system32\WiCuwn\qvjh.dll:Zone.Identifier read attributes | delete Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe TID: 4440 Thread sleep time: -660000s >= -30000s Jump to behavior
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\regsvr32.exe API coverage: 7.9 %
Source: C:\Windows\System32\regsvr32.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180008D28 FindFirstFileExW, 3_2_0000000180008D28
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_0000000180008D28 FindFirstFileExW, 4_2_0000000180008D28
Source: C:\Windows\System32\regsvr32.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\rundll32.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: regsvr32.exe, 00000003.00000002.323042922.0000000000CB5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: hGFsjg
Source: rundll32.exe, 00000005.00000002.321631471.00000264E3AB8000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\H
Source: regsvr32.exe, 00000006.00000003.494204988.00000000009E8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494204988.00000000009D4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.407309155.000000000099C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.407309155.00000000009E8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.407505388.00000000009D2000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494106768.000000000099C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000002.837838850.000000000099C000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000002.837838850.00000000009D4000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000003.494106768.00000000009E8000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000006.00000002.837838850.00000000009E8000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: rundll32.exe, 00000005.00000002.321631471.00000264E3AB8000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180001C48 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 3_2_0000000180001C48
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000A878 GetProcessHeap, 3_2_000000018000A878
Source: C:\Windows\System32\loaddll64.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180010C10 LdrFindResource_U,LdrAccessResource,NtAllocateVirtualMemory, 3_2_0000000180010C10
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180001C48 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 3_2_0000000180001C48
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800082EC RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 3_2_00000001800082EC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800017DC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 3_2_00000001800017DC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_0000000180001C48 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 4_2_0000000180001C48
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000001800082EC RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 4_2_00000001800082EC
Source: C:\Windows\System32\rundll32.exe Code function: 4_2_00000001800017DC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 4_2_00000001800017DC

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\System32\cmd.exe Process created / APC Queued / Resumed: C:\Windows\System32\rundll32.exe Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 159.65.88.10 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 164.90.222.65 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 213.239.212.5 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 186.194.240.217 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 104.168.155.143 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 159.89.202.34 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 160.16.142.56 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 91.121.146.47 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 91.207.28.33 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 103.43.75.120 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 45.235.8.30 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 72.15.201.15 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 163.44.196.120 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 206.189.28.199 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 107.170.39.149 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 187.63.160.88 80 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 66.228.32.31 7080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 82.223.21.224 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 149.56.131.28 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 169.57.156.166 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 182.162.143.56 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 1.234.2.232 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 167.172.199.165 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Thread APC queued: target process: C:\Windows\System32\rundll32.exe Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\f_00321b.dll",#1 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800070A0 cpuid 3_2_00000001800070A0
Source: C:\Windows\System32\regsvr32.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180001D98 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, 3_2_0000000180001D98

Stealing of Sensitive Information

barindex
Source: Yara match File source: 00000006.00000002.837764087.000000000095B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 4.2.rundll32.exe.263a5e10000.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.regsvr32.exe.b20000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.rundll32.exe.263a5e10000.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.regsvr32.exe.c60000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.regsvr32.exe.c60000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.rundll32.exe.264e3c10000.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.rundll32.exe.264e3c10000.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.regsvr32.exe.b20000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000004.00000002.321671737.00000263A5E10000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.322224352.00000264E3C10000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.322307535.00000264E3C41000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.322806911.0000000000C60000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.323368547.0000000000E61000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000002.322501137.00000263A7711000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.837994080.0000000000B20000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.838029759.0000000000B51000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs