\\vmware-host\Shared Folders\Projects\ABHTMLv6\ABHTML\Components\Binaries\Release\Toolbar32.pdb
Static task
static1
Behavioral task
behavioral1
Sample
64234b590422a1d522fcfed13cd7c1aa17d33511a0f9497b876be68ce8873b1e.dll
Resource
win7-20240611-en
General
-
Target
64234b590422a1d522fcfed13cd7c1aa17d33511a0f9497b876be68ce8873b1e
-
Size
235KB
-
MD5
58c415820f32552249b6939ede3c1957
-
SHA1
7973c42613a60768e7cb813105b3e1c263652aed
-
SHA256
64234b590422a1d522fcfed13cd7c1aa17d33511a0f9497b876be68ce8873b1e
-
SHA512
38c14872e5f750d920f01f0792a2484853fca17975a436b6dd66bba25576b021490ea16049d09031cd9e369b7cb71f8fc47682116b7a0dc08ed1d5c6ebc5df83
-
SSDEEP
6144:qONxvbbl1+A0nqLqT/BX9dv5MpfKKRn5tr43VIGY:qOTvj+AEqLqTtLv5MpfKKR5BC
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 64234b590422a1d522fcfed13cd7c1aa17d33511a0f9497b876be68ce8873b1e
Files
-
64234b590422a1d522fcfed13cd7c1aa17d33511a0f9497b876be68ce8873b1e.dll regsvr32 windows:5 windows x86 arch:x86
5e99eea411d8869a719c7d5c7988ad10
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
PDB Paths
Imports
urlmon
CoInternetGetSession
kernel32
WaitForSingleObject
GetModuleHandleW
GetCurrentProcess
LocalFree
FlushInstructionCache
RaiseException
SetEvent
GetCurrentThreadId
SetLastError
HeapFree
HeapAlloc
GetProcessHeap
DisableThreadLibraryCalls
InitializeCriticalSectionAndSpinCount
InterlockedIncrement
InterlockedDecrement
SetThreadLocale
GetThreadLocale
GetSystemTime
CreateEventW
CreateThread
GetStringTypeW
GetSystemTimeAsFileTime
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetModuleFileNameA
IsValidCodePage
GetOEMCP
GetACP
SetFilePointer
ReadFile
GetStartupInfoW
SetHandleCount
CloseHandle
GetModuleFileNameW
lstrlenA
lstrlenW
MultiByteToWideChar
GetLastError
Sleep
GetStdHandle
LoadLibraryW
GetProcAddress
DeleteCriticalSection
InitializeCriticalSection
FreeLibrary
WideCharToMultiByte
FindResourceExW
FindResourceW
LoadResource
LockResource
SizeofResource
LeaveCriticalSection
ExitProcess
EnterCriticalSection
SetEndOfFile
WriteFile
WriteConsoleW
CreateFileW
FlushFileBuffers
GetConsoleMode
GetConsoleCP
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
HeapCreate
GetCPInfo
LCMapStringW
GetCommandLineA
GetFileType
SetStdHandle
RtlUnwind
TerminateProcess
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
DecodePointer
EncodePointer
InterlockedExchange
InterlockedPopEntrySList
VirtualAlloc
VirtualFree
IsProcessorFeaturePresent
InterlockedPushEntrySList
InterlockedCompareExchange
HeapDestroy
HeapReAlloc
HeapSize
user32
GetMessageW
TranslateMessage
DispatchMessageW
AllowSetForegroundWindow
CharNextW
CreateWindowExW
UnregisterClassA
GetWindowLongW
RegisterClassExW
DefWindowProcW
DestroyWindow
PostMessageW
LoadCursorW
GetClassInfoExW
SetWindowLongW
CallWindowProcW
advapi32
ConvertSidToStringSidW
RegQueryInfoKeyW
RegGetKeySecurity
ConvertSecurityDescriptorToStringSecurityDescriptorW
InitializeSecurityDescriptor
InitializeAcl
AddAce
SetSecurityDescriptorDacl
RegSetKeySecurity
ConvertStringSecurityDescriptorToSecurityDescriptorW
GetTokenInformation
GetLengthSid
CopySid
RegEnumKeyExW
OpenProcessToken
RegSetValueExW
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryValueExW
RegDeleteKeyW
ole32
CoInitialize
CoUninitialize
StringFromGUID2
CoCreateInstance
StringFromIID
oleaut32
VariantChangeType
LoadRegTypeLi
DispCallFunc
RegisterTypeLi
UnRegisterTypeLi
LoadTypeLi
SysStringLen
SysStringByteLen
SysAllocStringByteLen
VariantCopyInd
SysAllocString
SafeArrayDestroy
SafeArrayCreate
SafeArrayGetUBound
SafeArrayGetLBound
VariantCopy
VariantClear
SafeArrayCopy
VariantInit
SysFreeString
SafeArrayGetVartype
SafeArrayUnlock
SafeArrayLock
Exports
Exports
DllCanUnloadNow
DllGetClassObject
DllInstall
DllRegisterServer
DllUnregisterServer
Sections
.text Size: 168KB - Virtual size: 168KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rdata Size: 37KB - Virtual size: 36KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.data Size: 9KB - Virtual size: 18KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 3KB - Virtual size: 2KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 16KB - Virtual size: 15KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ