regsvr.exe

The executable regsvr.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Msn Messsenger’. While running, it connects to the Internet address 210.151.74.137.fr.axspace.com on port 80 using the HTTP protocol.
MD5:
9db221717a5a1ebbd62bc10a0fa895ac

SHA-1:
49c16faa85b48cb0c0e2fd68677179c1ae2054cc

SHA-256:
74ca72f6646357f8775d68b4b4212ed29b492295a1891176b3bc10c341a94f9f

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
1/13/2025 4:23:41 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Tojan.Click (H)
17.2.8.9

File size:
1.7 MB (1,747,969 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\regsvr.exe

File PE Metadata
Compilation timestamp:
11/25/2007 1:21:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0xA5000

Entry point:
60, 85, E9, 0F, CA, 0F, BB, CF, 53, 81, FF, A9, 40, 00, 00, 77, 06, 28, C4, D1, F8, D1, E7, 8A, F9, 0F, A5, FE, EB, 06, 0F, C0, CF, 0F, BE, FC, 0F, A4, FD, B7, 8B, D9, 8B, F7, 3D, 50, 69, 00, 00, 0F, A5, C9, D1, D9, C6, C7, D6, FF, C8, C1, F1, 98, 68, 0C, 38, CC, 00, 56, 0F, C0, EE, 0F, BB, F0, E8, 00, 00, 00, 00, 5F, 0F, AD, D6, 86, E6, 8A, CA, 0F, C0, DA, 0F, AC, F9, 2F, 0F, B7, D5, 8D, 1D, C7, F2, 87, 40, 0F, AD, F5, 69, EB, C1, 59, A2, C6, F6, DE, D0, D9, 83, E3, 00, 0F, AF, CB, C1, F1, CB, 81, C3, FA...
 
[+]

Entropy:
3.3009

Code size:
404.5 KB (414,208 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Msn Messsenger

Command:
C:\users\{user}\appdata\roaming\regsvr.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to static.153.167.76.144.clients.your-server.de  (144.76.167.153:80)

TCP (HTTP):
Connects to 93-89-224-9.fbs.com.tr  (93.89.224.9:80)

TCP (HTTP):
Connects to 210.151.74.137.fr.axspace.com  (137.74.151.210:80)

Remove regsvr.exe - Powered by Reason Core Security