regsvr.exe

The executable regsvr.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Msn Messsenger’. While running, it connects to the Internet address ns8914.dotvndns.vn on port 80 using the HTTP protocol.
MD5:
a4d3e0b20bd9f56c84cca8b8f55d7d9c

SHA-1:
7bbbfe10f82bb817d143e2bd20fae416877392eb

SHA-256:
6a150f305ee85c243d5cd9f748e947e3f41223d51268ebea4118c6482b25353d

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/24/2024 3:06:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Tojan.Click (H)
17.2.11.6

File size:
896.5 KB (918,012 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\regsvr.exe

File PE Metadata
Compilation timestamp:
5/5/2009 12:03:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x103A00

Entry point:
60, E8, E6, 19, 00, 00, 8B, 74, 24, 20, E8, 08, 00, 00, 00, 61, 68, 00, 10, 4F, 00, C3, E9, 59, E8, 01, 16, 00, 00, 81, E6, 00, F0, FF, FF, 81, EE, 00, 10, 00, 00, 66, 81, 3E, 4D, 5A, 75, F3, 0F, B7, 7E, 3C, 03, FE, 8B, 6F, 78, 03, EE, 8B, 5D, 20, 03, DE, 33, C0, 8B, D6, 83, C3, 04, 40, 8B, 3B, 03, FA, E8, 0F, 00, 00, 00, 47, 65, 74, 50, 72, 6F, 63, 41, 64, 64, 72, 65, 73, 73, 00, 5E, 33, C9, B1, 0F, FC, F3, A6, 75, DA, 8B, F2, 8B, 5D, 24, 03, DE, 0F, B7, 0C, 43, 8B, 5D, 1C, 03, DE, 8B, 1C, 8B, 03, DE, 81...
 
[+]

Entropy:
7.3152

Packer / compiler:
ASPack v1.08.04

Code size:
404.5 KB (414,208 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Msn Messsenger

Command:
C:\users\{user}\appdata\roaming\regsvr.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ns8914.dotvndns.vn  (112.213.89.14:80)

TCP (HTTP):
Connects to 147.62.236.23.bc.googleusercontent.com  (23.236.62.147:80)

TCP (HTTP SSL):
Connects to 216-185-153-106.aus.us.siteprotect.com  (216.185.153.106:443)

TCP (HTTP SSL):
Connects to ec2-54-210-232-124.compute-1.amazonaws.com  (54.210.232.124:443)

TCP (HTTP SSL):
Connects to ec2-52-0-227-11.compute-1.amazonaws.com  (52.0.227.11:443)

Remove regsvr.exe - Powered by Reason Core Security