regsvr.exe

The executable regsvr.exe has been detected as malware by 41 anti-virus scanners. This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Msn Messsenger’. While running, it connects to the Internet address ir1.fp.vip.gq1.yahoo.com on port 80 using the HTTP protocol.
MD5:
ad98a35fa9b7808c3ec9008d628cff27

SHA-1:
fc6c9b0e9a9d0fb6f59165564331045fd12ff7f5

SHA-256:
ba4f73899cc8cb4b8fcc97eff5cb0d1f4ec6fd60c2de6ed57f1d40dc9fd0f28a

Scanner detections:
41 / 68

Status:
Malware

Analysis date:
4/25/2024 7:17:32 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Worm.Sohanad.NBN
866

Agnitum Outpost
Trojan.Autoit.DX
7.1.1

AhnLab V3 Security
Win32/Virut.F
14.09.22

Avira AntiVirus
TR/Autoit.CI.14
7.11.149.244

avast!
AutoIt:AutoRun-B@BC [Wrm]
2014.9-140922

AVG
Autoit
2015.0.3344

Baidu Antivirus
Virus.Win32.Virut.$NBP
4.0.3.14922

Bitdefender
Win32.Worm.Sohanad.NBN
1.0.20.1325

Bkav FE
W32.Vetor.PE
1.3.0.4959

Clam AntiVirus
Trojan.Siggen-7
0.98/213

Comodo Security
TrojWare.Win32.Trojan.Autoit.ci0
18281

Dr.Web
Win32.Virut.56
9.0.1.0265

Emsisoft Anti-Malware
Win32.Worm.Sohanad.NBN
8.14.09.22.01

ESET NOD32
Win32/Sohanad.NCB
8.9806

Fortinet FortiGate
W32/Autorun.HNW!tr
9/22/2014

F-Prot
W32/Trojan2.DFYJ
v6.4.7.1.166

F-Secure
IM-Worm:W32/Sohanad.HM
11.2014-22-09_2

G Data
Win32.Worm.Sohanad.NBN
14.9.24

IKARUS anti.virus
Trojan.Autoit
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.177.12101

Kaspersky
Worm.Win32.AutoRun
14.0.0.3215

Malwarebytes
Trojan.FakeFolder
v2014.09.22.01

McAfee
W32/Yahlover.worm
5600.7000

Microsoft Security Essentials
Threat.Undefined
1.173.2171.0

MicroWorld eScan
Win32.Worm.Sohanad.NBN
15.0.0.795

NANO AntiVirus
Trojan.Win32.AutoRun.bocatp
0.28.0.59911

Norman
Sohanad.gen5
11.20140922

nProtect
Win32.Worm.Sohanad.NBN
14.05.15.01

Panda Antivirus
W32/Autorun.IOI
14.09.22.01

Qihoo 360 Security
Worm.Win32.FakeFolder.BV
1.0.0.1015

Quick Heal
W32.Virut.G
9.14.14.00

Rising Antivirus
PE:Malware.FakeFolder@CV!1.6AA9
23.00.65.14920

Sophos
W32/AutoRun-BUC
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-AutoIt
10345

Total Defense
Win32/Virut.17408
37.0.10939

Trend Micro House Call
PE_VIRUX.R
7.2.265

Trend Micro
PE_VIRUX.R
10.465.22

Vba32 AntiVirus
Trojan.FakeFolder.2205
3.12.26.0

VIPRE Antivirus
Worm.Win32.Nuqel.z
29260

ViRobot
Win32.Virut.AM
2011.4.7.4223

Zillya! Antivirus
Virus.Virut.Win32.1938
2.0.0.1790

File size:
602.9 KB (617,343 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\regsvr.exe

File PE Metadata
Compilation timestamp:
11/25/2007 1:21:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:V3TdtLW5WIj1YSSdFxsBSXyMzBUWb9lx/9AgHLo8OW+rBj:9Dsj1dEcBcJ9nPx/igrp+1

Entry address:
0xA5001

Entry point:
60, E8, 03, 00, 00, 00, E9, EB, 04, 5D, 45, 55, C3, E8, 01, 00, 00, 00, EB, 5D, BB, ED, FF, FF, FF, 03, DD, 81, EB, 00, 50, 0A, 00, 83, BD, 22, 04, 00, 00, 00, 89, 9D, 22, 04, 00, 00, 0F, 85, 65, 03, 00, 00, 8D, 85, 2E, 04, 00, 00, 50, FF, 95, 4D, 0F, 00, 00, 89, 85, 26, 04, 00, 00, 8B, F8, 8D, 5D, 5E, 53, 50, FF, 95, 49, 0F, 00, 00, 89, 85, 4D, 05, 00, 00, 8D, 5D, 6B, 53, 57, FF, 95, 49, 0F, 00, 00, 89, 85, 51, 05, 00, 00, 8D, 45, 77, FF, E0, 56, 69, 72, 74, 75, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 56, 69, 72...
 
[+]

Entropy:
7.8228

Packer / compiler:
ASPack v2.12

Code size:
404.5 KB (414,208 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Msn Messsenger

Command:
C:\users\{user}\appdata\roaming\regsvr.exe


The file regsvr.exe has been seen being distributed by the following URL.

temp:WhatsApp Audio .exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ir1.fp.vip.ne1.yahoo.com  (98.138.253.109:80)

TCP (HTTP):
Connects to ir1.fp.vip.gq1.yahoo.com  (206.190.36.45:80)

TCP (HTTP):
Connects to ir2.fp.vip.sg3.yahoo.com  (106.10.138.240:80)

TCP (HTTP):
Connects to ir2.fp.vip.bf1.yahoo.com  (98.139.183.24:80)

TCP (HTTP):
Connects to ir1.fp.vip.sg3.yahoo.com  (106.10.139.246:80)

TCP (HTTP):
Connects to ir1.fp.vip.ir2.yahoo.com  (46.228.47.115:80)

Remove regsvr.exe - Powered by Reason Core Security