IEAdvpack.dll

  • File Path: C:\Windows\system32\IEAdvpack.dll
  • Description: ADVPACK

Hashes

Type Hash
MD5 2114D65021D3596907D983EDB81274FF
SHA1 1933F5BE30E3E037F635B389FF3B20DDB1EB2B42
SHA256 C4B652038665187373562F986F4638ED5DC94AFEF67D4E1A4EB65AA65B25D09F
SHA384 4B00DE35435DAAC8146F07FD8A0F4D8C644BF0170940F9FDEBB0F5FD2C8E33F8E2386486538692F477FC79552B63D17A
SHA512 D65A3C54832657B8765A87B92929B813C2FBFFD5D2D7F4A133E7DB35DF4B0B6AAF7CFB7AE47AA6A1C426EA03B518D0E4FEC2D051BE1182E8A6AF01010A4A5E28
SSDEEP 3072:YWoN5HHXKtGTJnKWPq7cASAmUMowcG8VkGt5MjxQiSferFrd:YtH3+GRPq7cALFMowcFFMjxQNf
IMP F4527A6EF5AFE648805E2A19F417A141
PESHA1 1A830E04EB618C40172A82E8450858FF2E470822
PE256 DB1865796F88150D5EBC0FCC85B28CE9FD73D04166853922256427E940C8665B

DLL Exports:

Function Name Ordinal Type
RegisterOCXW 12 Exported Function
RegRestoreAll 58 Exported Function
RegisterOCX 11 Exported Function
RegInstallA 56 Exported Function
RegInstallW 57 Exported Function
RegSaveRestoreA 62 Exported Function
RegSaveRestoreOnINF 63 Exported Function
RegSaveRestore 61 Exported Function
RegRestoreAllA 59 Exported Function
RegRestoreAllW 60 Exported Function
RegInstall 55 Exported Function
NeedRebootInit 48 Exported Function
OpenINFEngine 49 Exported Function
NeedReboot 47 Exported Function
LaunchINFSectionExW 45 Exported Function
LaunchINFSectionW 46 Exported Function
RebootCheckOnInstallA 53 Exported Function
RebootCheckOnInstallW 54 Exported Function
RebootCheckOnInstall 52 Exported Function
OpenINFEngineA 50 Exported Function
OpenINFEngineW 51 Exported Function
TranslateInfStringW 78 Exported Function
UserInstStubWrapper 79 Exported Function
TranslateInfStringExW 77 Exported Function
TranslateInfStringEx 75 Exported Function
TranslateInfStringExA 76 Exported Function
UserUnInstStubWrapperA 83 Exported Function
UserUnInstStubWrapperW 84 Exported Function
UserUnInstStubWrapper 82 Exported Function
UserInstStubWrapperA 80 Exported Function
UserInstStubWrapperW 81 Exported Function
TranslateInfStringA 74 Exported Function
RunSetupCommand 67 Exported Function
RunSetupCommandA 68 Exported Function
RegSaveRestoreW 66 Exported Function
RegSaveRestoreOnINFA 64 Exported Function
RegSaveRestoreOnINFW 65 Exported Function
SetPerUserSecValuesW 72 Exported Function
TranslateInfString 73 Exported Function
SetPerUserSecValuesA 71 Exported Function
RunSetupCommandW 69 Exported Function
SetPerUserSecValues 70 Exported Function
DoInfInstallA 4 Exported Function
DoInfInstallW 5 Exported Function
DoInfInstall 3 Exported Function
DelNodeRunDLL32W 22 Exported Function
DelNodeW 23 Exported Function
ExtractFiles 27 Exported Function
ExtractFilesA 28 Exported Function
ExecuteCabW 26 Exported Function
ExecuteCab 24 Exported Function
ExecuteCabA 25 Exported Function
DelNodeRunDLL32A 2 Exported Function
AdvInstallFile 16 Exported Function
AdvInstallFileA 17 Exported Function
AddDelBackupEntryW 15 Exported Function
AddDelBackupEntry 13 Exported Function
AddDelBackupEntryA 14 Exported Function
DelNodeA 21 Exported Function
DelNodeRunDLL32 1 Exported Function
DelNode 20 Exported Function
AdvInstallFileW 18 Exported Function
CloseINFEngine 19 Exported Function
GetVersionFromFileExW 41 Exported Function
GetVersionFromFileW 42 Exported Function
GetVersionFromFileExA 40 Exported Function
GetVersionFromFileA 38 Exported Function
GetVersionFromFileEx 39 Exported Function
LaunchINFSectionEx 9 Exported Function
LaunchINFSectionExA 10 Exported Function
LaunchINFSectionA 8 Exported Function
IsNTAdmin 43 Exported Function
LaunchINFSection 44 Exported Function
GetVersionFromFile 37 Exported Function
FileSaveMarkNotExistW 32 Exported Function
FileSaveRestore 6 Exported Function
FileSaveMarkNotExistA 31 Exported Function
ExtractFilesW 29 Exported Function
FileSaveMarkNotExist 30 Exported Function
FileSaveRestoreOnINFW 35 Exported Function
FileSaveRestoreW 36 Exported Function
FileSaveRestoreOnINFA 34 Exported Function
FileSaveRestoreA 7 Exported Function
FileSaveRestoreOnINF 33 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 330000026551AE1BBD005CBFBD000000000265
  • Thumbprint: E168609353F30FF2373157B4EB8CD519D07A2BFF
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: ADVPACK.DLL.MUI
  • Product Name: Internet Explorer
  • Company Name: Microsoft Corporation
  • File Version: 11.00.19041.1 (WinBuild.160101.0800)
  • Product Version: 11.00.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/71
  • VirusTotal Link: https://www.virustotal.com/gui/file/c4b652038665187373562f986f4638ed5dc94afef67d4e1a4eb65aa65b25d09f/detection/

File Similarity (ssdeep match)

File Score
C:\Windows\system32\advpack.dll 86

Possible Misuse

The following table contains possible examples of IEAdvpack.dll being misused. While IEAdvpack.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
LOLBAS Ieadvpack.yml Name: Ieadvpack.dll  
LOLBAS Ieadvpack.yml - Command: rundll32.exe ieadvpack.dll,LaunchINFSection c:\test.inf,DefaultInstall_SingleUser,1,  
LOLBAS Ieadvpack.yml - Command: rundll32.exe ieadvpack.dll,LaunchINFSection c:\test.inf,,1,  
LOLBAS Ieadvpack.yml - Command: rundll32.exe ieadvpack.dll,RegisterOCX test.dll  
LOLBAS Ieadvpack.yml - Command: rundll32.exe ieadvpack.dll,RegisterOCX calc.exe  
LOLBAS Ieadvpack.yml - Command: rundll32 ieadvpack.dll, RegisterOCX "cmd.exe /c calc.exe"  
LOLBAS Ieadvpack.yml - Path: c:\windows\system32\ieadvpack.dll  
LOLBAS Ieadvpack.yml - Path: c:\windows\syswow64\ieadvpack.dll  
LOLBAS Ieadvpack.yml - Code: https://github.com/LOLBAS-Project/LOLBAS-Project.github.io/blob/master/_lolbas/Libraries/Payload/Ieadvpack.inf  
atomic-red-team index.md - Atomic Test #4: Rundll32 ieadvpack.dll Execution [windows] MIT License. © 2018 Red Canary
atomic-red-team windows-index.md - Atomic Test #4: Rundll32 ieadvpack.dll Execution [windows] MIT License. © 2018 Red Canary
atomic-red-team T1218.011.md - Atomic Test #4 - Rundll32 ieadvpack.dll Execution MIT License. © 2018 Red Canary
atomic-red-team T1218.011.md ## Atomic Test #4 - Rundll32 ieadvpack.dll Execution MIT License. © 2018 Red Canary
atomic-red-team T1218.011.md Test execution of a command using rundll32.exe with ieadvpack.dll. MIT License. © 2018 Red Canary
atomic-red-team T1218.011.md Reference: https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSLibraries/Ieadvpack.yml MIT License. © 2018 Red Canary
atomic-red-team T1218.011.md rundll32.exe ieadvpack.dll,LaunchINFSection #{inf_to_execute},DefaultInstall_SingleUser,1, MIT License. © 2018 Red Canary

MIT License. Copyright (c) 2020 Strontic.