IEAdvpack.dll

  • File Path: C:\Windows\SysWOW64\IEAdvpack.dll
  • Description: ADVPACK

Hashes

Type Hash
MD5 D85054DBB788D95263DB2EA2D41C0B8E
SHA1 93A4D08D5F9FE875826CDEB8CC34A882AD881BD4
SHA256 304D1B1731B2D64C768E69A20AC35F65B298AE6EFC9FC11935FE15FB2BC68B99
SHA384 55B09595BA54E649CDA64D5FDBC079293EE7371E0E29836CF42236E84757F103654AACCF61E8EB48A453A18C84410135
SHA512 4DEF4FFD4CE881574A791D28916660CDC4520387041CEF9FD15965B2A085177EF7C9BF03D4DA63A6227027871269A3FF4DE3F581D0BC6136AB81D3CAF18B9BBC
SSDEEP 3072:c6cCdrEZyY755X5YTC81glxQUfifprFB:JiyS5JYN1glxQUfif
IMP 9B8A301A1AEBCA3289FF213FDCDBC165
PESHA1 F96859B0ACF12C2E27F4B68A44E5496A52CB9B63
PE256 1E96B098451027E9022FB5ED2A8938D04284F311D86E6B217217F347F90D4525

DLL Exports:

Function Name Ordinal Type
RegisterOCXW 12 Exported Function
RegRestoreAll 58 Exported Function
RegisterOCX 11 Exported Function
RegInstallA 56 Exported Function
RegInstallW 57 Exported Function
RegSaveRestoreA 62 Exported Function
RegSaveRestoreOnINF 63 Exported Function
RegSaveRestore 61 Exported Function
RegRestoreAllA 59 Exported Function
RegRestoreAllW 60 Exported Function
RegInstall 55 Exported Function
NeedRebootInit 48 Exported Function
OpenINFEngine 49 Exported Function
NeedReboot 47 Exported Function
LaunchINFSectionExW 45 Exported Function
LaunchINFSectionW 46 Exported Function
RebootCheckOnInstallA 53 Exported Function
RebootCheckOnInstallW 54 Exported Function
RebootCheckOnInstall 52 Exported Function
OpenINFEngineA 50 Exported Function
OpenINFEngineW 51 Exported Function
TranslateInfStringW 78 Exported Function
UserInstStubWrapper 79 Exported Function
TranslateInfStringExW 77 Exported Function
TranslateInfStringEx 75 Exported Function
TranslateInfStringExA 76 Exported Function
UserUnInstStubWrapperA 83 Exported Function
UserUnInstStubWrapperW 84 Exported Function
UserUnInstStubWrapper 82 Exported Function
UserInstStubWrapperA 80 Exported Function
UserInstStubWrapperW 81 Exported Function
TranslateInfStringA 74 Exported Function
RunSetupCommand 67 Exported Function
RunSetupCommandA 68 Exported Function
RegSaveRestoreW 66 Exported Function
RegSaveRestoreOnINFA 64 Exported Function
RegSaveRestoreOnINFW 65 Exported Function
SetPerUserSecValuesW 72 Exported Function
TranslateInfString 73 Exported Function
SetPerUserSecValuesA 71 Exported Function
RunSetupCommandW 69 Exported Function
SetPerUserSecValues 70 Exported Function
DoInfInstallA 4 Exported Function
DoInfInstallW 5 Exported Function
DoInfInstall 3 Exported Function
DelNodeRunDLL32W 22 Exported Function
DelNodeW 23 Exported Function
ExtractFiles 27 Exported Function
ExtractFilesA 28 Exported Function
ExecuteCabW 26 Exported Function
ExecuteCab 24 Exported Function
ExecuteCabA 25 Exported Function
DelNodeRunDLL32A 2 Exported Function
AdvInstallFile 16 Exported Function
AdvInstallFileA 17 Exported Function
AddDelBackupEntryW 15 Exported Function
AddDelBackupEntry 13 Exported Function
AddDelBackupEntryA 14 Exported Function
DelNodeA 21 Exported Function
DelNodeRunDLL32 1 Exported Function
DelNode 20 Exported Function
AdvInstallFileW 18 Exported Function
CloseINFEngine 19 Exported Function
GetVersionFromFileExW 41 Exported Function
GetVersionFromFileW 42 Exported Function
GetVersionFromFileExA 40 Exported Function
GetVersionFromFileA 38 Exported Function
GetVersionFromFileEx 39 Exported Function
LaunchINFSectionEx 9 Exported Function
LaunchINFSectionExA 10 Exported Function
LaunchINFSectionA 8 Exported Function
IsNTAdmin 43 Exported Function
LaunchINFSection 44 Exported Function
GetVersionFromFile 37 Exported Function
FileSaveMarkNotExistW 32 Exported Function
FileSaveRestore 6 Exported Function
FileSaveMarkNotExistA 31 Exported Function
ExtractFilesW 29 Exported Function
FileSaveMarkNotExist 30 Exported Function
FileSaveRestoreOnINFW 35 Exported Function
FileSaveRestoreW 36 Exported Function
FileSaveRestoreOnINFA 34 Exported Function
FileSaveRestoreA 7 Exported Function
FileSaveRestoreOnINF 33 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: ADVPACK.DLL.MUI
  • Product Name: Internet Explorer
  • Company Name: Microsoft Corporation
  • File Version: 11.00.19041.1 (WinBuild.160101.0800)
  • Product Version: 11.00.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/69
  • VirusTotal Link: https://www.virustotal.com/gui/file/304d1b1731b2d64c768e69a20ac35f65b298ae6efc9fc11935fe15fb2bc68b99/detection/

File Similarity (ssdeep match)

File Score
C:\Windows\SysWOW64\advpack.dll 85

Possible Misuse

The following table contains possible examples of IEAdvpack.dll being misused. While IEAdvpack.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
LOLBAS Ieadvpack.yml Name: Ieadvpack.dll  
LOLBAS Ieadvpack.yml - Command: rundll32.exe ieadvpack.dll,LaunchINFSection c:\test.inf,DefaultInstall_SingleUser,1,  
LOLBAS Ieadvpack.yml - Command: rundll32.exe ieadvpack.dll,LaunchINFSection c:\test.inf,,1,  
LOLBAS Ieadvpack.yml - Command: rundll32.exe ieadvpack.dll,RegisterOCX test.dll  
LOLBAS Ieadvpack.yml - Command: rundll32.exe ieadvpack.dll,RegisterOCX calc.exe  
LOLBAS Ieadvpack.yml - Command: rundll32 ieadvpack.dll, RegisterOCX "cmd.exe /c calc.exe"  
LOLBAS Ieadvpack.yml - Path: c:\windows\system32\ieadvpack.dll  
LOLBAS Ieadvpack.yml - Path: c:\windows\syswow64\ieadvpack.dll  
LOLBAS Ieadvpack.yml - Code: https://github.com/LOLBAS-Project/LOLBAS-Project.github.io/blob/master/_lolbas/Libraries/Payload/Ieadvpack.inf  
atomic-red-team index.md - Atomic Test #4: Rundll32 ieadvpack.dll Execution [windows] MIT License. © 2018 Red Canary
atomic-red-team windows-index.md - Atomic Test #4: Rundll32 ieadvpack.dll Execution [windows] MIT License. © 2018 Red Canary
atomic-red-team T1218.011.md - Atomic Test #4 - Rundll32 ieadvpack.dll Execution MIT License. © 2018 Red Canary
atomic-red-team T1218.011.md ## Atomic Test #4 - Rundll32 ieadvpack.dll Execution MIT License. © 2018 Red Canary
atomic-red-team T1218.011.md Test execution of a command using rundll32.exe with ieadvpack.dll. MIT License. © 2018 Red Canary
atomic-red-team T1218.011.md Reference: https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSLibraries/Ieadvpack.yml MIT License. © 2018 Red Canary
atomic-red-team T1218.011.md rundll32.exe ieadvpack.dll,LaunchINFSection #{inf_to_execute},DefaultInstall_SingleUser,1, MIT License. © 2018 Red Canary

MIT License. Copyright (c) 2020 Strontic.