ieframe.dll

  • File Path: C:\Windows\SysWOW64\ieframe.dll
  • Description: Internet Browser

Hashes

Type Hash
MD5 F2918721C5129A4704436504CF2DF263
SHA1 DFF849C31E330B825472C09A318ED0C8972B6238
SHA256 78AA17963926353EE79C27D8660DAF2698E762F251F9AD095B3E01AA5BC88013
SHA384 48FE5356870B8A6D1C3AC3E4475A514CD96673624FAABCC42E0C140F151C83124BAEC45AECFD680BE4A09869F57ED4C9
SHA512 C8112E1090EEC5FF80C4549334C35BC3EAA42BD58895ED57DA59C91B13CCCA26C620709BBDCC270653A70EEBEB31F0204C2CA7B2DB6F3061B986341E1A85B5D1
SSDEEP 98304:8AOLJncx7KyotSdM5zBdWO5bJIWx1fLhSTe/Lh4FqwMZAxCuRgx5jbeGF:8AOLmKTlWO5lIW7ASTh4A
IMP 56AFD4787BAB3AA334A3CEAEC8776BFC
PESHA1 C565BC68654E47BD2A4578212EF9740B4313312B
PE256 75E6D2B03A1D80EF0127FE06C954DBA0D37ADBD882114D5B4CF71BD66B7DE57C

DLL Exports:

Function Name Ordinal Type
IERegisterWritableRegistryKey 155 Exported Function
IERegCreateKeyEx 149 Exported Function
IERefreshElevationPolicy 148 Exported Function
IERegisterWritableRegistryValue 156 Exported Function
IESaveFile 157 Exported Function
IERemoveDirectory 111 Exported Function
IERegSetValueEx 154 Exported Function
IEMoveFileEx 110 Exported Function
IEIsInPrivateBrowsing 108 Exported Function
IEInPrivateFilteringEnabled 107 Exported Function
IEGetWriteableHKCU 144 Exported Function
IEIsProtectedModeProcess 145 Exported Function
IELaunchURL 147 Exported Function
IELaunchManageAddOnsUI 109 Exported Function
IEIsProtectedModeURL 146 Exported Function
SHAddSubscribeFavorite 163 Exported Function
SetQueryNetSessionCount 114 Exported Function
OpenURL 175 Exported Function
SoftwareUpdateMessageBox 176 Exported Function
URLQualifyW 179 Exported Function
URLQualifyA 178 Exported Function
TriggerFileDownload 177 Exported Function
ImportPrivacySettings 174 Exported Function
IEShowOpenFileDialog 169 Exported Function
IESetProtectedModeCookieEx 164 Exported Function
IESetProtectedModeCookie 161 Exported Function
IEShowSaveFileDialog 171 Exported Function
ImportCookieFileByProcessW 113 Exported Function
IEUnregisterWritableRegistry 173 Exported Function
IETrackingProtectionEnabled 112 Exported Function
IEGetWriteableFolderPath 140 Exported Function
DoAddToFavDlgW 124 Exported Function
DoAddToFavDlg 123 Exported Function
DllUnregisterServer 122 Exported Function
DoBlobDownload 125 Exported Function
DoOrganizeFavDlg 128 Exported Function
DoFileDownloadEx 127 Exported Function
DoFileDownload 126 Exported Function
DllRegisterServer 121 Exported Function
CreateExtensionGuidEnumerator 96 Exported Function
CORLockDownProvider 116 Exported Function
AddUrlToFavorites 115 Exported Function
DllCanUnloadNow 117 Exported Function
DllInstall 120 Exported Function
DllGetVersion 119 Exported Function
DllGetClassObject 118 Exported Function
IEDeleteFile 100 Exported Function
IECreateFile 99 Exported Function
IECreateDirectory 98 Exported Function
IEDisassociateThreadWithTab 138 Exported Function
IEGetProtectedModeCookie 139 Exported Function
IEGetFileAttributesEx 106 Exported Function
IEFindFirstFile 104 Exported Function
IECancelSaveFile 136 Exported Function
ExportCookieFileByProcessW 97 Exported Function
DoPrivacyDlg 130 Exported Function
DoOrganizeFavDlgW 129 Exported Function
HlinkFindFrame 131 Exported Function
IEAssociateThreadWithTab 134 Exported Function
HlinkFrameNavigateNHL 133 Exported Function
HlinkFrameNavigate 132 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: IEFRAME.DLL
  • Product Name: Internet Explorer
  • Company Name: Microsoft Corporation
  • File Version: 11.00.19041.488 (WinBuild.160101.0800)
  • Product Version: 11.00.19041.488
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/68
  • VirusTotal Link: https://www.virustotal.com/gui/file/78aa17963926353ee79c27d8660daf2698e762f251f9ad095b3e01aa5bc88013/detection/

Possible Misuse

The following table contains possible examples of ieframe.dll being misused. While ieframe.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_susp_rundll32_activity.yml - 'ieframe.dll' DRL 1.0
LOLBAS Ieframe.yml - Command: rundll32.exe ieframe.dll,OpenURL "C:\test\calc.url"  
LOLBAS Ieframe.yml - Path: c:\windows\system32\ieframe.dll  
LOLBAS Ieframe.yml - Path: c:\windows\syswow64\ieframe.dll  
LOLBAS Ieframe.yml - Link: https://windows10dll.nirsoft.net/ieframe_dll.html  

MIT License. Copyright (c) 2020-2021 Strontic.