
Emotet OCX Loader Beacons to Four Continents via regsvr32 Proxy
A 64-bit DLL disguised as an OLE Control Extension file uses regsvr32 to proxy its execution and contacts four geographically dispersed C2 servers spanning Malaysia, Ghana, Germany, and South Korea. The payload's high-entropy resource section, zero-import table, and Dridex-overlapping TLS fingerprint point to an active Emotet deployment with potential banking trojan second-stage delivery still observable as recently as June 2026.
A 64-bit Windows DLL masquerading as an OLE Control Extension file — delivered under the name hvxda.ocx and designed to run through regsvr32 rather than a conventional executable launcher — sits at the centre of an active Emotet deployment that has been beaconing to four geographically dispersed command-and-control servers across Malaysia, Ghana, Germany, and South Korea.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read