cred.dll
First submission 2024-10-16 21:19:03
File details
File type: | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows |
Mime type: | application/x-dosexec |
File size: | 1059.5 KB (1084928 bytes) |
Compile time: | 2024-08-15 09:45:07 |
MD5: | 0961bd2ba614e84e0b9b93444179fb07 |
SHA1: | 01b08bc5d94786033817737a15d5a644e6c5522e |
SHA256: | 6a96055edb6ed8095a65c6625fbd7dfb9c11cc50b70535f798701741c42d29c7 |
Import Hash : | 213cc311d974657ce4f52e13b2302f94 |
Sections 5 | .text .rdata .data .rsrc .reloc |
Directories 5 | import export resource debug relocation |
File features detected
Signed
XOR
OSINT Enrichments
Virus Total: | 41/77 VT report date: 2024-09-01 12:35:45 |
Malware Type 3 | trojan downloader spyware |
Threat Type 3 | lazy stealer amadey |
URLs, FQDN and IP indicators 1
PE Sections 0 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
.text | 0x1000 | 0xe3ee8 | 933888 | c5bf5c59868855be265b986539ed4f1a07ec50b4 | 4bf3c5c9c6ad13e8723a8bbfad68af65 | |
.rdata | 0xe5000 | 0x1aee2 | 110592 | 0fd2b777dcee21a81f900e462ad60ff6773f021b | 2b0a54de13d10e5164392b438ec37053 | |
.data | 0x100000 | 0x8f3c | 11264 | 2a59530251e56b631aead7325344c79c3911ef93 | 57d5422df62ff375150c6f0773c343fd | |
.rsrc | 0x109000 | 0xf8 | 512 | 559dd1af6be9b7f0e774e38607b61734b83898f4 | ac715e79d7a1c770f83f459c3488063f | |
.reloc | 0x10a000 | 0x6a64 | 27648 | c234933b7ab8627ddc1f4c1959c6582c2bdee5d2 | 6952cdb665702dec570775137775fd2c |
PE Resources 1
Name | Language | Sublanguage | Offset | Size | Data |
---|---|---|---|---|---|
RT_MANIFEST | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x109060 | 145 |
Packers detected 1
Borland Delphi 3.0 (???) |
Anti debug functions 10
GetLastError |
IsDebuggerPresent |
IsProcessorFeaturePresent |
OutputDebugStringA |
OutputDebugStringW |
Process32FirstW |
Process32NextW |
RaiseException |
TerminateProcess |
UnhandledExceptionFilter |
Anti debug functions 1
VMCheck.dll |
Strings analysis - File found
XML |
Psi\profiles\default\accounts.xml |
FileZilla\sitemanager.xml |
\.purple\accounts.xml |
.purple\accounts.xml |
Library |
mscoree.dll |
KERNEL32.dll |
ADVAPI32.dll |
SHELL32.dll |
WININET.dll |
Crypt32.dll |
STEALERDLL.dll |
nss3.dll |
bcrypt.dll |
Strings analysis - Possible IPs found 1
3.8.7.4 |
Import functions
PE Exports 2 suspicious
Function | Address |
---|---|
Main | 0x100b1100 |
Save | 0x100045c0 |
Name | Latest seen | MD5 |
---|---|---|
cred.dll | 2024-07-21 09:03:01 | 765ad3b71d73ed1ae9e4fb004876837e |
cred.dll | 2024-07-29 00:15:02 | d696e4ee5dac5d3e4b5073359224fcdc |
cred.dll | 2024-10-16 21:00:02 | b3d199fd9fa4a18f08d4aa9e17181869 |
cred.dll | 2024-10-16 21:17:02 | 13c5fbf7e0d1ea910bf55a32a877217f |
cred.dll | 2024-10-16 21:18:02 | 16ab3210260ec2df7ffc2292e9ad4abb |
cred.dll | 2024-10-16 21:20:03 | 7c5bea5cda7a89450f82fa18497a0191 |