cred.dll

First submission 2024-10-16 21:19:03

File details

File type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 1059.5 KB (1084928 bytes)
Compile time: 2024-08-15 09:45:07
MD5: 0961bd2ba614e84e0b9b93444179fb07
SHA1: 01b08bc5d94786033817737a15d5a644e6c5522e
SHA256: 6a96055edb6ed8095a65c6625fbd7dfb9c11cc50b70535f798701741c42d29c7
Import Hash : 213cc311d974657ce4f52e13b2302f94
Sections 5 .text .rdata .data .rsrc .reloc
Directories 5 import export resource debug relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 41/77 VT report date: 2024-09-01 12:35:45
Malware Type 3 trojan downloader spyware
Threat Type 3 lazy stealer amadey

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://amoamoxxx.org/h9fmdW5/Plugins/cred.dll VirusTotal Report amoamoxxx.org VirusTotal Report 2024-10-16 21:19:03

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0xe3ee8 933888 c5bf5c59868855be265b986539ed4f1a07ec50b4 4bf3c5c9c6ad13e8723a8bbfad68af65
.rdata 0xe5000 0x1aee2 110592 0fd2b777dcee21a81f900e462ad60ff6773f021b 2b0a54de13d10e5164392b438ec37053
.data 0x100000 0x8f3c 11264 2a59530251e56b631aead7325344c79c3911ef93 57d5422df62ff375150c6f0773c343fd
.rsrc 0x109000 0xf8 512 559dd1af6be9b7f0e774e38607b61734b83898f4 ac715e79d7a1c770f83f459c3488063f
.reloc 0x10a000 0x6a64 27648 c234933b7ab8627ddc1f4c1959c6582c2bdee5d2 6952cdb665702dec570775137775fd2c

PE Resources 1

Name Language Sublanguage Offset Size Data
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x109060 145

Packers detected 1

Borland Delphi 3.0 (???)

Anti debug functions 10

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
OutputDebugStringA
OutputDebugStringW
Process32FirstW
Process32NextW
RaiseException
TerminateProcess
UnhandledExceptionFilter

Anti debug functions 1

VMCheck.dll

Strings analysis - File found

XML
Psi\profiles\default\accounts.xml
FileZilla\sitemanager.xml
\.purple\accounts.xml
.purple\accounts.xml
Library
mscoree.dll
KERNEL32.dll
ADVAPI32.dll
SHELL32.dll
WININET.dll
Crypt32.dll
STEALERDLL.dll
nss3.dll
bcrypt.dll

Strings analysis - Possible IPs found 1

3.8.7.4

Import functions

PE Exports 2 suspicious

Function Address
Main 0x100b1100
Save 0x100045c0
Name Latest seen MD5
cred.dll 2024-07-21 09:03:01 765ad3b71d73ed1ae9e4fb004876837e
cred.dll 2024-07-29 00:15:02 d696e4ee5dac5d3e4b5073359224fcdc
cred.dll 2024-10-16 21:00:02 b3d199fd9fa4a18f08d4aa9e17181869
cred.dll 2024-10-16 21:17:02 13c5fbf7e0d1ea910bf55a32a877217f
cred.dll 2024-10-16 21:18:02 16ab3210260ec2df7ffc2292e9ad4abb
cred.dll 2024-10-16 21:20:03 7c5bea5cda7a89450f82fa18497a0191