cred.dll

First submission 2024-10-16 21:17:02

File details

File type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 1059.5 KB (1084928 bytes)
Compile time: 2024-02-19 22:01:37
MD5: 13c5fbf7e0d1ea910bf55a32a877217f
SHA1: 94c4ead19fe2a1460991a93ef0cb68f8af6affab
SHA256: 3d0614fc19ceaa2d1deb3c1a58b12a60d104815d16dcb1c1859d82bff56fa09d
Import Hash : 213cc311d974657ce4f52e13b2302f94
Sections 5 .text .rdata .data .rsrc .reloc
Directories 5 import export resource debug relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 48/77 VT report date: 2024-05-06 08:31:15
Malware Type 3 trojan downloader virus
Threat Type 3 amadey stealer lazy

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://185.11.61.121/h8s9k20gnb2/Plugins/cred.dll VirusTotal Report 185.11.61.121 VirusTotal Report 2024-10-16 21:17:02

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0xe3ee8 933888 49f5391dbe25c7c177b19ccea1ea04d96eca2806 f0286f699c61b6f05877940ec4dc4129
.rdata 0xe5000 0x1aeb2 110592 516f869b7ae8e825e24d6e9f837a28b2e066a4b1 90974e9e5a65eaaf53464e79006932d6
.data 0x100000 0x8eec 11264 60d8ea6c8ef177b41e631f8a7834e3209526a4d3 af0a6469ec938920e5a33ed8a8cbfd8d
.rsrc 0x109000 0xf8 512 559dd1af6be9b7f0e774e38607b61734b83898f4 ac715e79d7a1c770f83f459c3488063f
.reloc 0x10a000 0x6a38 27648 f14ddf5fb51a8c4dad87aa3ca06b87eca6478876 c7aa27898786c5fd08f520932c8c037b

PE Resources 1

Name Language Sublanguage Offset Size Data
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x109060 145

Packers detected 1

Borland Delphi 3.0 (???)

Anti debug functions 10

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
OutputDebugStringA
OutputDebugStringW
Process32FirstW
Process32NextW
RaiseException
TerminateProcess
UnhandledExceptionFilter

Anti debug functions 1

VMCheck.dll

Strings analysis - File found

XML
Psi\profiles\default\accounts.xml
FileZilla\sitemanager.xml
\.purple\accounts.xml
.purple\accounts.xml
Library
mscoree.dll
KERNEL32.dll
ADVAPI32.dll
SHELL32.dll
WININET.dll
Crypt32.dll
STEALERDLL.dll
nss3.dll
bcrypt.dll

Strings analysis - Possible IPs found 1

3.8.7.4

Import functions

PE Exports 2 suspicious

Function Address
Main 0x100b1240
Save 0x10004570
Name Latest seen MD5
cred.dll 2024-07-21 09:03:01 765ad3b71d73ed1ae9e4fb004876837e
cred.dll 2024-07-29 00:15:02 d696e4ee5dac5d3e4b5073359224fcdc
cred.dll 2024-10-16 21:00:02 b3d199fd9fa4a18f08d4aa9e17181869
cred.dll 2024-10-16 21:18:02 16ab3210260ec2df7ffc2292e9ad4abb
cred.dll 2024-10-16 21:19:03 0961bd2ba614e84e0b9b93444179fb07
cred.dll 2024-10-16 21:20:03 7c5bea5cda7a89450f82fa18497a0191