clip.dll

First submission 2024-10-16 22:39:02 Last sumbission 2024-10-16 22:59:02

File details

File type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 127.5 KB (130560 bytes)
Compile time: 2024-08-15 09:45:13
MD5: 143a210c0ca4bd09985f12b588663ab4
SHA1: 8c65022cb4ded4828355b14a14d4405520841431
SHA256: f827d48567e71dfd1c461fb55eba0487c8d4b37eedbb10141a4b7a4bb4cbb0e4
Import Hash : 61d6334c6ae4948c906d9fa7fdf019fa
Sections 5 .text .rdata .data .rsrc .reloc
Directories 5 import export resource debug relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 54/77 VT report date: 2024-09-23 04:22:31
Malware Type 2 trojan spyware
Threat Type 3 clipbanker zusy amadey

URLs, FQDN and IP indicators 2

URL Host (FQDN/IP) Date Added
hXXp://amoamoxxx.org/h9fmdW5/Plugins/clip.dll VirusTotal Report amoamoxxx.org VirusTotal Report 2024-10-16 22:59:07
hXXp://amoamoxxx.org/h9fmdW5/Plugins/clip64.dll VirusTotal Report amoamoxxx.org VirusTotal Report 2024-10-16 22:39:02

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x15196 86528 a226706d03e3b544a2fc8563f843be11874db9b9 4a7a23b4f2e31cba4b61dde618028e54
.rdata 0x17000 0x7484 30208 8887824f565d7765dca46503ec7ea40158d2d21a 0062af3c04bcb323d3e0d9089eb65059
.data 0x1f000 0x1fec 5120 6eb3ab51a43d826acc2b861a90658128c9aa8f64 47194855062a9f9e40dc0935b821e7d6
.rsrc 0x21000 0xf8 512 556dad6d72965fdf2d4e270faef33671467ab7fa afd41cb39f7e6ea2c4693556d1b1867c
.reloc 0x22000 0x1b74 7168 a341b97c54669501d7c1f3153bb8112e91998c0e 198e2af552621b3e5788e524a653b98b

PE Resources 1

Name Language Sublanguage Offset Size Data
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x21060 145

Packers detected 1

Borland Delphi 3.0 (???)

Anti debug functions 6

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
RaiseException
TerminateProcess
UnhandledExceptionFilter

Strings analysis - File found

Library
mscoree.dll
USER32.dll
WININET.dll
ClipperDLL.dll
KERNEL32.dll

Import functions

PE Exports 3 suspicious

Function Address
??4CClipperDLL@@QAEAAV0@$$QAV0@@Z 0x10001d60
??4CClipperDLL@@QAEAAV0@ABV0@@Z 0x10001d60
Main 0x10005b50
Name Latest seen MD5
clip.dll 2024-07-21 09:04:01 8cfd7419f24c7904d2a71b5ae6ea5daa
clip.dll 2024-07-29 00:11:01 7d257e3bb8441810561e09092162df73
clip64.dll 2024-08-28 07:06:02 babfda6375b07d76f6a46af11bdc3787
clip64.dll 2024-10-16 21:40:02 b7836f044f3f89eff107ee5d2342a9a2
clip.dll 2024-10-16 22:57:01 9730e0bcf27e4265d1be56b8a7767759
clip.dll 2024-10-16 23:15:02 bd38b3834594180499a656b6cf3dfab0
clip64.dll 2024-10-16 23:16:03 b865aac4da61f8cc682d090819d12dd6