cred.dll
First submission 2024-10-16 21:18:02
File details
File type: | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows |
Mime type: | application/x-dosexec |
File size: | 1059.5 KB (1084928 bytes) |
Compile time: | 2024-09-03 21:59:27 |
MD5: | 16ab3210260ec2df7ffc2292e9ad4abb |
SHA1: | 949054dbd0ce544abffb550462d322ff6f91a1f7 |
SHA256: | f8dc1e4d3a7b22529a99578313d6168aa5f915913217b1ed4348f773f0a37c4e |
Import Hash : | 213cc311d974657ce4f52e13b2302f94 |
Sections 5 | .text .rdata .data .rsrc .reloc |
Directories 5 | import export resource debug relocation |
File features detected
Signed
XOR
OSINT Enrichments
Virus Total: | 39/77 VT report date: 2024-10-16 20:49:30 |
Malware Type 3 | trojan downloader virus |
Threat Type 3 | zusy stealer amadey |
URLs, FQDN and IP indicators 1
PE Sections 0 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
.text | 0x1000 | 0xe3ee8 | 933888 | ea9fa306a5b326da9cc6d9a24f15ec0a579d5e8e | 9a9876375fd2ade75569dbc58ad53984 | |
.rdata | 0xe5000 | 0x1af62 | 110592 | 62a92e2b29a9c3b84c7647e939f4105a47a59786 | 680cf709af1843f69b7d0bbbe3f08f04 | |
.data | 0x100000 | 0x8f3c | 11264 | 2a59530251e56b631aead7325344c79c3911ef93 | 57d5422df62ff375150c6f0773c343fd | |
.rsrc | 0x109000 | 0xf8 | 512 | 559dd1af6be9b7f0e774e38607b61734b83898f4 | ac715e79d7a1c770f83f459c3488063f | |
.reloc | 0x10a000 | 0x6a60 | 27648 | 628b6a1008bb855c92341885a4ae172817c446d1 | 4030b5cf8ff59e050b061b8896286d15 |
PE Resources 1
Name | Language | Sublanguage | Offset | Size | Data |
---|---|---|---|---|---|
RT_MANIFEST | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x109060 | 145 |
Packers detected 1
Borland Delphi 3.0 (???) |
Anti debug functions 10
GetLastError |
IsDebuggerPresent |
IsProcessorFeaturePresent |
OutputDebugStringA |
OutputDebugStringW |
Process32FirstW |
Process32NextW |
RaiseException |
TerminateProcess |
UnhandledExceptionFilter |
Anti debug functions 1
VMCheck.dll |
Strings analysis - File found
XML |
Psi\profiles\default\accounts.xml |
FileZilla\sitemanager.xml |
\.purple\accounts.xml |
.purple\accounts.xml |
Library |
mscoree.dll |
KERNEL32.dll |
ADVAPI32.dll |
SHELL32.dll |
WININET.dll |
Crypt32.dll |
STEALERDLL.dll |
nss3.dll |
bcrypt.dll |
Strings analysis - Possible IPs found 1
3.8.7.4 |
Import functions
PE Exports 2 suspicious
Function | Address |
---|---|
Main | 0x100b1100 |
Save | 0x100045c0 |
Name | Latest seen | MD5 |
---|---|---|
cred.dll | 2024-07-21 09:03:01 | 765ad3b71d73ed1ae9e4fb004876837e |
cred.dll | 2024-07-29 00:15:02 | d696e4ee5dac5d3e4b5073359224fcdc |
cred.dll | 2024-10-16 21:00:02 | b3d199fd9fa4a18f08d4aa9e17181869 |
cred.dll | 2024-10-16 21:17:02 | 13c5fbf7e0d1ea910bf55a32a877217f |
cred.dll | 2024-10-16 21:19:03 | 0961bd2ba614e84e0b9b93444179fb07 |
cred.dll | 2024-10-16 21:20:03 | 7c5bea5cda7a89450f82fa18497a0191 |