cred.dll

First submission 2024-10-16 21:18:02

File details

File type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 1059.5 KB (1084928 bytes)
Compile time: 2024-09-03 21:59:27
MD5: 16ab3210260ec2df7ffc2292e9ad4abb
SHA1: 949054dbd0ce544abffb550462d322ff6f91a1f7
SHA256: f8dc1e4d3a7b22529a99578313d6168aa5f915913217b1ed4348f773f0a37c4e
Import Hash : 213cc311d974657ce4f52e13b2302f94
Sections 5 .text .rdata .data .rsrc .reloc
Directories 5 import export resource debug relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 39/77 VT report date: 2024-10-16 20:49:30
Malware Type 3 trojan downloader virus
Threat Type 3 zusy stealer amadey

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://specificsecurity.ru/NfjxzZz9jn/Plugins/cred.dll VirusTotal Report specificsecurity.ru VirusTotal Report 2024-10-16 21:18:02

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0xe3ee8 933888 ea9fa306a5b326da9cc6d9a24f15ec0a579d5e8e 9a9876375fd2ade75569dbc58ad53984
.rdata 0xe5000 0x1af62 110592 62a92e2b29a9c3b84c7647e939f4105a47a59786 680cf709af1843f69b7d0bbbe3f08f04
.data 0x100000 0x8f3c 11264 2a59530251e56b631aead7325344c79c3911ef93 57d5422df62ff375150c6f0773c343fd
.rsrc 0x109000 0xf8 512 559dd1af6be9b7f0e774e38607b61734b83898f4 ac715e79d7a1c770f83f459c3488063f
.reloc 0x10a000 0x6a60 27648 628b6a1008bb855c92341885a4ae172817c446d1 4030b5cf8ff59e050b061b8896286d15

PE Resources 1

Name Language Sublanguage Offset Size Data
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x109060 145

Packers detected 1

Borland Delphi 3.0 (???)

Anti debug functions 10

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
OutputDebugStringA
OutputDebugStringW
Process32FirstW
Process32NextW
RaiseException
TerminateProcess
UnhandledExceptionFilter

Anti debug functions 1

VMCheck.dll

Strings analysis - File found

XML
Psi\profiles\default\accounts.xml
FileZilla\sitemanager.xml
\.purple\accounts.xml
.purple\accounts.xml
Library
mscoree.dll
KERNEL32.dll
ADVAPI32.dll
SHELL32.dll
WININET.dll
Crypt32.dll
STEALERDLL.dll
nss3.dll
bcrypt.dll

Strings analysis - Possible IPs found 1

3.8.7.4

Import functions

PE Exports 2 suspicious

Function Address
Main 0x100b1100
Save 0x100045c0
Name Latest seen MD5
cred.dll 2024-07-21 09:03:01 765ad3b71d73ed1ae9e4fb004876837e
cred.dll 2024-07-29 00:15:02 d696e4ee5dac5d3e4b5073359224fcdc
cred.dll 2024-10-16 21:00:02 b3d199fd9fa4a18f08d4aa9e17181869
cred.dll 2024-10-16 21:17:02 13c5fbf7e0d1ea910bf55a32a877217f
cred.dll 2024-10-16 21:19:03 0961bd2ba614e84e0b9b93444179fb07
cred.dll 2024-10-16 21:20:03 7c5bea5cda7a89450f82fa18497a0191