clip.dll

First submission 2024-10-16 22:56:01 Last sumbission 2024-10-16 22:57:01

File details

File type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 127.5 KB (130560 bytes)
Compile time: 2024-10-09 14:37:15
MD5: 9730e0bcf27e4265d1be56b8a7767759
SHA1: 11af04e5c73de95a2fb4231970a9f145b39cf381
SHA256: a7a307c332573b2bf76edcf53d37e5a91c1fa3a8ce36f720cb10c8c22928f388
Import Hash : 61d6334c6ae4948c906d9fa7fdf019fa
Sections 5 .text .rdata .data .rsrc .reloc
Directories 5 import export resource debug relocation

File features detected

Is DLL
Packers
Anti Debug
Anti VM
Signed
XOR

OSINT Enrichments

Virus Total: 57/77 VT report date: 2024-10-11 00:37:34
Malware Type 2 trojan spyware
Threat Type 3 clipbanker zusy amadey

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://78.153.139.168/gfj38cHcw/Plugins/clip64.dll VirusTotal Report 78.153.139.168 VirusTotal Report 2024-10-16 22:56:01

PE Sections 0 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0x15196 86528 0f446c9f220827614f4a23dc5c3dca1223ed6de6 3df1fbf159d588846128ab5741f219c7
.rdata 0x17000 0x7494 30208 5fa3f185a3184d120d82d82f039eb67633fa7696 b9b446c7d5ccc1f0870831194a6ec800
.data 0x1f000 0x1fec 5120 6eb3ab51a43d826acc2b861a90658128c9aa8f64 47194855062a9f9e40dc0935b821e7d6
.rsrc 0x21000 0xf8 512 556dad6d72965fdf2d4e270faef33671467ab7fa afd41cb39f7e6ea2c4693556d1b1867c
.reloc 0x22000 0x1b74 7168 5a33b59fb36082c307d118f3e09017372785e6db bc753732a68839a2e93de3610ff5992f

PE Resources 1

Name Language Sublanguage Offset Size Data
RT_MANIFEST LANG_ENGLISH SUBLANG_ENGLISH_US 0x21060 145

Packers detected 1

Borland Delphi 3.0 (???)

Anti debug functions 6

GetLastError
IsDebuggerPresent
IsProcessorFeaturePresent
RaiseException
TerminateProcess
UnhandledExceptionFilter

Strings analysis - File found

Library
mscoree.dll
USER32.dll
WININET.dll
ClipperDLL.dll
KERNEL32.dll

Import functions

PE Exports 3 suspicious

Function Address
??4CClipperDLL@@QAEAAV0@$$QAV0@@Z 0x10001d60
??4CClipperDLL@@QAEAAV0@ABV0@@Z 0x10001d60
Main 0x10005b50
Name Latest seen MD5
clip.dll 2024-07-21 09:04:01 8cfd7419f24c7904d2a71b5ae6ea5daa
clip.dll 2024-07-29 00:11:01 7d257e3bb8441810561e09092162df73
clip64.dll 2024-08-28 07:06:02 babfda6375b07d76f6a46af11bdc3787
clip64.dll 2024-10-16 21:40:02 b7836f044f3f89eff107ee5d2342a9a2
clip.dll 2024-10-16 22:59:02 143a210c0ca4bd09985f12b588663ab4
clip.dll 2024-10-16 23:15:02 bd38b3834594180499a656b6cf3dfab0
clip64.dll 2024-10-16 23:16:03 b865aac4da61f8cc682d090819d12dd6