cred64.dll
First submission 2024-10-16 20:45:03
File details
File type: | PE32+ executable (DLL) (GUI) x86-64, for MS Windows |
Mime type: | application/x-dosexec |
File size: | 1255.0 KB (1285120 bytes) |
Compile time: | 2024-09-03 21:59:30 |
MD5: | d936bcd060924a3ea77c08a9fe550990 |
SHA1: | a3a9c67d106f77a20421b7a17efd0be074559c02 |
SHA256: | efadeacca8afa370fce709a27632f7d9a7d684cb55840024421f740494d69633 |
Import Hash : | 3eb70f83441fc8632e81bd6eb89f424d |
Sections 7 | .text .rdata .data .pdata _RDATA .rsrc .reloc |
Directories 5 | import export resource debug relocation |
File features detected
Anti VM
Signed
XOR
OSINT Enrichments
Virus Total: | 53/77 VT report date: 2024-09-11 17:28:54 |
Malware Type 1 | trojan |
Threat Type 3 | zusy convagent stealer |
URLs, FQDN and IP indicators 1
PE Sections 0 suspicious
Name | VAddress | VSize | Size | SHA1 | MD5 | Suspicious |
---|---|---|---|---|---|---|
.text | 0x1000 | 0xfbaa8 | 1031168 | 4c86f839c3605d22816cb11a433b3debd7bb7fa0 | f7e3936c1d5c3876c3846ba667f8ad66 | |
.rdata | 0xfd000 | 0x2ce82 | 184320 | c10276732c16b7d1cab17d97e278a7ec98308a08 | 7b0a41da3a8f8b6f99b2aeb120fee706 | |
.data | 0x12a000 | 0xbbac | 17408 | a78813eb452a3ea2733051f72437b458f0703625 | eab9f520f4edf8588a5524e594081081 | |
.pdata | 0x136000 | 0xad70 | 44544 | 21225e390cbfbc5e0c05a9f9998082b47836f31f | 5bd39d890756751db792ba8782af79ce | |
_RDATA | 0x141000 | 0x94 | 512 | f614a0b55af015a86a724f9a265c569786aed260 | 830a5ca5b68ce0d267a64e5736f6792f | |
.rsrc | 0x142000 | 0xf8 | 512 | 6f2aee814106277dae3a8e6b3254dde0bfde7fc7 | 193fc41b7ab2ce83170d116dba1ce3ac | |
.reloc | 0x143000 | 0x15f4 | 5632 | 504479f5c87d1ebd3d14936d8dcdcff6fc54d6d1 | 501292eff00701982bb1989dbf91a69f |
PE Resources 1
Name | Language | Sublanguage | Offset | Size | Data |
---|---|---|---|---|---|
RT_MANIFEST | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0x142060 | 145 |
Anti debug functions 10
GetLastError |
IsDebuggerPresent |
IsProcessorFeaturePresent |
OutputDebugStringA |
OutputDebugStringW |
Process32FirstW |
Process32NextW |
RaiseException |
TerminateProcess |
UnhandledExceptionFilter |
Strings analysis - File found
XML |
FileZilla\sitemanager.xml |
Psi\profiles\default\accounts.xml |
\.purple\accounts.xml |
.purple\accounts.xml |
Library |
mscoree.dll |
KERNEL32.dll |
bcrypt.dll |
ADVAPI32.dll |
WININET.dll |
SHELL32.dll |
Crypt32.dll |
STEALERDLL.dll |
nss3.dll |
Strings analysis - Possible IPs found 1
3.8.7.4 |
Import functions
PE Exports 2 suspicious
Function | Address |
---|---|
Main | 0x1800c0c40 |
Save | 0x180005d80 |
Name | Latest seen | MD5 |
---|---|---|
cred64.dll | 2024-07-15 20:36:02 | b9bccd35addce48384491a98e1b89eb5 |
cred64.dll | 2024-07-29 00:14:02 | d4944b1c2a2636220b189ab9b8dbbc00 |
cred64.dll | 2024-08-28 07:05:02 | 4a4527a3ecf33ac8dc86e12681abf97b |
cred64.dll | 2024-10-16 20:46:04 | 9bafe5c5cfe47a1ed2e15f2748986d92 |
cred64.dll | 2024-10-16 20:47:03 | 1b32cdb682dc2b89bab7263aa4f1f08b |
cred64.dll | 2024-10-16 20:48:02 | 304e7afdf32dbcbdce75b6366103abcb |
cred64.dll | 2024-10-16 20:49:04 | 86d2400fe6cf41987dc3d7431cbc1279 |