sqlite3.dll

First submission 2023-06-25 09:17:02 Last sumbission 2023-09-25 17:41:03

File details

File type: PE32 executable (DLL) (console) Intel 80386, for MS Windows
Mime type: application/x-dosexec
File size: 1073.46 KB (1099223 bytes)
Compile time: 2022-03-12 15:07:30
MD5: dbf4f8dcefb8056dc6bae4b67ff810ce
SHA1: bbac1dd8a07c6069415c04b62747d794736d0689
SHA256: 47b64311719000fa8c432165a0fdcdfed735d5b54977b052de915b1cbbbf9d68
Import Hash : e727d00364cd87d72f56e7ba919d1d40
Sections 18 .text .data .rdata .bss .edata .idata .CRT .tls .rsrc .reloc /4 /19 /31 /45 /57 /70 /81 /92
Directories 5 import export resource tls relocation
Virus Total: 0/70 VT report date: 2023-06-24 22:01:26

File features detected

Is DLL

Packers

Anti Debug

Anti VM

Signed

XOR

URLs, FQDN and IP indicators 1

URL Host (FQDN/IP) Date Added
hXXp://65.109.2.42/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll VirusTotal Report 65.109.2.42 VirusTotal Report 2023-09-25 17:41:05

PE Sections 3 suspicious

Name VAddress VSize Size SHA1 MD5 Suspicious
.text 0x1000 0xb0aac 723968 668dacf9b2238fed3fdfb97f67c50e0afbe5ea11 1cbf4009d5554d48748fe996f7b2abed
.data 0xb2000 0x277c 10240 e73c42837fe5fe1daf9b09e81885f46cedc64983 ebce072aec3912946cc8aef4060f2ddb
.rdata 0xb5000 0x14410 83456 d958774e298a94324930826183f052c006f55cd0 4a03cf5597b9ed410409c3939c5ba9c5
.bss 0xca000 0x828 0 da39a3ee5e6b4b0d3255bfef95601890afd80709 d41d8cd98f00b204e9800998ecf8427e
.edata 0xcb000 0x2a6e 11264 fd41a5b6d4b1bc8abb7190c9403187d83d744f8c e9c6286841bdc6b54f498df7d254c782
.idata 0xce000 0xcd0 3584 5ad7c5617f38b81b3c0446ed464e38b9d6e28137 9381c2986139e34617c4100bc4d2a962
.CRT 0xcf000 0x2c 512 9e8937e3b944bd0e140daf94e1ef20ffd63902ea 0193ef3a0dedffbedf1c1f5b4dd3dd1a
.tls 0xd0000 0x20 512 8149c1f8b6083f0d3fcac28b88c09eae2fb29640 bd9b70beb768e1b7aa58c6ff99c198bc
.rsrc 0xd1000 0x4a8 1536 602a256a0d369799553bf3bebef87e5b7899ffc0 74d039ea689aa073733f005bd5c9d129
.reloc 0xd2000 0x3be0 15360 48252c96fc1561f5e86783d1590e99f863ea707f 9ce00fcfd13a6d7d89e7f98bc0a1961b
/4 0xd6000 0x538 1536 3f0e70dafafa4c48893261024d1f33376099fcf0 075d1e908510a024f1804c77fd67a028
/19 0xd7000 0xc852 51712 47ae9425191dd357224b8d83678a1de5d302ee23 d783f819bf4ada9fc3135ef9a358d461
/31 0xe4000 0x275d 10240 98f7715c89a0fe456fbf641bcc6a308eba9ea474 2acd32ceee2eabb1b41b2156475cf2bf
/45 0xe7000 0x2d9a 11776 4b33245881325a6c758f27473c9dc35f6b55baa0 609e55ba5003accbee3f7de7fecd058c
/57 0xea000 0xb5c 3072 3d4bf8542f5e56a6705f202c5d7e9543dcc998dc 3b0d1b8ef15b4b49fd9afc2fde7930e2
/70 0xeb000 0x323 1024 125f0a4686f4ab36a2e70b3eeedc1ee28b38945a 2030959f875392ef618b84f7bea8535a
/81 0xec000 0x3a73 15360 3f943da0688991f4696890e8225d3e1c47ab27c6 abe8969bcdcceab5a1af9c0c3bbff1c8
/92 0xf0000 0x350 1024 015d30ce044b653cbb6c72868a9c10ab95539c85 12f4aae57e6ac90fc06369b130799fcf

PE Resources 1

Name Language Sublanguage Offset Size Data
RT_VERSION LANG_ENGLISH SUBLANG_ENGLISH_US 0xd1058 1104

Meta infos 9

LegalCopyright: http://www.sqlite.org/copyright.html
InternalName: sqlite3
FileVersion: 3.38.1
CompanyName: SQLite Development Team
SourceId: 2022-03-12 13:37:29 38c210fdd258658321c85ec9c01a072fda3ada94540e3239d29b34dc547a8cbc
ProductVersion: 3.38.1
FileDescription: SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.
Translation: 0x0409 0x04b0
ProductName: SQLite

Anti debug functions 5

GetLastError
OutputDebugStringA
OutputDebugStringW
TerminateProcess
UnhandledExceptionFilter

Anti debug functions 1

VMCheck.dll

Strings analysis - File found

Library
libgcj-16.dll
MSVCRT.dll
KERNEL32.dll
SQLite3.dll

Strings analysis - Possible URLs found 1

http://www.sqlite.org/copyright.html

Import functions

PE Exports 339 suspicious

Function Address
sqlite3_aggregate_context 0x61e1d413
sqlite3_aggregate_count 0x61e03793
sqlite3_auto_extension 0x61eab5eb
sqlite3_autovacuum_pages 0x61e05c5f
sqlite3_backup_finish 0x61e5512b
sqlite3_backup_init 0x61e54b93
sqlite3_backup_pagecount 0x61e03357
sqlite3_backup_remaining 0x61e0334c
sqlite3_backup_step 0x61e52af4
sqlite3_bind_blob 0x61e2d82e
sqlite3_bind_blob64 0x61e2d85d
sqlite3_bind_double 0x61e2d534
sqlite3_bind_int 0x61e2d5d4
sqlite3_bind_int64 0x61e2d585
sqlite3_bind_null 0x61e2d5fa
sqlite3_bind_parameter_count 0x61e037d4
sqlite3_bind_parameter_index 0x61e1566c
sqlite3_bind_parameter_name 0x61e037e6
sqlite3_bind_pointer 0x61e2d62b
sqlite3_bind_text 0x61e2d88c
sqlite3_bind_text16 0x61e2d8f7
sqlite3_bind_text64 0x61e2d8bb
sqlite3_bind_value 0x61e2d926
sqlite3_bind_zeroblob 0x61e2d6b3
sqlite3_bind_zeroblob64 0x61e2d6f7
sqlite3_blob_bytes 0x61e038b6
sqlite3_blob_close 0x61e5623c
sqlite3_blob_open 0x61e96542
sqlite3_blob_read 0x61e57e29
sqlite3_blob_reopen 0x61e96cdc
sqlite3_blob_write 0x61e58b8b
sqlite3_busy_handler 0x61e059e0
sqlite3_busy_timeout 0x61e0e511
sqlite3_cancel_auto_extension 0x61e045a3
sqlite3_changes 0x61e05894
sqlite3_changes64 0x61e05886
sqlite3_clear_bindings 0x61e0b27f
sqlite3_close 0x61e55322
sqlite3_close_v2 0x61e55330
sqlite3_collation_needed 0x61e05d4f
sqlite3_collation_needed16 0x61e05d93
sqlite3_column_blob 0x61e1f67c
sqlite3_column_bytes 0x61e1f4a3
sqlite3_column_bytes16 0x61e1f4e0
sqlite3_column_count 0x61e037a1
sqlite3_column_database_name 0x61e1fba5
sqlite3_column_database_name16 0x61e1fbbd
sqlite3_column_decltype 0x61e1fb72
sqlite3_column_decltype16 0x61e1fb8a
sqlite3_column_double 0x61e2e3e5
sqlite3_column_int 0x61e116a1
sqlite3_column_int64 0x61e116cd
sqlite3_column_name 0x61e1fb3f
sqlite3_column_name16 0x61e1fb57
sqlite3_column_origin_name 0x61e1fc0b
sqlite3_column_origin_name16 0x61e1fc23
sqlite3_column_table_name 0x61e1fbd8
sqlite3_column_table_name16 0x61e1fbf0
sqlite3_column_text 0x61e1f6a8
sqlite3_column_text16 0x61e1fc3e
sqlite3_column_type 0x61e11771
sqlite3_column_value 0x61e116f6
sqlite3_commit_hook 0x61e05b99
sqlite3_compileoption_get 0x61e05e99
sqlite3_compileoption_used 0x61e09a63
sqlite3_complete 0x61e05560
sqlite3_complete16 0x61eab791
sqlite3_config 0x61e34cc0
sqlite3_context_db_handle 0x61e03730
sqlite3_create_collation 0x61e2d0c7
sqlite3_create_collation16 0x61e2d0fe
sqlite3_create_collation_v2 0x61e2d070
sqlite3_create_filename 0x61e39c52
sqlite3_create_function 0x61e2cbb5
sqlite3_create_function16 0x61e2ce8a
sqlite3_create_function_v2 0x61e2cdff
sqlite3_create_module 0x61e2385f
sqlite3_create_module_v2 0x61e2396b
sqlite3_create_window_function 0x61e2ce45
sqlite3_data_count 0x61e037b6
sqlite3_data_directory 0x61eca020
sqlite3_database_file_object 0x61e029ff
sqlite3_db_cacheflush 0x61e5244e
sqlite3_db_config 0x61e143f3
sqlite3_db_filename 0x61e13626
sqlite3_db_handle 0x61e03803
sqlite3_db_mutex 0x61e057ff
sqlite3_db_readonly 0x61e05e77
sqlite3_db_release_memory 0x61e15277
sqlite3_db_status 0x61e16d68
sqlite3_declare_vtab 0x61e895ef
sqlite3_deserialize 0x61e8c3f4
sqlite3_drop_modules 0x61e23989
sqlite3_enable_load_extension 0x61e34c7a
sqlite3_enable_shared_cache 0x61e02c9c
sqlite3_errcode 0x61e2d285
sqlite3_errmsg 0x61e2d2f8
sqlite3_errmsg16 0x61e2d37b
sqlite3_error_offset 0x61e2d23e
sqlite3_errstr 0x61e0e508
sqlite3_exec 0x61e737c4
sqlite3_expanded_sql 0x61e1f2f0
sqlite3_expired 0x61e0369a
sqlite3_extended_errcode 0x61e2d2c0
sqlite3_extended_result_codes 0x61e05de8
sqlite3_file_control 0x61e15e0c
sqlite3_filename_database 0x61e05e3f
sqlite3_filename_journal 0x61e09a08
sqlite3_filename_wal 0x61e09a41
sqlite3_finalize 0x61e5614b
sqlite3_free 0x61e0ac4a
sqlite3_free_filename 0x61e0b681
sqlite3_free_table 0x61e0b634
sqlite3_get_autocommit 0x61e05dd7
sqlite3_get_auxdata 0x61e03758
sqlite3_get_table 0x61e8bc08
sqlite3_global_recover 0x61eabe45
sqlite3_hard_heap_limit64 0x61e35725
sqlite3_initialize 0x61e34ec1
sqlite3_interrupt 0x61e08768
sqlite3_keyword_check 0x61e131f7
sqlite3_keyword_count 0x61e05056
sqlite3_keyword_name 0x61e05021
sqlite3_last_insert_rowid 0x61e05843
sqlite3_libversion 0x61e057e1
sqlite3_libversion_number 0x61e057eb
sqlite3_limit 0x61e05d0a
sqlite3_load_extension 0x61e44a05
sqlite3_log 0x61e2a45a
sqlite3_malloc 0x61e357b3
sqlite3_malloc64 0x61e36866
sqlite3_memory_alarm 0x61e332fd
sqlite3_memory_highwater 0x61e2c7b9
sqlite3_memory_used 0x61e2c789
sqlite3_mprintf 0x61e42cb9
sqlite3_msize 0x61e017b6
sqlite3_mutex_alloc 0x61e3542a
sqlite3_mutex_enter 0x61e01759
sqlite3_mutex_free 0x61e01746
sqlite3_mutex_leave 0x61e01781
sqlite3_mutex_try 0x61e0176c
sqlite3_next_stmt 0x61e03869
sqlite3_open 0x61eabd30
sqlite3_open16 0x61eabd63
sqlite3_open_v2 0x61eabd4b
sqlite3_os_end 0x61e34aa0
sqlite3_os_init 0x61e35363
sqlite3_overload_function 0x61e46465
sqlite3_prepare 0x61e83448
sqlite3_prepare16 0x61e86af6
sqlite3_prepare16_v2 0x61e86b1d
sqlite3_prepare16_v3 0x61e86b44
sqlite3_prepare_v2 0x61e85e9f
sqlite3_prepare_v3 0x61e863d0
sqlite3_preupdate_blobwrite 0x61e34af1
sqlite3_preupdate_count 0x61e34ab1
sqlite3_preupdate_depth 0x61e34acf
sqlite3_preupdate_hook 0x61eabe03
sqlite3_preupdate_new 0x61e34b09
sqlite3_preupdate_old 0x61e500dc
sqlite3_profile 0x61e05b45
sqlite3_progress_handler 0x61e05a2e
sqlite3_randomness 0x61e486cd
sqlite3_realloc 0x61e39f48
sqlite3_realloc64 0x61e3b3c4
sqlite3_release_memory 0x61e0179e
sqlite3_reset 0x61e58c26
sqlite3_reset_auto_extension 0x61eab67d
sqlite3_result_blob 0x61e20a0c
sqlite3_result_blob64 0x61e2126b
sqlite3_result_double 0x61e13698
sqlite3_result_error 0x61e1e736
sqlite3_result_error16 0x61e1ea65
sqlite3_result_error_code 0x61e1ea9e
sqlite3_result_error_nomem 0x61e20917
sqlite3_result_error_toobig 0x61e1eb34
sqlite3_result_int 0x61e0b179
sqlite3_result_int64 0x61e0b1ad
sqlite3_result_null 0x61e0b20c
sqlite3_result_pointer 0x61e13800
sqlite3_result_subtype 0x61e0370c
sqlite3_result_text 0x61e20a28
sqlite3_result_text16 0x61e21265
sqlite3_result_text16be 0x61e21227
sqlite3_result_text16le 0x61e21246
sqlite3_result_text64 0x61e212bf
sqlite3_result_value 0x61e1e24c
sqlite3_result_zeroblob 0x61e0b325
sqlite3_result_zeroblob64 0x61e0b333
sqlite3_rollback_hook 0x61e05c1d
sqlite3_rtree_geometry_callback 0x61eabe4c
sqlite3_rtree_query_callback 0x61eabeca
sqlite3_serialize 0x61e8c1eb
sqlite3_set_authorizer 0x61e03fbb
sqlite3_set_auxdata 0x61e1a93f
sqlite3_set_last_insert_rowid 0x61e05851
sqlite3_shutdown 0x61eab6d0
sqlite3_sleep 0x61e352c9
sqlite3_snprintf 0x61e2a14a
sqlite3_soft_heap_limit 0x61e35701
sqlite3_soft_heap_limit64 0x61e3562c
sqlite3_sourceid 0x61e0875e
sqlite3_sql 0x61e038a2
sqlite3_status 0x61e2c731
sqlite3_status64 0x61e2c6a1
sqlite3_step 0x61e7300c
sqlite3_stmt_busy 0x61e0384a
sqlite3_stmt_isexplain 0x61e03830
sqlite3_stmt_readonly 0x61e03813
sqlite3_stmt_status 0x61e11554
sqlite3_str_append 0x61e1d065
sqlite3_str_appendall 0x61e1d09a
sqlite3_str_appendchar 0x61e1d20b
sqlite3_str_appendf 0x61e1a3b9
sqlite3_str_errcode 0x61e017f3
sqlite3_str_finish 0x61e1a6eb
sqlite3_str_length 0x61e01808
sqlite3_str_new 0x61e3688c
sqlite3_str_reset 0x61e0ad39
sqlite3_str_value 0x61e01819
sqlite3_str_vappendf 0x61e18f3e
sqlite3_strglob 0x61e0a826
sqlite3_stricmp 0x61e01998
sqlite3_strlike 0x61e0a841
sqlite3_strnicmp 0x61e019be
sqlite3_system_errno 0x61e05cf9
sqlite3_table_column_metadata 0x61e8b63e
sqlite3_temp_directory 0x61eca024
sqlite3_test_control 0x61eaafe3
sqlite3_thread_cleanup 0x61e05de3
sqlite3_threadsafe 0x61e057f5
sqlite3_total_changes 0x61e058ad
sqlite3_total_changes64 0x61e0589f
sqlite3_trace 0x61e05a9c
sqlite3_trace_v2 0x61e05aed
sqlite3_transfer_bindings 0x61e12e1c
sqlite3_txn_state 0x61e058b8
sqlite3_update_hook 0x61e05bdb
sqlite3_uri_boolean 0x61e0997c
sqlite3_uri_int64 0x61e11dc4
sqlite3_uri_key 0x61e099af
sqlite3_uri_parameter 0x61e09921
sqlite3_user_data 0x61e03722
sqlite3_value_blob 0x61e1f57f
sqlite3_value_bytes 0x61e1f495
sqlite3_value_bytes16 0x61e1f4cf
sqlite3_value_double 0x61e18f32
sqlite3_value_dup 0x61e35a8c
sqlite3_value_free 0x61e0b386
sqlite3_value_frombind 0x61e036fa
sqlite3_value_int 0x61e0c8c4
sqlite3_value_int64 0x61e0c8d1
sqlite3_value_nochange 0x61e036e1
sqlite3_value_numeric_type 0x61e32c37
sqlite3_value_pointer 0x61e11c0e
sqlite3_value_subtype 0x61e036b7
sqlite3_value_text 0x61e1f546
sqlite3_value_text16 0x61e1fc6a
sqlite3_value_text16be 0x61e1fa97
sqlite3_value_text16le 0x61e1faa8
sqlite3_value_type 0x61e036cc
sqlite3_version 0x61ec8840
sqlite3_vfs_find 0x61e35266
sqlite3_vfs_register 0x61e35300
sqlite3_vfs_unregister 0x61e353ea
sqlite3_vmprintf 0x61e429ec
sqlite3_vsnprintf 0x61e2a0ee
sqlite3_vtab_collation 0x61e28a0d
sqlite3_vtab_config 0x61e2c7e8
sqlite3_vtab_distinct 0x61e04dae
sqlite3_vtab_in 0x61e04d70
sqlite3_vtab_in_first 0x61e50dbd
sqlite3_vtab_in_next 0x61e50dce
sqlite3_vtab_nochange 0x61e0373d
sqlite3_vtab_on_conflict 0x61e04949
sqlite3_vtab_rhs_value 0x61e2eefc
sqlite3_wal_autocheckpoint 0x61e0e560
sqlite3_wal_checkpoint 0x61e8bbbb
sqlite3_wal_checkpoint_v2 0x61e8bb77
sqlite3_wal_hook 0x61e05cb7
sqlite3_win32_is_nt 0x61e33481
sqlite3_win32_mbcs_to_utf8 0x61eab48c
sqlite3_win32_mbcs_to_utf8_v2 0x61eab4b5
sqlite3_win32_set_directory 0x61eab5e5
sqlite3_win32_set_directory16 0x61eab599
sqlite3_win32_set_directory8 0x61eab52a
sqlite3_win32_sleep 0x61e33366
sqlite3_win32_unicode_to_utf8 0x61eab46b
sqlite3_win32_utf8_to_mbcs 0x61eab4db
sqlite3_win32_utf8_to_mbcs_v2 0x61eab504
sqlite3_win32_utf8_to_unicode 0x61eab44a
sqlite3_win32_write_debug 0x61e33304
sqlite3changegroup_add 0x61ead883
sqlite3changegroup_add_strm 0x61ead8e5
sqlite3changegroup_delete 0x61ead94b
sqlite3changegroup_new 0x61eada9a
sqlite3changegroup_output 0x61ead8c9
sqlite3changegroup_output_strm 0x61ead92b
sqlite3changeset_apply 0x61ead776
sqlite3changeset_apply_strm 0x61ead835
sqlite3changeset_apply_v2 0x61ead709
sqlite3changeset_apply_v2_strm 0x61ead7c4
sqlite3changeset_concat 0x61eada1f
sqlite3changeset_concat_strm 0x61ead9a4
sqlite3changeset_conflict 0x61eaca08
sqlite3changeset_finalize 0x61eaca6b
sqlite3changeset_fk_conflicts 0x61eaca48
sqlite3changeset_invert 0x61ead674
sqlite3changeset_invert_strm 0x61ead6b3
sqlite3changeset_new 0x61e0f297
sqlite3changeset_next 0x61eac9a1
sqlite3changeset_old 0x61e0f25d
sqlite3changeset_op 0x61eac9b8
sqlite3changeset_pk 0x61eac9e8
sqlite3changeset_start 0x61eac8d9
sqlite3changeset_start_strm 0x61eac938
sqlite3changeset_start_v2 0x61eac90a
sqlite3changeset_start_v2_strm 0x61eac96d
sqlite3rebaser_configure 0x61eadaa3
sqlite3rebaser_create 0x61ead970
sqlite3rebaser_delete 0x61eadbc3
sqlite3rebaser_rebase 0x61eadaf3
sqlite3rebaser_rebase_strm 0x61eadb5a
sqlite3session_attach 0x61eac0d6
sqlite3session_changeset 0x61eac702
sqlite3session_changeset_size 0x61eac8cb
sqlite3session_changeset_strm 0x61eac72e
sqlite3session_config 0x61eadbe8
sqlite3session_create 0x61eabf5c
sqlite3session_delete 0x61eac028
sqlite3session_diff 0x61eac22a
sqlite3session_enable 0x61eac7c0
sqlite3session_indirect 0x61eac7fb
sqlite3session_isempty 0x61eac836
sqlite3session_memory_used 0x61eac881
sqlite3session_object_config 0x61eac88f
sqlite3session_patchset 0x61eac791
sqlite3session_patchset_strm 0x61eac75e
sqlite3session_table_filter 0x61eac0bb
Name Latest seen MD5
sqlite3.dll 2023-09-30 19:27:02 1f44d4d3087c2b202cf9c90ee9d04b0f