MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 074269c39cb4bdaf98e922f4581808ea49eb164822afd6fed695b1dd240648e2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RedLineStealer
Vendor detections: 18
| SHA256 hash: | 074269c39cb4bdaf98e922f4581808ea49eb164822afd6fed695b1dd240648e2 |
|---|---|
| SHA3-384 hash: | ff9e4c34d200db6c6fd9568b6613d4018983dee0aceeffdd551ab7ef74c9202a79238c7e5fdc260f2b2c38cb94a1b718 |
| SHA1 hash: | 90b41cbf092afe08206a88c46cbbd9559b3f8890 |
| MD5 hash: | 71f45273e91f293ed6b1f97665b13bf7 |
| humanhash: | stream-angel-happy-oregon |
| File name: | file |
| Download: | download sample |
| Signature | RedLineStealer |
| File size: | 554'816 bytes |
| First seen: | 2023-06-30 16:20:21 UTC |
| Last seen: | 2023-06-30 16:56:22 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 54223957b934118afc498e8a06f5b541 (5 x RedLineStealer, 3 x Amadey) |
| ssdeep | 12288:uo7Uku5hJ6UaS5MYBgAcF0VpT1fg0ebtFa5c70X5WAgQdQZ:uo7UZvdN5VGr0VpSTLa5c5Ao |
| Threatray | 2'546 similar samples on MalwareBazaar |
| TLSH | T1E7C4E05176C104A2C7622E32A5A485A39D79FCE05FA446533F3857264EF22D0BEF0DEA |
| TrID | 44.5% (.EXE) Win64 Executable (generic) (10523/12/4) 21.3% (.EXE) Win16 NE executable (generic) (5038/12/1) 8.5% (.EXE) OS/2 Executable (generic) (2029/13) 8.5% (.EXE) Clipper DOS Executable (2018/12) 8.4% (.EXE) Generic Win/DOS Executable (2002/3) |
| Reporter | |
| Tags: | exe RedLineStealer |
Intelligence
File Origin
USVendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
77.91.68.63/doma/net/index.php
Unpacked files
f08dbd5c068e1566324891efec0237d6b26489dee9ab030bd4e324d7a720a504
e7f393b15453061a5985bb104112fc942a9a8988b808481ab598353fb6c4e648
4059bcb9d4e8af4b9ff05142ea89eff281b2797355071c64bb3a7d670ca056f3
01aa99c5ba4a800a458d981aa3c4b6073824291ae788ea3dfeef2d41eb89964f
2b30661397e5f2ddca5993a075543d481cac944fac980a4a49ee93f502836e5a
34109fa97f85cd1f1138bcb0d2cb7b75c585858fae6849df3a7e577e8f38f09b
5431eb87b9ad7b89f4e967b42d40eb5d3ca92a13a27a0adb01949c301f28f47c
6fec8d77291bcd9bacfa3b5dc98c54f1bd2865e832a01e53268bb3a16424ef05
2c87d0a12ae4f136fa4bc4a7e78c33aa0fadfa4f54873a814dafcaff4e5f3ff1
4be6cfbccca9dcab0af1d1dad51f9d5e76274e3cc31f034198166b5c0edda751
453ef51c0af6f148746bb721095ef0ae875d07d077c8fc9c97dac993ba9f8ae0
c02bcd0a9954efc757843ed7cb05da07385ead554d57e140e712095fb6984361
c475ad88a8be90ba3e04a8918cc1a9380252e0781744e5c6412751dda1adc032
01df357140cab08154d7288fc1cde4829aee66ec02bcce8985506bf63961e024
d9d9c314c029b02087cd28124df3253c533532f122b3ede2f0a1d1a9a267425e
63ffebbe4a88dfcc781e6d38de5cbffc7fc8f938f9f230352f4f31a6c6eee1c4
8bb15fa045c03ba626b91f478aa0b7837f39a9aa038033ef91f0908b02e3907a
7e014c48883a5e5d1b2ec8ed24fc04fb7c1f15406ebc80ba5acea7ab263ecff3
4eefe15812a6806769912c731f734edab166fbfa94b9734551ce04e47dac5acf
0607901ab40d19311dd4db0ef9200597bb5523be82ac72c1ce0a6cef7484dd5a
5be6593f4824f92d9609894ca4b13bad83039b0ca6d56f20f44c45f2eb9c5ec5
bbd00039d177e33d3a4346167533dfa08644f03537327d13a8be851be3eb6e9f
074269c39cb4bdaf98e922f4581808ea49eb164822afd6fed695b1dd240648e2
b8e7d04229a437d1aabf41445a2e44d2908f46b0fda3041879e2d7b2c4e776c4
2aeab80d235649c691822260dc94d1cfa804881cf788206f7ba66e5f7de2eebc
f08dbd5c068e1566324891efec0237d6b26489dee9ab030bd4e324d7a720a504
e7f393b15453061a5985bb104112fc942a9a8988b808481ab598353fb6c4e648
4059bcb9d4e8af4b9ff05142ea89eff281b2797355071c64bb3a7d670ca056f3
01aa99c5ba4a800a458d981aa3c4b6073824291ae788ea3dfeef2d41eb89964f
2b30661397e5f2ddca5993a075543d481cac944fac980a4a49ee93f502836e5a
34109fa97f85cd1f1138bcb0d2cb7b75c585858fae6849df3a7e577e8f38f09b
5431eb87b9ad7b89f4e967b42d40eb5d3ca92a13a27a0adb01949c301f28f47c
6fec8d77291bcd9bacfa3b5dc98c54f1bd2865e832a01e53268bb3a16424ef05
2c87d0a12ae4f136fa4bc4a7e78c33aa0fadfa4f54873a814dafcaff4e5f3ff1
4be6cfbccca9dcab0af1d1dad51f9d5e76274e3cc31f034198166b5c0edda751
453ef51c0af6f148746bb721095ef0ae875d07d077c8fc9c97dac993ba9f8ae0
c02bcd0a9954efc757843ed7cb05da07385ead554d57e140e712095fb6984361
c475ad88a8be90ba3e04a8918cc1a9380252e0781744e5c6412751dda1adc032
01df357140cab08154d7288fc1cde4829aee66ec02bcce8985506bf63961e024
d9d9c314c029b02087cd28124df3253c533532f122b3ede2f0a1d1a9a267425e
63ffebbe4a88dfcc781e6d38de5cbffc7fc8f938f9f230352f4f31a6c6eee1c4
8bb15fa045c03ba626b91f478aa0b7837f39a9aa038033ef91f0908b02e3907a
7e014c48883a5e5d1b2ec8ed24fc04fb7c1f15406ebc80ba5acea7ab263ecff3
4eefe15812a6806769912c731f734edab166fbfa94b9734551ce04e47dac5acf
0607901ab40d19311dd4db0ef9200597bb5523be82ac72c1ce0a6cef7484dd5a
5be6593f4824f92d9609894ca4b13bad83039b0ca6d56f20f44c45f2eb9c5ec5
bbd00039d177e33d3a4346167533dfa08644f03537327d13a8be851be3eb6e9f
074269c39cb4bdaf98e922f4581808ea49eb164822afd6fed695b1dd240648e2
b8e7d04229a437d1aabf41445a2e44d2908f46b0fda3041879e2d7b2c4e776c4
2aeab80d235649c691822260dc94d1cfa804881cf788206f7ba66e5f7de2eebc
f08dbd5c068e1566324891efec0237d6b26489dee9ab030bd4e324d7a720a504
e7f393b15453061a5985bb104112fc942a9a8988b808481ab598353fb6c4e648
4059bcb9d4e8af4b9ff05142ea89eff281b2797355071c64bb3a7d670ca056f3
01aa99c5ba4a800a458d981aa3c4b6073824291ae788ea3dfeef2d41eb89964f
2b30661397e5f2ddca5993a075543d481cac944fac980a4a49ee93f502836e5a
34109fa97f85cd1f1138bcb0d2cb7b75c585858fae6849df3a7e577e8f38f09b
5431eb87b9ad7b89f4e967b42d40eb5d3ca92a13a27a0adb01949c301f28f47c
6fec8d77291bcd9bacfa3b5dc98c54f1bd2865e832a01e53268bb3a16424ef05
2c87d0a12ae4f136fa4bc4a7e78c33aa0fadfa4f54873a814dafcaff4e5f3ff1
4be6cfbccca9dcab0af1d1dad51f9d5e76274e3cc31f034198166b5c0edda751
453ef51c0af6f148746bb721095ef0ae875d07d077c8fc9c97dac993ba9f8ae0
c02bcd0a9954efc757843ed7cb05da07385ead554d57e140e712095fb6984361
c475ad88a8be90ba3e04a8918cc1a9380252e0781744e5c6412751dda1adc032
01df357140cab08154d7288fc1cde4829aee66ec02bcce8985506bf63961e024
d9d9c314c029b02087cd28124df3253c533532f122b3ede2f0a1d1a9a267425e
63ffebbe4a88dfcc781e6d38de5cbffc7fc8f938f9f230352f4f31a6c6eee1c4
8bb15fa045c03ba626b91f478aa0b7837f39a9aa038033ef91f0908b02e3907a
7e014c48883a5e5d1b2ec8ed24fc04fb7c1f15406ebc80ba5acea7ab263ecff3
4eefe15812a6806769912c731f734edab166fbfa94b9734551ce04e47dac5acf
0607901ab40d19311dd4db0ef9200597bb5523be82ac72c1ce0a6cef7484dd5a
5be6593f4824f92d9609894ca4b13bad83039b0ca6d56f20f44c45f2eb9c5ec5
bbd00039d177e33d3a4346167533dfa08644f03537327d13a8be851be3eb6e9f
074269c39cb4bdaf98e922f4581808ea49eb164822afd6fed695b1dd240648e2
b8e7d04229a437d1aabf41445a2e44d2908f46b0fda3041879e2d7b2c4e776c4
2aeab80d235649c691822260dc94d1cfa804881cf788206f7ba66e5f7de2eebc
f08dbd5c068e1566324891efec0237d6b26489dee9ab030bd4e324d7a720a504
e7f393b15453061a5985bb104112fc942a9a8988b808481ab598353fb6c4e648
4059bcb9d4e8af4b9ff05142ea89eff281b2797355071c64bb3a7d670ca056f3
01aa99c5ba4a800a458d981aa3c4b6073824291ae788ea3dfeef2d41eb89964f
2b30661397e5f2ddca5993a075543d481cac944fac980a4a49ee93f502836e5a
34109fa97f85cd1f1138bcb0d2cb7b75c585858fae6849df3a7e577e8f38f09b
5431eb87b9ad7b89f4e967b42d40eb5d3ca92a13a27a0adb01949c301f28f47c
6fec8d77291bcd9bacfa3b5dc98c54f1bd2865e832a01e53268bb3a16424ef05
2c87d0a12ae4f136fa4bc4a7e78c33aa0fadfa4f54873a814dafcaff4e5f3ff1
4be6cfbccca9dcab0af1d1dad51f9d5e76274e3cc31f034198166b5c0edda751
453ef51c0af6f148746bb721095ef0ae875d07d077c8fc9c97dac993ba9f8ae0
c02bcd0a9954efc757843ed7cb05da07385ead554d57e140e712095fb6984361
c475ad88a8be90ba3e04a8918cc1a9380252e0781744e5c6412751dda1adc032
01df357140cab08154d7288fc1cde4829aee66ec02bcce8985506bf63961e024
d9d9c314c029b02087cd28124df3253c533532f122b3ede2f0a1d1a9a267425e
63ffebbe4a88dfcc781e6d38de5cbffc7fc8f938f9f230352f4f31a6c6eee1c4
8bb15fa045c03ba626b91f478aa0b7837f39a9aa038033ef91f0908b02e3907a
7e014c48883a5e5d1b2ec8ed24fc04fb7c1f15406ebc80ba5acea7ab263ecff3
4eefe15812a6806769912c731f734edab166fbfa94b9734551ce04e47dac5acf
0607901ab40d19311dd4db0ef9200597bb5523be82ac72c1ce0a6cef7484dd5a
5be6593f4824f92d9609894ca4b13bad83039b0ca6d56f20f44c45f2eb9c5ec5
bbd00039d177e33d3a4346167533dfa08644f03537327d13a8be851be3eb6e9f
074269c39cb4bdaf98e922f4581808ea49eb164822afd6fed695b1dd240648e2
b8e7d04229a437d1aabf41445a2e44d2908f46b0fda3041879e2d7b2c4e776c4
2aeab80d235649c691822260dc94d1cfa804881cf788206f7ba66e5f7de2eebc
f08dbd5c068e1566324891efec0237d6b26489dee9ab030bd4e324d7a720a504
e7f393b15453061a5985bb104112fc942a9a8988b808481ab598353fb6c4e648
4059bcb9d4e8af4b9ff05142ea89eff281b2797355071c64bb3a7d670ca056f3
01aa99c5ba4a800a458d981aa3c4b6073824291ae788ea3dfeef2d41eb89964f
2b30661397e5f2ddca5993a075543d481cac944fac980a4a49ee93f502836e5a
34109fa97f85cd1f1138bcb0d2cb7b75c585858fae6849df3a7e577e8f38f09b
5431eb87b9ad7b89f4e967b42d40eb5d3ca92a13a27a0adb01949c301f28f47c
6fec8d77291bcd9bacfa3b5dc98c54f1bd2865e832a01e53268bb3a16424ef05
2c87d0a12ae4f136fa4bc4a7e78c33aa0fadfa4f54873a814dafcaff4e5f3ff1
4be6cfbccca9dcab0af1d1dad51f9d5e76274e3cc31f034198166b5c0edda751
453ef51c0af6f148746bb721095ef0ae875d07d077c8fc9c97dac993ba9f8ae0
c02bcd0a9954efc757843ed7cb05da07385ead554d57e140e712095fb6984361
c475ad88a8be90ba3e04a8918cc1a9380252e0781744e5c6412751dda1adc032
01df357140cab08154d7288fc1cde4829aee66ec02bcce8985506bf63961e024
d9d9c314c029b02087cd28124df3253c533532f122b3ede2f0a1d1a9a267425e
63ffebbe4a88dfcc781e6d38de5cbffc7fc8f938f9f230352f4f31a6c6eee1c4
8bb15fa045c03ba626b91f478aa0b7837f39a9aa038033ef91f0908b02e3907a
7e014c48883a5e5d1b2ec8ed24fc04fb7c1f15406ebc80ba5acea7ab263ecff3
4eefe15812a6806769912c731f734edab166fbfa94b9734551ce04e47dac5acf
0607901ab40d19311dd4db0ef9200597bb5523be82ac72c1ce0a6cef7484dd5a
5be6593f4824f92d9609894ca4b13bad83039b0ca6d56f20f44c45f2eb9c5ec5
bbd00039d177e33d3a4346167533dfa08644f03537327d13a8be851be3eb6e9f
074269c39cb4bdaf98e922f4581808ea49eb164822afd6fed695b1dd240648e2
b8e7d04229a437d1aabf41445a2e44d2908f46b0fda3041879e2d7b2c4e776c4
2aeab80d235649c691822260dc94d1cfa804881cf788206f7ba66e5f7de2eebc
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | cobalt_strike_tmp01925d3f |
|---|---|
| Author: | The DFIR Report |
| Description: | files - file ~tmp01925d3f.exe |
| Reference: | https://thedfirreport.com |
| Rule name: | detect_Redline_Stealer |
|---|---|
| Author: | Varp0s |
| Rule name: | INDICATOR_EXE_Packed_ConfuserEx |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables packed with ConfuserEx Mod |
| Rule name: | MALWARE_Win_RedLine |
|---|---|
| Author: | ditekSHen |
| Description: | Detects RedLine infostealer |
| Rule name: | PE_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | pe_imphash |
|---|
| Rule name: | PE_Potentially_Signed_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | redline_stealer_1 |
|---|---|
| Author: | Nikolaos 'n0t' Totosis |
| Description: | RedLine Stealer Payload |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.