MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0d171af287469dcb4d710c5ad03a6f042098e501106199ae016bedfa5ef50dcd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RedLineStealer
Vendor detections: 16
| SHA256 hash: | 0d171af287469dcb4d710c5ad03a6f042098e501106199ae016bedfa5ef50dcd |
|---|---|
| SHA3-384 hash: | 558e54efe6d0b8e0c10a9e7da31b1beeb8b31f72194d2e67ba6c4189a1847f57d32dd1c2bffeb239e76411243bc809e8 |
| SHA1 hash: | 36b653555a792d8a23edd3fd50fcbce19bee10f0 |
| MD5 hash: | 60e2e910dcf0bf3ec511a6a8a96517c5 |
| humanhash: | ink-venus-bravo-black |
| File name: | 60e2e910dcf0bf3ec511a6a8a96517c5.exe |
| Download: | download sample |
| Signature | RedLineStealer |
| File size: | 269'592 bytes |
| First seen: | 2023-06-17 18:20:30 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 8b20c0aa1a6b70c064e1b0a2222ddac4 (17 x RedLineStealer, 8 x Healer, 1 x Spambot.Kelihos) |
| ssdeep | 3072:qpmbUZsF++CnDLAypR0Hgm6SeqsRoAmgzmkm0GxpSHyQrpbRutnlz18Ft0x:Ug+pn9Seqs7mgzmkm0G+pr3uZlzG |
| TLSH | T160443A1231E0BD24D405487FB479469BB6AE68DFF7D8C4FA152421DB2A172892F3D33A |
| TrID | 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 15.9% (.EXE) Win64 Executable (generic) (10523/12/4) 9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 7.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 6.8% (.EXE) Win32 Executable (generic) (4505/5/1) |
| Reporter | |
| Tags: | exe RedLineStealer |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
b5a399ddb6c2ba1ee189578a55c71d2e25ce0f128eda1579b9a30502adb2dbad
7f1938beed0d0e4058ece6afdb6203be598a1929cc154be0b11c51fb24c41536
c755dfe3e64ad8fb363401365cc6597a53f66293f0aee0f82ac9405b02a674e0
fe07da6735b39c3c27f0f3b6d79dcc252ed160fb15bb408df1d85543e041c1c1
a84a517102d26a77dd41d9bbe73fc2f30221b5e841b5997831d30f4c973bcb6a
087c532422bfb865eed6ffdaad1c5af374c4c35a2e3866e23d54f4a21524c405
ff334dc8e2d590d41d79dc0e75f12b5a9c818ffc8191c392046bf2bcc2da7e44
2059a50fbc47b60810eb532179fe9cc5132474e7f64bd7daa24147d53a4383e9
d9e279d1691b3e893392143aa4ef65acc37d473e1fc84d7fdbdcabe887405782
8af68d964529e9dfec9d6b2735f0f1b9664e75097569170b376cbd7da1b6dbf8
de2f4cf128b90a83b3e44bd5fad4aeb8d5068b564dfe7d90e6a5db950f6b3c36
5b6eeff5e160f538a569232ed92cd3e5fb3172cac5a4b5bd5e89bf0b5b359f21
4e4eed16b3a6b4c9f1168745b8268765a9b7a0b5c557cc7e2975c24940eed32d
6173dc53f3ee8fac2a364496d428673f009d13b966b3471624809b5e91d39bb1
0d171af287469dcb4d710c5ad03a6f042098e501106199ae016bedfa5ef50dcd
68a95ec42a5c30c3a792d344bb54a3ca7e0c628234d5d9cd21ffe7237dc772aa
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_EXE_Packed_ConfuserEx |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables packed with ConfuserEx Mod |
| Rule name: | MALWARE_Win_RedLine |
|---|---|
| Author: | ditekSHen |
| Description: | Detects RedLine infostealer |
| Rule name: | PE_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | pe_imphash |
|---|
| Rule name: | PE_Potentially_Signed_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | redline_stealer_1 |
|---|---|
| Author: | Nikolaos 'n0t' Totosis |
| Description: | RedLine Stealer Payload |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.