MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 19b2a5a72d27f8841152bca2694ce3d720dca29885a588443a375dec9c0a7b52. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RiseProStealer
Vendor detections: 14
| SHA256 hash: | 19b2a5a72d27f8841152bca2694ce3d720dca29885a588443a375dec9c0a7b52 |
|---|---|
| SHA3-384 hash: | 09925e064c8dbf0158949452853b9b9e421746d2fd4076753aa09f664a7d2cbeaab2eb5acb7f6c39824ecefe81e7daed |
| SHA1 hash: | 3bb5afdb9cc2aa069cd944192bd1740f939c0a03 |
| MD5 hash: | 70dacb108d23e83d818c5006da2eae9c |
| humanhash: | three-four-colorado-alaska |
| File name: | 70dacb108d23e83d818c5006da2eae9c.exe |
| Download: | download sample |
| Signature | RiseProStealer |
| File size: | 2'024'448 bytes |
| First seen: | 2023-11-29 05:30:36 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 646167cce332c1c252cdcb1839e0cf48 (8'473 x RedLineStealer, 4'851 x Amadey, 290 x Smoke Loader) |
| ssdeep | 49152:J42unm8qgWinFJdXSJY6d5Fv7T1/VYC23HzhyRsNm:u2um8qgWinyjvT23NyRim |
| Threatray | 670 similar samples on MalwareBazaar |
| TLSH | T150953303D7E9D031DBF5273058BB07E31E367C91FDB4536B2669E9894821AA458B232F |
| TrID | 41.1% (.CPL) Windows Control Panel Item (generic) (57583/11/19) 22.2% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 11.8% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5) 7.5% (.EXE) Win64 Executable (generic) (10523/12/4) 4.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) |
| File icon (PE): | |
| dhash icon | f8f0f4c8c8c8d8f0 (8'803 x RedLineStealer, 5'078 x Amadey, 288 x Smoke Loader) |
| Reporter | |
| Tags: | exe RiseProStealer |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
fd13cdd897c6f627ad8b02ef425687b81109a71eccd213a989744b15d70547e6
b2ce4969d9a32bb0825f61ae01a0b789f6fefab7cec1cd3eb155c2d098ac8b0b
8f682183913956c6d0414d2ee9165d9f31957934507b4fb010e1eafd29b3cf0e
19b2a5a72d27f8841152bca2694ce3d720dca29885a588443a375dec9c0a7b52
e72b8d48554951d7c19ac727e4718ed0f7e72e095f47cfc9cf8669dc6dcff3ad
80521b1682d5e13e9bbeeadfd585ad3bf51bcf6164d378fce34a512056f4fa3f
914fb27e6fcc06d274cb0803c948b798f24a89133b07089c4c5d1c5d1330a492
cc6a9c67aab8b828de9342bf348f131b8d255a5d3a88bfd439c76717867a58ba
428d3eac1d6720cca1a2461153b8e39b5ac10340f458c1c5ae93d2c85cebc054
fd13cdd897c6f627ad8b02ef425687b81109a71eccd213a989744b15d70547e6
8f682183913956c6d0414d2ee9165d9f31957934507b4fb010e1eafd29b3cf0e
19b2a5a72d27f8841152bca2694ce3d720dca29885a588443a375dec9c0a7b52
80521b1682d5e13e9bbeeadfd585ad3bf51bcf6164d378fce34a512056f4fa3f
914fb27e6fcc06d274cb0803c948b798f24a89133b07089c4c5d1c5d1330a492
428d3eac1d6720cca1a2461153b8e39b5ac10340f458c1c5ae93d2c85cebc054
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | detect_Redline_Stealer |
|---|---|
| Author: | Varp0s |
| Rule name: | INDICATOR_EXE_Packed_ConfuserEx |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables packed with ConfuserEx Mod |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | win_redline_wextract_hunting_oct_2023 |
|---|---|
| Author: | Matthew @ Embee_Research |
| Description: | Detects wextract archives related to redline/amadey |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.