MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2137265dc6a29ece0da45f06d99707cf689ee05393f68c2710e636d006e42412. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedLineStealer


Vendor detections: 16


Intelligence 16 IOCs YARA File information Comments

SHA256 hash: 2137265dc6a29ece0da45f06d99707cf689ee05393f68c2710e636d006e42412
SHA3-384 hash: 394d67ae097ec50dc076db0f2daab4ce3a489805eefce66bbe39f5d5707c68ac9268ff65bca96d0674628b0f4de9ca7f
SHA1 hash: 8e013645f4cda80cf7e324ab46e4b100e98dec95
MD5 hash: cb4166baa04d3473f12be48a291f90a6
humanhash: happy-lamp-minnesota-shade
File name:cb4166baa04d3473f12be48a291f90a6.exe
Download: download sample
Signature RedLineStealer
File size:37'701 bytes
First seen:2023-12-20 13:35:16 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 768:3E45SLnQpEhOB/hAGflc5xOXhr7gvexzv36:3E4EqEhOPNfqStgvexzv3
TLSH T1FC03D08A1C219A78FE1542F7169C8FD4533DD8CB61F3AF4D4A36893764CB7B482342A9
TrID 42.6% (.EXE) Win32 Executable (generic) (4505/5/1)
19.2% (.EXE) OS/2 Executable (generic) (2029/13)
18.9% (.EXE) Generic Win/DOS Executable (2002/3)
18.9% (.EXE) DOS Executable Generic (2000/1)
0.2% (.VXD) VXD Driver (29/21)
Reporter abuse_ch
Tags:exe RedLineStealer


Avatar
abuse_ch
RedLineStealer C2:
193.233.132.71:45650

Intelligence


File Origin
# of uploads :
1
# of downloads :
343
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
cb4166baa04d3473f12be48a291f90a6.exe
Verdict:
Malicious activity
Analysis date:
2023-12-20 13:38:40 UTC
Tags:
loader smoke smokeloader stealer redline

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for synchronization primitives
Sending a custom TCP request
Сreating synchronization primitives
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Creating a file in the %temp% directory
Creating a process from a recently created file
DNS request
Sending an HTTP POST request
Unauthorized injection to a system process
Enabling autorun by creating a file
Sending an HTTP POST request to an infection source
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
overlay packed smokeloader xpack
Result
Threat name:
Glupteba, LummaC Stealer, Petite Virus,
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code contains very large array initializations
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Benign windows process drops PE files
C2 URLs / IPs found in malware configuration
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Connects to a pastebin service (likely for C&C)
Connects to many ports of the same IP (likely port scanning)
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found Tor onion address
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
PE file has a writeable .text section
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses process hollowing technique
Sample uses string decryption to hide its real strings
System process connects to network (likely due to code injection or exploit)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
UAC bypass detected (Fodhelper)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected Generic Downloader
Yara detected Glupteba
Yara detected LummaC Stealer
Yara detected Petite Virus
Yara detected RedLine Stealer
Yara detected SmokeLoader
Yara detected Socks5Systemz
Yara detected Stealc
Yara detected Telegram RAT
Yara detected zgRAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1365059 Sample: 8RYB9RzQA5.exe Startdate: 20/12/2023 Architecture: WINDOWS Score: 100 160 pastebin.com 2->160 162 host-host-file8.com 2->162 164 10 other IPs or domains 2->164 186 Multi AV Scanner detection for domain / URL 2->186 188 Found malware configuration 2->188 190 Malicious sample detected (through community Yara rule) 2->190 194 24 other signatures 2->194 14 8RYB9RzQA5.exe 2->14         started        17 gwtvacc 2->17         started        19 svchost.exe 34 2->19         started        21 TrustedInstaller.exe 2->21         started        signatures3 192 Connects to a pastebin service (likely for C&C) 160->192 process4 signatures5 246 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 14->246 248 Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation)) 14->248 250 Maps a DLL or memory area into another process 14->250 23 explorer.exe 29 25 14->23 injected 252 Checks if the current machine is a virtual machine (disk enumeration) 17->252 254 Creates a thread in another existing process (thread injection) 17->254 28 WerFault.exe 19->28         started        process6 dnsIp7 170 185.215.113.68, 49735, 80 WHOLESALECONNECTIONSNL Portugal 23->170 172 5.42.65.125, 49738, 80 RU-KSTVKolomnaGroupofcompaniesGuarantee-tvRU Russian Federation 23->172 174 4 other IPs or domains 23->174 122 C:\Users\user\AppData\Roaming\gwtvacc, PE32 23->122 dropped 124 C:\Users\user\AppData\Roaming\gdtvacc, PE32 23->124 dropped 126 C:\Users\user\AppData\Local\Temp\7D34.exe, PE32 23->126 dropped 128 9 other files (2 malicious) 23->128 dropped 200 System process connects to network (likely due to code injection or exploit) 23->200 202 Benign windows process drops PE files 23->202 204 Deletes itself after installation 23->204 206 Hides that the sample has been downloaded from the Internet (zone.identifier) 23->206 30 6DF1.exe 23->30         started        33 42BA.exe 4 23->33         started        36 84A8.exe 23->36         started        39 2 other processes 23->39 file8 signatures9 process10 dnsIp11 140 C:\Users\user\AppData\Local\...\toolspub2.exe, PE32 30->140 dropped 142 C:\...\31839b57a4f11171d6abc8bbc4451ee4.exe, PE32 30->142 dropped 144 C:\Users\user\AppData\Local\Temp\tuc3.exe, PE32 30->144 dropped 146 C:\Users\user\AppData\...\InstallSetup9.exe, PE32 30->146 dropped 41 tuc3.exe 30->41         started        44 toolspub2.exe 30->44         started        47 31839b57a4f11171d6abc8bbc4451ee4.exe 30->47         started        54 2 other processes 30->54 148 C:\Users\user\AppData\...\Protect544cd51a.dll, PE32 33->148 dropped 182 Found many strings related to Crypto-Wallets (likely being stolen) 33->182 184 Sample uses process hollowing technique 33->184 49 RegSvcs.exe 8 4 33->49         started        52 WerFault.exe 33->52         started        166 attachmentartikidw.fun 104.21.76.167 CLOUDFLARENETUS United States 36->166 168 176.123.7.190 ALEXHOSTMD Moldova Republic of 39->168 file12 signatures13 process14 dnsIp15 130 C:\Users\user\AppData\Local\Temp\...\tuc3.tmp, PE32 41->130 dropped 56 tuc3.tmp 41->56         started        222 Detected unpacking (changes PE section rights) 44->222 224 Contains functionality to inject code into remote processes 44->224 226 Sample uses process hollowing technique 44->226 228 Injects a PE file into a foreign processes 44->228 58 toolspub2.exe 44->58         started        230 Detected unpacking (overwrites its own PE header) 47->230 232 UAC bypass detected (Fodhelper) 47->232 234 Found Tor onion address 47->234 236 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 47->236 61 cmd.exe 47->61         started        152 195.20.16.103, 18305, 49739 EITADAT-ASFI Finland 49->152 238 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 49->238 240 Found many strings related to Crypto-Wallets (likely being stolen) 49->240 242 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 49->242 244 2 other signatures 49->244 154 api4.ipify.org 173.231.16.77 WEBNXUS United States 54->154 156 91.92.254.7 THEZONEBG Bulgaria 54->156 158 2 other IPs or domains 54->158 132 C:\Users\user\AppData\...\nsy8FE3.tmp.exe, PE32 54->132 dropped 134 C:\Users\user\AppData\Local\Temp\...\Math.dll, PE32 54->134 dropped 136 C:\Users\user\AppData\Local\...\INetC.dll, PE32 54->136 dropped 138 2 other files (none is malicious) 54->138 dropped 63 nsy8FE3.tmp.exe 54->63         started        65 BroomSetup.exe 54->65         started        file16 signatures17 process18 signatures19 67 tuc3.exe 56->67         started        208 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 58->208 210 Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation)) 58->210 212 Maps a DLL or memory area into another process 58->212 220 2 other signatures 58->220 70 fodhelper.exe 61->70         started        72 conhost.exe 61->72         started        74 fodhelper.exe 61->74         started        76 fodhelper.exe 61->76         started        214 Detected unpacking (changes PE section rights) 63->214 216 Detected unpacking (overwrites its own PE header) 63->216 218 Injects a PE file into a foreign processes 63->218 78 nsy8FE3.tmp.exe 63->78         started        process20 dnsIp21 116 C:\Users\user\AppData\Local\Temp\...\tuc3.tmp, PE32 67->116 dropped 82 tuc3.tmp 67->82         started        86 31839b57a4f11171d6abc8bbc4451ee4.exe 70->86         started        180 77.91.76.36 FOTONTELECOM-TRANSIT-ASFOTONTELECOMISPRU Russian Federation 78->180 118 C:\Users\user\AppData\...\msvcp140[1].dll, PE32 78->118 dropped 120 C:\ProgramData\msvcp140.dll, PE32 78->120 dropped 256 Tries to harvest and steal browser information (history, passwords, etc) 78->256 file22 signatures23 process24 file25 108 C:\Program Files (x86)\...\stdbutton.exe, PE32 82->108 dropped 110 C:\Program Files (x86)\...\is-STSS2.tmp, PE32 82->110 dropped 112 C:\Program Files (x86)\...\is-S6UV7.tmp, PE32 82->112 dropped 114 106 other files (none is malicious) 82->114 dropped 196 Uses schtasks.exe or at.exe to add and modify task schedules 82->196 88 net.exe 82->88         started        90 stdbutton.exe 82->90         started        93 schtasks.exe 82->93         started        95 stdbutton.exe 82->95         started        198 Found Tor onion address 86->198 98 powershell.exe 86->98         started        signatures26 process27 dnsIp28 100 conhost.exe 88->100         started        102 net1.exe 88->102         started        176 dtamnky.info 185.196.8.22 SIMPLECARRER2IT Switzerland 90->176 178 95.216.227.177 HETZNER-ASDE Germany 90->178 104 conhost.exe 93->104         started        150 C:\ProgramData\M73Bitrate\M73Bitrate.exe, PE32 95->150 dropped 106 conhost.exe 98->106         started        file29 process30
Threat name:
Win32.Trojan.SmokeLoader
Status:
Malicious
First seen:
2023-12-17 00:35:28 UTC
File Type:
PE (Exe)
AV detection:
22 of 23 (95.65%)
Threat level:
  5/5
Verdict:
malicious
Result
Malware family:
Score:
  10/10
Tags:
family:djvu family:glupteba family:lumma family:redline family:smokeloader family:stealc family:zgrat botnet:666 botnet:@oleh_ps botnet:livetraffic botnet:up3 backdoor discovery dropper infostealer loader persistence ransomware rat spyware stealer trojan
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
Runs net.exe
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Enumerates physical storage devices
Program crash
Drops file in Program Files directory
Suspicious use of SetThreadContext
Adds Run key to start application
Checks installed software on the system
Legitimate hosting services abused for malware hosting/C2
Looks up external IP address via web service
Checks computer location settings
Deletes itself
Executes dropped EXE
Loads dropped DLL
Modifies file permissions
Reads user/profile data of web browsers
Downloads MZ/PE file
Detect Lumma Stealer payload V4
Detect ZGRat V1
Detected Djvu ransomware
Djvu Ransomware
Glupteba
Glupteba payload
Lumma Stealer
RedLine
RedLine payload
SmokeLoader
Stealc
ZGRat
Malware Config
C2 Extraction:
http://185.215.113.68/fks/index.php
176.123.7.190:32927
193.233.132.71:45650
77.105.132.87:17066
http://host-file-host6.com/
http://host-host-file8.com/
http://77.91.76.36
http://attachmentartikidw.fun/api
195.20.16.103:18305
http://zexeq.com/test1/get.php
Unpacked files
SH256 hash:
2137265dc6a29ece0da45f06d99707cf689ee05393f68c2710e636d006e42412
MD5 hash:
cb4166baa04d3473f12be48a291f90a6
SHA1 hash:
8e013645f4cda80cf7e324ab46e4b100e98dec95
Detections:
SmokeLoaderStage2 win_smokeloader_a2
Malware family:
SmokeLoader
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments