MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 61e82301d812c2d2710dcd4900890e6c291e0e7dfcbe60762ef199e726b44212. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RedLineStealer
Vendor detections: 17
| SHA256 hash: | 61e82301d812c2d2710dcd4900890e6c291e0e7dfcbe60762ef199e726b44212 |
|---|---|
| SHA3-384 hash: | b710dfc584d3a327181bec9cc82bc31a41b02752ca6061651b6e4f64d55121456aa0a13ef9883e8751c6d7a6a5835e4c |
| SHA1 hash: | 652f5cf71a9e906e5df82e2bea88593356df1163 |
| MD5 hash: | 6d0e06115140f3738ad91484dcd384fd |
| humanhash: | kilo-beer-bacon-india |
| File name: | file |
| Download: | download sample |
| Signature | RedLineStealer |
| File size: | 818'688 bytes |
| First seen: | 2023-06-16 23:24:12 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 646167cce332c1c252cdcb1839e0cf48 (8'473 x RedLineStealer, 4'851 x Amadey, 290 x Smoke Loader) |
| ssdeep | 24576:xyJ2M2jV+ADzDUKZFV3LfPIR7blc6ksCKLCENf7:kJjiV+YcKZfPIplcOCKLC6f |
| TLSH | T107051317BBC48432DEB817704CF646C30E35BCA1D864822B2786AD6D4CB36C49A7977B |
| TrID | 70.4% (.CPL) Windows Control Panel Item (generic) (197083/11/60) 11.1% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 5.9% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5) 3.7% (.EXE) Win64 Executable (generic) (10523/12/4) 2.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) |
| File icon (PE): | |
| dhash icon | f8f0f4c8c8c8d8f0 (8'803 x RedLineStealer, 5'078 x Amadey, 288 x Smoke Loader) |
| Reporter | |
| Tags: | exe RedLineStealer |
Intelligence
File Origin
USVendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
77.91.68.63/doma/net/index.php
Unpacked files
c9ec54189e36ee057b3c134c6118d18046e0b808d352d68ddee33ff58e0d047f
2ccd357e94ebb0dbc6b4dc7d77247c08474593d983b5c9cfd191a2f8c105bc80
844ec6982cd490e5fd08a9ecc4be54a3c8f5b43b76e0475b733573cb31dd9dfa
defc8629ec568833c618b6fe81ac45ff7908bb553b2811850a2e7f2e60b446b8
2238986fb7a16be5dad3f0c3f8d8cac880588e5e84127fc83228ffc6d7814eef
61e82301d812c2d2710dcd4900890e6c291e0e7dfcbe60762ef199e726b44212
bac87051ee827b2e05115e579ba03c1e234618b1dcaa99304c0ec6a296d1a7e6
14ad0b220fec046cad2a8e8dff2d89f107566da3f68c011c225fa6bab29c52ad
958431035edfb762865e04d7b7779642990562be407a3239a0d05737fdaf4873
6366eb832db7377d14b1065e56360344c77d4233d896ffc56538f2c3c563014d
989bf8e0d175239e3bbcaf55a5fd9608b02f231e7173d5c521f45ba2fb93a377
61e82301d812c2d2710dcd4900890e6c291e0e7dfcbe60762ef199e726b44212
99718dc39609da9473eead2af9e29ccb0ba4c6a153806a4d03f28b09ff39b12d
e6a1433270d416790653fb7e895f879c16445417513b7ff85298af3c8aaab4fd
1b17a7d9e11eba0178b3070e35fc0a6a02ff70a05cabba2fb82ac7d6d48e78c8
53ee2143ab012cd4fc37ab89860014be7619a75af3db77e15dac7e79eff5f750
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | detect_Redline_Stealer |
|---|---|
| Author: | Varp0s |
| Rule name: | INDICATOR_EXE_Packed_ConfuserEx |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables packed with ConfuserEx Mod |
| Rule name: | MALWARE_Win_RedLine |
|---|---|
| Author: | ditekSHen |
| Description: | Detects RedLine infostealer |
| Rule name: | pe_imphash |
|---|
| Rule name: | redline_stealer_1 |
|---|---|
| Author: | Nikolaos 'n0t' Totosis |
| Description: | RedLine Stealer Payload |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.