MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 6a804f8a720d308d62aef87f7b1fcc00c250c17df1db9a32a03833fa70fa7f2c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RedLineStealer
Vendor detections: 15
| SHA256 hash: | 6a804f8a720d308d62aef87f7b1fcc00c250c17df1db9a32a03833fa70fa7f2c |
|---|---|
| SHA3-384 hash: | ba96305839977939f1e75dfbeaca7e5306c74a68a3daf8b065fae3365846a4ffb966618452375576363a2f8b5194b424 |
| SHA1 hash: | cdc5adfc00a5a82f31a6d037c9f25368a8b9cdaf |
| MD5 hash: | 572271ee451db8db86c5642e60def136 |
| humanhash: | victor-twenty-paris-mexico |
| File name: | 572271ee451db8db86c5642e60def136 |
| Download: | download sample |
| Signature | RedLineStealer |
| File size: | 951'808 bytes |
| First seen: | 2023-09-29 17:08:36 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 646167cce332c1c252cdcb1839e0cf48 (8'473 x RedLineStealer, 4'851 x Amadey, 290 x Smoke Loader) |
| ssdeep | 12288:GMrsy90P2Jqkad49zP2u/fCU6C3E1X2WwfP8sN3PJhB4RnT7vGza2f0xOJ0lBnRw:WyJad49zPHdE1mWXsBB4Z7Al0eu5e |
| Threatray | 800 similar samples on MalwareBazaar |
| TLSH | T18A152312A6F41132E8F857B019F707830B3ABD529A3983AF2654B59F5CF369004B57AF |
| TrID | 70.4% (.CPL) Windows Control Panel Item (generic) (197083/11/60) 11.1% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 5.9% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5) 3.7% (.EXE) Win64 Executable (generic) (10523/12/4) 2.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) |
| File icon (PE): | |
| dhash icon | f8f0f4c8c8c8d8f0 (8'803 x RedLineStealer, 5'078 x Amadey, 288 x Smoke Loader) |
| Reporter | |
| Tags: | 32 exe RedLineStealer |
Intelligence
File Origin
FRVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
18442229e86be0803345decd123943e28d522e586bd43844e6e8b9f91053587e
66e233d66cfa61401190bf8d28963173d97eb27a66561ce04e7fa23f52e2d05c
7246254d224a08d78eaad8bbcb7b83c10b28ef4c3e77373b4602edea4c1e61f7
6a804f8a720d308d62aef87f7b1fcc00c250c17df1db9a32a03833fa70fa7f2c
bb8fe4694e32e961db930b73d43c5d3afe3169b8394b6e04a5fe53e8f6238beb
86a168c145da81f5afdae6fc649c12f16159009b8ec3ab185d867cdc4bed8d36
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | detect_Redline_Stealer |
|---|---|
| Author: | Varp0s |
| Rule name: | INDICATOR_EXE_Packed_ConfuserEx |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables packed with ConfuserEx Mod |
| Rule name: | MALWARE_Win_RedLine |
|---|---|
| Author: | ditekSHen |
| Description: | Detects RedLine infostealer |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | redline_stealer_1 |
|---|---|
| Author: | Nikolaos 'n0t' Totosis |
| Description: | RedLine Stealer Payload |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.url : hxxp://77.91.68.238/new/foto7447.exe