MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 72022f67687bc3c0d164d0bdc19ab286f612d4ae77b44d5209ab4633d4f6a48f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedLineStealer


Vendor detections: 3


Intelligence 3 IOCs 1 YARA 5 File information Comments

SHA256 hash: 72022f67687bc3c0d164d0bdc19ab286f612d4ae77b44d5209ab4633d4f6a48f
SHA3-384 hash: dc13fea49d57fb2bbc7331b5d26634f47e9d3291fc805a35411685367cc91a160daa28e674f21d4aa0be9791308b00e2
SHA1 hash: 6c995eccb927dbfab351b6eb2012b5d20a64568e
MD5 hash: c381fae4eaaedc8453d3ec2ea0b75218
humanhash: cola-quiet-fanta-thirteen
File name:impulseflow.rar
Download: download sample
Signature RedLineStealer
File size:15'920'446 bytes
First seen:2023-01-14 18:07:58 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
Note:This file is a password protected archive. The password is: impulse2023
ssdeep 393216:8YoVqFuzDqePFMDITr65PdV3Ljg+PNNcDvP7qSK9:8YoKKvtMDI365PdZLfNNcDvpK9
TLSH T186F63354178989B184E39689F47E0382823307D4D8EB50BC9F867D869B9DF1EC369B4F
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter iamdeadlyz
Tags:167-235-233-35 exe FakeEmberSword file-pumped pw impulse2023 rar RedLineStealer


Avatar
Iamdeadlyz
From impulse-flow.com (impersonation of embersword.com)
RedLineStealer C&C: 167.235.233.35:16621

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
167.235.233.35:16621 https://threatfox.abuse.ch/ioc/842482/

Intelligence


File Origin
# of uploads :
1
# of downloads :
252
Origin country :
n/a
File Archive Information

This file archive contains 29 file(s), sorted by their relevance:

File name:4100
File size:160 bytes
SHA256 hash: 71e1d3c639233b5c101f551a90c8932531fe2a1cac527c0777b29c5d37edf0f8
MD5 hash: 7bde4e780664131ab332abe21a697e71
MIME type:application/octet-stream
Signature RedLineStealer
File name:RarExt.dll
File size:647'832 bytes
SHA256 hash: b28d116dd3066e7a3c9f0cc2f63d34a7189c9d78e869d1255c9dec59172a9d5f
MD5 hash: 650a771d005941c7a23926011d75ad8f
MIME type:application/x-dosexec
Signature RedLineStealer
File name:PresentationFramework-SystemCore.dll
File size:26'384 bytes
SHA256 hash: 0a8c66bf5d001fae154a617c711356ea2c3a6ff83cba4e3cca99c6830f0cd150
MD5 hash: 2f0fb8a843e0eac96f570f6e5ba709f8
MIME type:application/x-dosexec
Signature RedLineStealer
File name:string.txt
File size:1'790 bytes
SHA256 hash: 492da94c7a05abcb0d3888a94746ead1f489bcbbc506e9fcdbe686ab7a769d66
MD5 hash: f71ff6ae0996164a61adda0f8e4854eb
MIME type:application/octet-stream
Signature RedLineStealer
File name:PresentationFramework.Luna.dll
File size:498'456 bytes
SHA256 hash: 39c46cc5735eb7e0a69979397761428feeb82dcc322003c8fdae19c4d23888ee
MD5 hash: f5af8f1ac2132f373a43a346c8020b15
MIME type:application/x-dosexec
Signature RedLineStealer
File name:EXTARCINFODLG
File size:1'384 bytes
SHA256 hash: b1c4530aa47de7ffce37f67ecc4878f9e6b4dc0330742b53cd918502258d8937
MD5 hash: 31993e44cad02856c7598f0d0588fcb6
MIME type:application/octet-stream
Signature RedLineStealer
File name:PresentationFramework.Royale.dll
File size:213'272 bytes
SHA256 hash: e6dd001c21b1181fe8f9cf0314994767cef4490116e196853e23f1db431c33d6
MD5 hash: d26f67692e8f3ec2ebf8e2975e6e5dc5
MIME type:application/x-dosexec
Signature RedLineStealer
File name:sbs_wminet_utils.dll
File size:7'680 bytes
SHA256 hash: 118361edeb3ae2c7f791a454fd08969f8d8288d735db44a3c150bafe332d4a66
MD5 hash: a1a3f9e8a096b629cba87f9a1ef0cac6
MIME type:application/x-dosexec
Signature RedLineStealer
File name:PresentationFramework.Classic.dll
File size:191'768 bytes
SHA256 hash: 26d0688398999c8df19cd46dc6732f214170229eb038d096ac12c9537cac3b1b
MD5 hash: bc42024ab8409bf9c9d0c90b9dd18379
MIME type:application/x-dosexec
Signature RedLineStealer
File name:PresentationFramework.Aero2.dll
File size:257'304 bytes
SHA256 hash: 196d725793de3f04eb13c59b70a84c724b74a065270b5e7bd2b1f779f91a33dd
MD5 hash: 8cd6a231a8535c99870cdb7190875c3e
MIME type:application/x-dosexec
Signature RedLineStealer
File name:11
File size:69'003 bytes
SHA256 hash: 4d830c2921ca9d1408dd409571f74a072c9bfb473f7d03bfb1a83a79ec1d9a63
MD5 hash: b0568908ac8c5861e6f7df216a8b42a8
MIME type:image/png
Signature RedLineStealer
File name:RarExt32.dll
File size:557'720 bytes
SHA256 hash: baabfc3548679965c551181efb7985bb699c3cdadc8e41fc353e80701c6bc947
MD5 hash: d73ad741400b8e2f92282a85f39fa295
MIME type:application/x-dosexec
Signature RedLineStealer
File name:4100.bmp
File size:1'286 bytes
SHA256 hash: 954e650f09f11869ec6ce3f58acf73054db16d47f1a318bc3f0c760e5eaba586
MD5 hash: 9131c1428a2b3168da0b8ed3aca2d623
MIME type:image/bmp
Signature RedLineStealer
File name:PresentationFramework-SystemXmlLinq.dll
File size:23'320 bytes
SHA256 hash: 2c52cdb0af3266a181920b8fff727c01f0a2d443c98dd56b8badab206da8b6ca
MD5 hash: 404502e00a5ef1c4c28fd0f4f79137d2
MIME type:application/x-dosexec
Signature RedLineStealer
File name:PresentationFramework-SystemXml.dll
File size:25'360 bytes
SHA256 hash: 71dfd3d72201c3c3128611dab8c886e68a348b7d448ac088851edaf63b0eafa2
MD5 hash: 0d2f115a596a77b198680f49f3c17a0d
MIME type:application/x-dosexec
Signature RedLineStealer
File name:EXTCMTARCINFODLG
File size:100 bytes
SHA256 hash: 5f2de23875cc15bcd38913fc0d76914cc748381ef82ac3ad132d0a6136ca39ac
MD5 hash: 17f8a5ebf2217ddcb4bc32cde666ee89
MIME type:application/octet-stream
Signature RedLineStealer
File name:system.ni.dll
File size:10'856'072 bytes
SHA256 hash: e06815f1b36f354cd9cb33931b30ce80f8e4c726f9fc32eb28b6e6268ad7f7a7
MD5 hash: c321f3cf6f973d449069e2a095ff0eae
MIME type:application/x-dosexec
Signature RedLineStealer
File name:PresentationFramework.AeroLite.dll
File size:182'040 bytes
SHA256 hash: e9963a479ff848e0aa6911401ca640040641b84406a3a061ef2c76fa8bd4a617
MD5 hash: 4b9f888ebb6edca23c272e14a3b2edfb
MIME type:application/x-dosexec
Signature RedLineStealer
File name:mscorlib.ni.dll
File size:21'039'432 bytes
SHA256 hash: 4863e7e44fb672ca38639ab9043c2048bc830d8b2633542fd4619e8a0b3fd1d3
MD5 hash: 6c3c5f2d3e00223faa75d1db018ef89a
MIME type:application/x-dosexec
Signature RedLineStealer
File name:7zxa.dll
File size:215'040 bytes
SHA256 hash: 6c3f5910637e2a4517d35ea42b0f4a83f6033dc31aebb3e54abb3435e653fb0b
MD5 hash: b478b92256a3d7fb87dda554e8e1e32f
MIME type:application/x-dosexec
Signature RedLineStealer
File name:PresentationFramework.dll
File size:6'294'432 bytes
SHA256 hash: 7b71a3fa8c2a3956dd02be6526a6bb04a79d9300f8afe4839d184d34039ab165
MD5 hash: e11c36a0b9dcc8ab41012b02fb01c079
MIME type:application/x-dosexec
Signature RedLineStealer
File name:PresentationFramework-SystemDrawing.dll
File size:25'368 bytes
SHA256 hash: 035fedb19c5bc2d1511c7180888b9ba4bdfcf1f0a70e8be32e82b51a9a2ea985
MD5 hash: 03d9b44c037f6591a56c3659714c5c62
MIME type:application/x-dosexec
Signature RedLineStealer
File name:2
File size:381 bytes
SHA256 hash: 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
MD5 hash: 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
MIME type:text/xml
Signature RedLineStealer
File name:PresentationFramework.Aero.dll
File size:253'208 bytes
SHA256 hash: d4c90909b35dc36b3d1fa06c07d47623215fc18eadbea939483e5fa9bf64e1aa
MD5 hash: 1e35f45cf80ad53d0bc5c6882e789c91
MIME type:application/x-dosexec
Signature RedLineStealer
File name:system.core.ni.dll
File size:8'501'384 bytes
SHA256 hash: f9fc98f5855d59bf320456a0e9a072b1a62028c32776c026c9ae146114934569
MD5 hash: a833a1e8ddcf9204ba4c3c3cec65d0bf
MIME type:application/x-dosexec
Signature RedLineStealer
File name:PresentationFramework-SystemData.dll
File size:18'832 bytes
SHA256 hash: 7697f88e6385c65f6b43c861726fe41df2a4507a57b705e6a6e3a9e287159d08
MD5 hash: 7ff0f10ccb6c71d2be1c4f5ed1875ed2
MIME type:application/x-dosexec
Signature RedLineStealer
File name:PresentationHost_v0400.dll
File size:234'944 bytes
SHA256 hash: 62a2eaf0d45933cf16b662790aa4f9ba2574aef037e7cc19764c5642fe1a23ef
MD5 hash: 4c60311347f2b4a5219a9081c3f776c7
MIME type:application/x-dosexec
Signature RedLineStealer
File name:_RDATA
File size:512 bytes
SHA256 hash: f2b2e1a2d55abfc9e028263352a2f3b7c2ed8df57d78ddf78cf9ad726a8446b0
MD5 hash: 7ab51487176d0510746fa180824dc8fd
MIME type:application/octet-stream
Signature RedLineStealer
File name:Impulse.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:734'264'280 bytes
SHA256 hash: 525c76af818223860817ac909c4db6c0defe8d0d98da30528c8374cc641d897e
MD5 hash: 9953b4b5279e35414adcc45c159820bd
De-pumped file size:248'832 bytes (Vs. original size of 734'264'280 bytes)
De-pumped SHA256 hash: 1e2085bb3e6b9e2daf2b4e72a376aa135e8b56c565ce9f5d62cb0744f4b1870f
De-pumped MD5 hash: 3ec84ba5702734f2437bc253031d956f
MIME type:application/x-dosexec
Signature RedLineStealer
Vendor Threat Intelligence
Gathering data
Result
Verdict:
MALICIOUS
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_EXE_Packed_SmartAssembly
Author:ditekSHen
Description:Detects executables packed with SmartAssembly
Rule name:MALWARE_Win_RedLine
Author:ditekSHen
Description:Detects RedLine infostealer
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RedLineStealer

rar 72022f67687bc3c0d164d0bdc19ab286f612d4ae77b44d5209ab4633d4f6a48f

(this sample)

525c76af818223860817ac909c4db6c0defe8d0d98da30528c8374cc641d897e

  
Dropping
SHA256 525c76af818223860817ac909c4db6c0defe8d0d98da30528c8374cc641d897e
  
Delivery method
Distributed via web download

Comments