MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 79f08c4fd32a89c0d00a0f74669421fa36a7e1dab0fe8ccdb614fafa34cb246b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RedLineStealer
Vendor detections: 17
| SHA256 hash: | 79f08c4fd32a89c0d00a0f74669421fa36a7e1dab0fe8ccdb614fafa34cb246b |
|---|---|
| SHA3-384 hash: | 394bcb501b0b56e75b94f84c65978be1877e752e2feec16ffbb2aabc33961e968eb405631ea692dbb447df9f4ef4d63f |
| SHA1 hash: | 1c2c8f4ddc0b7065b1b250fc2b6e0d7d102238b0 |
| MD5 hash: | 237f21cf70ee646ba45ef8f25567e376 |
| humanhash: | wyoming-mexico-orange-batman |
| File name: | i5274199.exe |
| Download: | download sample |
| Signature | RedLineStealer |
| File size: | 261'702 bytes |
| First seen: | 2023-06-13 01:40:41 UTC |
| Last seen: | 2023-06-13 02:32:52 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 9c08ef92fb7c351c8e6c0ebf347d1602 (2 x RedLineStealer) |
| ssdeep | 3072:vMiBIHozcM2o5/rmRviNhLI1fbCeOYTpL6GXraZKegBc4054fxvwXZBa:vMCI22OmqTMraEeFnqCZBa |
| Threatray | 874 similar samples on MalwareBazaar |
| TLSH | T1604439C736A0EA76D44AC1B63842CD8895FF2452C65682DDFADDDBCC231C7F06AAC461 |
| TrID | 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 15.9% (.EXE) Win64 Executable (generic) (10523/12/4) 9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 7.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 6.8% (.EXE) Win32 Executable (generic) (4505/5/1) |
| Reporter | |
| Tags: | exe RedLineStealer |
Intelligence
File Origin
USVendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
687d0b0186e4533c96949185042937a69acafb01720207a61a402b045d29a38a
4a8717223bb41c1a9ef72c6692b7c5764ca942f665ed6fac72d75db5a710a1fa
a8d25eebb258abb8283ec3124a7a95fc1c684665ce8869932591d4abfcf0a5a0
da11108b7fb14023a20b5d1316e9a5853690b80e079e77a1879ea9a446ef392a
fc7a2d08160f299450390086b02c5b02277e1eb8c7cab88bb4313594d0c0cb67
79f08c4fd32a89c0d00a0f74669421fa36a7e1dab0fe8ccdb614fafa34cb246b
9e60f719f6c1ae293ad593dc093e5872bc1a7df340a54527e7a1c9186ad66712
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_EXE_Packed_ConfuserEx |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables packed with ConfuserEx Mod |
| Rule name: | MALWARE_Win_RedLine |
|---|---|
| Author: | ditekSHen |
| Description: | Detects RedLine infostealer |
| Rule name: | PE_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | pe_imphash |
|---|
| Rule name: | PE_Potentially_Signed_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | redline_stealer_1 |
|---|---|
| Author: | Nikolaos 'n0t' Totosis |
| Description: | RedLine Stealer Payload |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.