MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 854e5c0dbeb31b0953c41b36dc88fa4e959c00c848fb723dc2f9223aeb5a359a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedLineStealer


Vendor detections: 11


Intelligence 11 IOCs 3 YARA File information Comments

SHA256 hash: 854e5c0dbeb31b0953c41b36dc88fa4e959c00c848fb723dc2f9223aeb5a359a
SHA3-384 hash: 4b18118c28b1dc8d0e432077d98a136d926a4f016c804b2a3cd352a573f068078c1a7669eaa68df96658adf0b4f395c5
SHA1 hash: 2c69cb985d7c422faa5c2e424b72ca45e94a6666
MD5 hash: 7d12550f98dc72b2f48816a9e979dfe9
humanhash: maryland-harry-eleven-eleven
File name:7D12550F98DC72B2F48816A9E979DFE9.exe
Download: download sample
Signature RedLineStealer
File size:4'861'253 bytes
First seen:2021-08-11 20:25:49 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c05041e01f84e1ccca9c4451f3b6a383 (141 x RedLineStealer, 101 x GuLoader, 64 x DiamondFox)
ssdeep 98304:yju4l+nX+HrTHNIgv9Ks/54b2X1sPPlki4YRTTLDPK:y8OH3HNXv9Ks/5Ge1sPPl+sTTS
Threatray 291 similar samples on MalwareBazaar
TLSH T1BE2633784246C2F6C6BDD1B438BBCE471B90DE025339A85BAF907A857C2D991EC35B0D
dhash icon b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla)
Reporter abuse_ch
Tags:exe RedLineStealer


Avatar
abuse_ch
RedLineStealer C2:
http://74.119.195.135/

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://74.119.195.135/ https://threatfox.abuse.ch/ioc/171652/
http://cleaner-partners.top/decision.php https://threatfox.abuse.ch/ioc/172113/
45.14.49.128:16334 https://threatfox.abuse.ch/ioc/172157/

Intelligence


File Origin
# of uploads :
1
# of downloads :
163
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a file
Searching for the window
Running batch commands
Connection attempt
Sending a custom TCP request
DNS request
Sending an HTTP GET request
Deleting a recently created file
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
RedLine Socelars Vidar Xmrig
Detection:
malicious
Classification:
troj.spyw.evad.mine
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Antivirus detection for dropped file
Antivirus detection for URL or domain
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Creates processes via WMI
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Disable Windows Defender real time protection (registry)
Drops PE files to the document folder of the user
Found many strings related to Crypto-Wallets (likely being stolen)
Machine Learning detection for dropped file
Machine Learning detection for sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
PE file has a writeable .text section
Sigma detected: Suspicious Svchost Process
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected RedLine Stealer
Yara detected Socelars
Yara detected Vidar stealer
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 463678 Sample: QObP0KFKI8.exe Startdate: 11/08/2021 Architecture: WINDOWS Score: 100 92 208.95.112.1 TUT-ASUS United States 2->92 94 20.42.73.29 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 2->94 96 11 other IPs or domains 2->96 114 Antivirus detection for URL or domain 2->114 116 Antivirus detection for dropped file 2->116 118 Multi AV Scanner detection for dropped file 2->118 120 15 other signatures 2->120 11 QObP0KFKI8.exe 10 2->11         started        signatures3 process4 file5 58 C:\Users\user\AppData\...\setup_installer.exe, PE32 11->58 dropped 14 setup_installer.exe 8 11->14         started        process6 file7 60 C:\Users\user\AppData\...\setup_install.exe, PE32 14->60 dropped 62 C:\Users\user\AppData\...\libwinpthread-1.dll, PE32 14->62 dropped 64 C:\Users\user\AppData\...\libstdc++-6.dll, PE32 14->64 dropped 66 3 other files (none is malicious) 14->66 dropped 17 setup_install.exe 11 14->17         started        process8 dnsIp9 88 172.67.170.195 CLOUDFLARENETUS United States 17->88 90 127.0.0.1 unknown unknown 17->90 50 C:\Users\user\AppData\...\ace3e10e2377.exe, PE32 17->50 dropped 52 C:\Users\user\AppData\...\62bac2450133.exe, PE32 17->52 dropped 54 C:\Users\user\...\1a6424056cd08a61.exe, PE32 17->54 dropped 56 7 other files (2 malicious) 17->56 dropped 21 cmd.exe 17->21         started        23 cmd.exe 1 17->23         started        25 cmd.exe 1 17->25         started        27 6 other processes 17->27 file10 process11 process12 29 ace3e10e2377.exe 21->29         started        34 62bac2450133.exe 91 23->34         started        36 0e344493feb412.exe 25->36         started        38 1a6424056cd08a61.exe 2 27->38         started        40 ef59bf9776.exe 27->40         started        42 23ffe9e2dd84.exe 4 27->42         started        44 325a324218d375.exe 27->44         started        dnsIp13 98 37.0.10.236 WKD-ASIE Netherlands 29->98 100 37.0.11.8 WKD-ASIE Netherlands 29->100 110 16 other IPs or domains 29->110 68 C:\Users\...\sZOUimABbWSb7uf42diucgMU.exe, PE32 29->68 dropped 70 C:\Users\...\owiahClwF5ss63xltWxirRqv.exe, PE32 29->70 dropped 72 C:\Users\...\ovvuhtduG1m_wb7w892MgW3S.exe, PE32 29->72 dropped 76 41 other files (37 malicious) 29->76 dropped 122 Drops PE files to the document folder of the user 29->122 124 Tries to harvest and steal browser information (history, passwords, etc) 29->124 126 Disable Windows Defender real time protection (registry) 29->126 102 74.114.154.18 AUTOMATTICUS Canada 34->102 104 176.123.2.239 ALEXHOSTMD Moldova Republic of 34->104 78 12 other files (none is malicious) 34->78 dropped 128 Detected unpacking (changes PE section rights) 34->128 130 Detected unpacking (overwrites its own PE header) 34->130 132 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 34->132 134 Tries to steal Crypto Currency Wallets 34->134 136 Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation)) 36->136 138 Checks if the current machine is a virtual machine (disk enumeration) 36->138 106 192.168.2.1 unknown unknown 38->106 140 Creates processes via WMI 38->140 46 1a6424056cd08a61.exe 38->46         started        108 172.67.190.140 CLOUDFLARENETUS United States 40->108 74 C:\Users\user\AppData\Roaming\7542598.exe, PE32 40->74 dropped 80 2 other files (none is malicious) 40->80 dropped 82 2 other files (none is malicious) 42->82 dropped 84 2 other files (none is malicious) 44->84 dropped file14 signatures15 process16 dnsIp17 112 104.21.70.98 CLOUDFLARENETUS United States 46->112 86 C:\Users\user\AppData\Local\Temp\sqlite.dll, PE32 46->86 dropped file18
Threat name:
Win32.Spyware.Socelars
Status:
Malicious
First seen:
2021-08-10 16:37:00 UTC
AV detection:
18 of 28 (64.29%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:raccoon family:redline family:smokeloader family:socelars family:vidar botnet:39b871ed120e56ecbdc546b8a8a78c4e5516bc1f botnet:706 botnet:7new aspackv2 backdoor infostealer persistence stealer suricata trojan
Behaviour
Checks SCSI registry key(s)
Kills process with taskkill
Script User-Agent
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Adds Run key to start application
Legitimate hosting services abused for malware hosting/C2
Looks up external IP address via web service
Loads dropped DLL
ASPack v2.12-2.42
Downloads MZ/PE file
Executes dropped EXE
Vidar Stealer
Process spawned unexpected child process
Raccoon
Raccoon Stealer Payload
RedLine
RedLine Payload
SmokeLoader
Socelars
Socelars Payload
Vidar
suricata: ET MALWARE Observed Elysium Stealer Variant CnC Domain (all-brain-company .xyz in TLS SNI)
suricata: ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile
Malware Config
C2 Extraction:
https://prophefliloc.tumblr.com/
http://aucmoney.com/upload/
http://thegymmum.com/upload/
http://atvcampingtrips.com/upload/
http://kuapakualaman.com/upload/
http://renatazarazua.com/upload/
http://nasufmutlu.com/upload/
sytareliar.xyz:80
yabelesatg.xyz:80
ceneimarck.xyz:80
Unpacked files
SH256 hash:
1cdddf182f161ab789edfcc68a0706d0b8412a9ba67a3f918fe60fab270eabff
MD5 hash:
0965da18bfbf19bafb1c414882e19081
SHA1 hash:
e4556bac206f74d3a3d3f637e594507c30707240
SH256 hash:
c5483b2acbb352dc5c9a811d9616c4519f0e07c13905552be5ec869613ada775
MD5 hash:
13a289feeb15827860a55bbc5e5d498f
SHA1 hash:
e1f0a544fcc5b3bc0ab6a788343185ad1ad077ad
SH256 hash:
081f98edcc1f80cf0ce2c428a9324820ed6f039ffbff4dbd5566d95cc0b5cdf3
MD5 hash:
914ed92ed191f615e8fde6c30586a1dd
SHA1 hash:
d83a6c7764636122e91311bf526fd31fdf89ae97
SH256 hash:
20f141968ca94ce06fdd226e4669be3f924db0bf40b5133f3361a095c7dbd24f
MD5 hash:
413b067278fc114a0ec67440c47ec167
SHA1 hash:
b7b8d76c314b966aeabe6e6a1a8b4112d30ca708
SH256 hash:
78958d664b1c140f2b45e56c4706108eeb5f14756977e2efd3409f8a788d3c98
MD5 hash:
c0d18a829910babf695b4fdaea21a047
SHA1 hash:
236a19746fe1a1063ebe077c8a0553566f92ef0f
SH256 hash:
a7abe50505fc2fd6a920828b3cad0d45756d5c645dbed69f1fbabb006a78f9ec
MD5 hash:
c94637bcd99414ea70328b46a9ae9a97
SHA1 hash:
f6cc4ffa67c2092e7535921d716db695cd4a7222
SH256 hash:
a5f373f8bcfae3d9f4895c477206de63f66f08e66b413114cf2666bed798eb71
MD5 hash:
7aaf005f77eea53dc227734db8d7090b
SHA1 hash:
b6be1dde4cf73bbf0d47c9e07734e96b3442ed59
SH256 hash:
dce21c183a366ab2cbd82e2cf4ae0c45634d4fd4469110485455a005d5bd4a8c
MD5 hash:
edcf0859069fe9acba0a1a528fec8c4d
SHA1 hash:
69992bd13adff8bacd1c94583cb35c263489173c
SH256 hash:
e1cc6a9d780602fe6e789bf5c3a27e87e197a4e3bf7c8138ea2f9dfec70fb963
MD5 hash:
f707252b9c9579677fffb013e0cfc646
SHA1 hash:
8ab483023fa8773afb8c13464c39c5b8e687f126
SH256 hash:
ddbe26b2ac611988d9035c782fa4f8ef01ed7b8fb4995cab60f7ec4a933657a3
MD5 hash:
f058187cd33c10725678e55e672b0bb1
SHA1 hash:
f2644114ba4f8a2aeb5769ac9c0413b0b59cde6b
SH256 hash:
61494bca647b46aa9c7cfe3530385a7d6f9dc2287c9b0b4fd61dfa701ba7a4ad
MD5 hash:
df2208cc1e06995916314451713aa5b0
SHA1 hash:
ae2d9d9cdbe24556f5359b13767533bbe9c046d1
SH256 hash:
dd5c306519cc94125348f67bd6a533e9ec5fe06a0be2404e7f7175dd150cdeaa
MD5 hash:
12c4e83713e044a173a2a56d0689cc4c
SHA1 hash:
a72587ad2fd0c93a469edb802cfc753bc00f1fff
SH256 hash:
e811f993638c622c71e0fdb895b57bdbe86d13915785a93673064b1e9a6007b3
MD5 hash:
acac1d2458bcf0cf39520d2326aa42f5
SHA1 hash:
e9d60cdc2444a0c5abd0ca816733143335f29141
SH256 hash:
3dc34665672aa3b5c9d5c2a73aab735610d272209d41af69b76051b7261e3817
MD5 hash:
5966ae3a490bd2ec1f3c25d52e6b606e
SHA1 hash:
a8d820533b71ba52b596c6a3374acffb7f7e83a3
Detections:
win_socelars_auto
SH256 hash:
854e5c0dbeb31b0953c41b36dc88fa4e959c00c848fb723dc2f9223aeb5a359a
MD5 hash:
7d12550f98dc72b2f48816a9e979dfe9
SHA1 hash:
2c69cb985d7c422faa5c2e424b72ca45e94a6666
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments