MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 89412e4bb4f807d2f6ad8478bf2e5b4f36534950809d0508b82491eacd032e0f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RedLineStealer
Vendor detections: 18
| SHA256 hash: | 89412e4bb4f807d2f6ad8478bf2e5b4f36534950809d0508b82491eacd032e0f |
|---|---|
| SHA3-384 hash: | 74025fbb206c1ca9a3f3078cb7eec43bfc0a9a37769763a381a0249a16a03559c656cc42885872e3499e43a2a04066d1 |
| SHA1 hash: | f39d3c4122f2bb2df2aa73917c73c77a46b978c5 |
| MD5 hash: | 3992bc3ca59e21de0db770795dbb063f |
| humanhash: | don-carpet-juliet-arizona |
| File name: | 3992bc3ca59e21de0db770795dbb063f.exe |
| Download: | download sample |
| Signature | RedLineStealer |
| File size: | 781'312 bytes |
| First seen: | 2023-05-26 09:15:40 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 646167cce332c1c252cdcb1839e0cf48 (8'473 x RedLineStealer, 4'851 x Amadey, 290 x Smoke Loader) |
| ssdeep | 12288:9MrYy9094GO1zq0YhimZyH9n6maB5DOLlB9zfuloU4q+4dB/md/LBxEgr2Js:By9GO12Th976Lv97U4p4f/mdDj26 |
| Threatray | 3'642 similar samples on MalwareBazaar |
| TLSH | T17EF42312BFEC0132C8A017B05DF713834536BDA1AEBD832B2741A95F5DB36946935B2B |
| TrID | 70.4% (.CPL) Windows Control Panel Item (generic) (197083/11/60) 11.1% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 5.9% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5) 3.7% (.EXE) Win64 Executable (generic) (10523/12/4) 2.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) |
| File icon (PE): | |
| dhash icon | f8f0f4c8c8c8d8f0 (8'803 x RedLineStealer, 5'078 x Amadey, 288 x Smoke Loader) |
| Reporter | |
| Tags: | exe RedLineStealer |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
64a87db707bc088702e85a06d7b0a5323d3391d813c06f81e6d69dcbaa56d0ca
b8cb0830c58b6d528cd6495d084ba86e32036cc95a8f6fa86517fcd52411e444
ea8b31eb0f5a2a90ed64a5c5920b425846631e17b1198c90ac62726af9c18fdf
6a573853b0e3b3326ad7d61767d545a5834b55eda1699bf6b504f3d23ddb7aa3
64a87db707bc088702e85a06d7b0a5323d3391d813c06f81e6d69dcbaa56d0ca
b8cb0830c58b6d528cd6495d084ba86e32036cc95a8f6fa86517fcd52411e444
dabdaf0eecf2a5f597363d3373718861f6e4fb1f77aad8944d695243e8e50405
612a40afbbc2d8ef6c3625a74b339ed2da36480433e099a0461aa1c5dd569028
a4ef8452671e67065db2373e5954dd3a0ac5cd6a85ad9be032eb1538d888fc07
0bdc689d741094b2e7b09693bc9322bee5d9a4f993fc1dc63024f956a4f808c2
ec666c76c27338ebacabe84b9576a8f07cdeac95d06911cd7da0dc700ff5da2d
fbd5d8cc4edf1713af52314e595cd8f889026d1bb7ebe4502ec1e2ebd81011da
38ac1b6d0d24f2b5edec5949e87ab80431dc9a11d8cd0d383df58b16018c7273
9ecfa08f0cc38faadfa1af3697ea7669bef3ac4cd283a719672b2a131d10e2cf
d825fa29205747a0583ba9342989eb71043ceebdb323a3c717ec7149763799f3
de69842d0b844c1b7d75ecc08050b9c35ab4c587c4eccef966b82df6c65c6be7
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefender |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables embedding registry key / value combination indicative of disabling Windows Defedner features |
| Rule name: | pdb_YARAify |
|---|---|
| Author: | @wowabiy314 |
| Description: | PDB |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.