MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92df7deea6b7d758f0c0a60a87c68de90e40fa07b3e261bebe7a5a48541656e5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedLineStealer


Vendor detections: 2


Intelligence 2 IOCs 1 YARA 7 File information Comments

SHA256 hash: 92df7deea6b7d758f0c0a60a87c68de90e40fa07b3e261bebe7a5a48541656e5
SHA3-384 hash: dc7af134b50c6b7a4206b3df51372490646fed8f9afcff40c7b91cada189d799a5b379eaf967f64145380c58707cd53b
SHA1 hash: b7ce96399a1264514abe4296696b36f3c1ae2c93
MD5 hash: 2441174cabf9e14f7e01977105087a65
humanhash: equal-river-eleven-coffee
File name:PureLand Metaverse.rar
Download: download sample
Signature RedLineStealer
File size:12'424'590 bytes
First seen:2023-03-04 04:33:05 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
Note:This file is a password protected archive. The password is: pureland2023
ssdeep 196608:vEnvo9nCSgIK1jzhHYgzRSnyyL3v7QrNHlThEP89vH023zW0VwLK4h09845yjb:v4YLg5zFYg92yy7zQxHlTh689vH023rI
TLSH T1A5C6333295FABEAD04F946730E9334DD97935EABF589126105CD83C4E58B8FE63E4820
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter iamdeadlyz
Tags:162-55-188-117 exe file-pumped pw pureland2023 rar RedLineStealer


Avatar
Iamdeadlyz
From thepureland.io (impersonation of Rune Teller - https://store.steampowered.com/app/1944360/Rune_Teller/)
Related incident: https://www.coindesk.com/business/2023/03/02/blockchain-game-the-sandbox-warns-of-phishing-email-after-security-breach/
RedLineStealer C&C: 162.55.188.117:48958

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
162.55.188.117:48958 https://threatfox.abuse.ch/ioc/1078699/

Intelligence


File Origin
# of uploads :
1
# of downloads :
305
Origin country :
n/a
File Archive Information

This file archive contains 23 file(s), sorted by their relevance:

File name:sharedassets1.assets
File size:410'084 bytes
SHA256 hash: c0b7a9d84a1d2de6ee226213e6420ee18d033cb50935ed66e6d3252cad0b400c
MD5 hash: 276f7d9a54bf29fcd2dbc801bf6403a0
MIME type:application/octet-stream
Signature RedLineStealer
File name:unity_builtin_extra
File size:390'644 bytes
SHA256 hash: b8cad02ee7e8ef68377ebab2b70fa2918420355b0cb29cf7a1b48e0515362bd4
MD5 hash: e830b287acfc7046bd4ef777b9402e6d
MIME type:application/octet-stream
Signature RedLineStealer
File name:globalgamemanagers
File size:574'140 bytes
SHA256 hash: ec3d38ed66bf3147355d33bc0cb1ca6a220f70c73c6cc192456287781a51970e
MD5 hash: fa2f46837817d0ecea82ecfc22b321b2
MIME type:application/octet-stream
Signature RedLineStealer
File name:UnityCrashHandler64.exe
File size:1'232'984 bytes
SHA256 hash: 225827869340676dce8cee2ba8dc7e4007f93f5f28d2c922f33adb3a951f869a
MD5 hash: 141e6688c27c76994dc7821eaddefa3f
MIME type:application/x-dosexec
Signature RedLineStealer
File name:sharedassets1.assets.resS
File size:8'912'896 bytes
SHA256 hash: 2c6af803b29cd3be8abe70478edb7a2bf4c19a9b7422ef15c03915c0896eb461
MD5 hash: cc69d0a6f715c050833a9d668c925e4b
MIME type:application/octet-stream
Signature RedLineStealer
File name:sharedassets2.assets
File size:200'244 bytes
SHA256 hash: cfc36378816d022d04663926b6244b2e9bc00a0caf667cef57307113f8ee2fa0
MD5 hash: de71b1a7bcdba02008f621738b0bdd6f
MIME type:application/octet-stream
Signature RedLineStealer
File name:web.config
File size:18'857 bytes
SHA256 hash: 15a2c7a9242bf54d3ccb3e07fa6d8f84ba8b303d8877243787a1103009941bdb
MD5 hash: 08101241b15b53ef0ab908f6d388881f
MIME type:text/xml
Signature RedLineStealer
File name:config.xml
File size:25'817 bytes
SHA256 hash: 0c56e34c69124510fa8c19e7b4c2ca6c1c4ff460ae19f798dd0ca035809e396d
MD5 hash: f34b330f20dce1bdcce9058fca287099
MIME type:text/xml
Signature RedLineStealer
File name:sharedassets0.assets
File size:15'729'768 bytes
SHA256 hash: 23265757ef1824a3382b240023049b11e94b09eefce47e16e2b628f29bdfa93c
MD5 hash: 20ce4c7d175335aac3617bb160d8879c
MIME type:application/octet-stream
Signature RedLineStealer
File name:settings.map
File size:2'622 bytes
SHA256 hash: ce1db1ad8a9512073164e3eccdc193f7eda036e1a9733caec4635de21b2865c8
MD5 hash: ba17ade8a8e3ee221377534c8136f617
MIME type:text/xml
Signature RedLineStealer
File name:sharedassets0.assets.resS
File size:9'953'412 bytes
SHA256 hash: ee83191343cd5a84b1ce9a6df55bc136ddc15c47f5c58f839f48ab776b24f6f7
MD5 hash: 5f685cd19f5d32407d28c2ef2efc0c85
MIME type:application/octet-stream
Signature RedLineStealer
File name:config
File size:3'276 bytes
SHA256 hash: 60099cf91bb1a5717fc1f2d23cf36a61d3bfb70d9489fbb6f4bae98c560bf3d5
MD5 hash: d9bc824737177af5792846f26507231c
MIME type:text/plain
Signature RedLineStealer
File name:app.info
File size:41 bytes
SHA256 hash: d95ab3a0e1a848fed8627741c70a20cde5c5b05df76136bbc5bb447419a44486
MD5 hash: 8422f6bbb1de88f818425091c7d11f90
MIME type:text/plain
Signature RedLineStealer
File name:ScriptingAssemblies.json
File size:3'782 bytes
SHA256 hash: 342538798e6c47c31c92dc25cbe5ec95d6071f39e0a296862cef9ab20776eed4
MD5 hash: ccf089f0bb570114f0ca7dc6b1378386
MIME type:application/json
Signature RedLineStealer
File name:sharedassets0.resource
File size:7'008 bytes
SHA256 hash: 0821af96ecfc09db99f843a57d12a395b6d9a2503f68fa547105dd70a0d7f24a
MD5 hash: ccbfefdf750008d2065c4b633b55da8d
MIME type:application/octet-stream
Signature RedLineStealer
File name:Pure Land Launcher v1.4.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:688'145'872 bytes
SHA256 hash: de57a7a49d78ccab0c875e193e5e4949a87e394bda3bb1fe950c724ef78f6f73
MD5 hash: 2a8c603669379c077a19b02017e176e2
De-pumped file size:271'360 bytes (Vs. original size of 688'145'872 bytes)
De-pumped SHA256 hash: b9fc13ce9933a6b09f4d458d876b1dffc29d9f07a6d3c986d29c772207043c05
De-pumped MD5 hash: a1a2935b1e618d810a60a222d649e3c6
MIME type:application/x-dosexec
Signature RedLineStealer
File name:DefaultWsdlHelpGenerator.aspx
File size:60'575 bytes
SHA256 hash: 751861040b69ea63a3827507b7c8da9c7f549dc181c1c8af4b7ca78cc97d710a
MD5 hash: f7be9f1841ff92f9d4040aed832e0c79
MIME type:text/html
Signature RedLineStealer
File name:boot.config
File size:69 bytes
SHA256 hash: 25202c8f0caa8139d220c1db829ac0445de52047059b03c920c7d145ddfeb4ba
MD5 hash: 2b77119d737c1c2caf66bc03e37efed2
MIME type:text/plain
Signature RedLineStealer
File name:browscap.ini
File size:311'984 bytes
SHA256 hash: 4ddd50f31fb968f30bedefc253a46dc3f2890192d05cdaa9e0a64a056eee807e
MD5 hash: 378be809df7d15aac75a175693e25fbb
MIME type:text/plain
Signature RedLineStealer
File name:unity default resources
File size:4'844'872 bytes
SHA256 hash: 458713a9e0aca9b787f40e355055a9e8f8193d0a203058b21164035fc573ad4a
MD5 hash: 45ca075a660921149eb37eaf028c14a0
MIME type:application/octet-stream
Signature RedLineStealer
File name:Compat.browser
File size:1'605 bytes
SHA256 hash: 8a1082057ac5681dcd4e9c227ed7fb8eb42ac1618963b5de3b65739dd77e2741
MD5 hash: 0d831c1264b5b32a39fa347de368fe48
MIME type:text/plain
Signature RedLineStealer
File name:sharedassets2.assets.resS
File size:7'837'312 bytes
SHA256 hash: ad971443cb9405a747351f955d80cb67c82a6055d3ee326c92b3785b9cb383ef
MD5 hash: 95b7d04093f91d954c5a063c0709a780
MIME type:application/octet-stream
Signature RedLineStealer
File name:machine.config
File size:34'106 bytes
SHA256 hash: ef9b9387168fd1dd6c996f96c134d9c44f8eb06f9587004bf997252a520182d6
MD5 hash: 0869544722561f5aff0eefc83fc7b001
MIME type:text/xml
Signature RedLineStealer
Vendor Threat Intelligence
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
spyware
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_EXE_Packed_SmartAssembly
Author:ditekSHen
Description:Detects executables packed with SmartAssembly
Rule name:MALWARE_Win_RedLine
Author:ditekSHen
Description:Detects RedLine infostealer
Rule name:pe_imphash
Rule name:Saudi_Phish_Trojan
Author:Florian Roth (Nextron Systems)
Description:Detects a trojan used in Saudi Aramco Phishing
Reference:https://goo.gl/Z3JUAA
Rule name:Saudi_Phish_Trojan_RID2E2F
Author:Florian Roth
Description:Detects a trojan used in Saudi Aramco Phishing
Reference:https://goo.gl/Z3JUAA
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RedLineStealer

rar 92df7deea6b7d758f0c0a60a87c68de90e40fa07b3e261bebe7a5a48541656e5

(this sample)

de57a7a49d78ccab0c875e193e5e4949a87e394bda3bb1fe950c724ef78f6f73

  
Dropping
SHA256 de57a7a49d78ccab0c875e193e5e4949a87e394bda3bb1fe950c724ef78f6f73
  
Delivery method
Distributed via web download

Comments