MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 bc1363062c4f4aff514d71fd85fc9a5a08ad7fc2ea9a40298bb8865d041b8a3f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RedTigerStealer
Vendor detections: 14
| SHA256 hash: | bc1363062c4f4aff514d71fd85fc9a5a08ad7fc2ea9a40298bb8865d041b8a3f |
|---|---|
| SHA3-384 hash: | fb7d850542d86fd76ed12453e861981a254883d8b9520fb5c85d766dc91a8aacac192287cb64d0878c76e341962091f0 |
| SHA1 hash: | a885a46b11f6795960f595317a64b8d2c0ffb648 |
| MD5 hash: | 33cc51d4e64c95c356a8492e0af68d0e |
| humanhash: | burger-cold-alabama-fanta |
| File name: | atrmenu.exe |
| Download: | download sample |
| Signature | RedTigerStealer |
| File size: | 80'603'204 bytes |
| First seen: | 2026-05-25 09:01:21 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | dcaf48c1f10b0efa0a4472200f3850ed (716 x Efimer, 60 x BlankGrabber, 23 x SalatStealer) |
| ssdeep | 1572864:3TIA70sr8rE+vWlM9ojCrD4WWJvKSc/JUNnzrxq0oZVDq5e4/wLGodwfy:3Z0frzelKbDSc/iFzlqhee47 |
| TLSH | T1E90833848E807C4BF85DD13A8BE29D11D97BA86D2A425E4F23A005753FB77CC447EA72 |
| TrID | 70.9% (.EXE) InstallShield setup (43053/19/16) 10.7% (.EXE) Win64 Executable (generic) (6522/11/2) 8.3% (.EXE) Win16 NE executable (generic) (5038/12/1) 3.3% (.EXE) OS/2 Executable (generic) (2029/13) 3.3% (.EXE) Generic Win/DOS Executable (2002/3) |
| Magika | pebin |
| dhash icon | c6c2ccc4f4e0e0f8 (49 x PythonStealer, 32 x Adware.Yogi, 29 x SVCStealer) |
| Reporter | |
| Tags: | exe RedTigerStealer |
Intelligence
File Origin
# of uploads :
1
# of downloads :
171
Origin country :
SEVendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
atrmenu.exe
Verdict:
Malicious activity
Analysis date:
2026-05-25 08:59:22 UTC
Tags:
evasion ip-check python stealer discord pyinstaller generic redtiger rust openssl tool
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
96.5%
Tags:
extens virus sage
Result
Verdict:
Suspicious
Maliciousness:
Behaviour
Creating a file in the %temp% subdirectories
Restart of the analyzed sample
Creating a window
Running batch commands
Creating a process with a hidden window
DNS request
Connection attempt
Delayed reading of the file
Sending a custom TCP request
Sending an HTTP GET request
Launching a process
Using the Windows Management Instrumentation requests
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
anti-debug expand installer-heuristic lolbin microsoft_visual_cc overlay packed packed packed pyinstaller pyinstaller reconnaissance similar-threat
Verdict:
Malicious
Labled as:
Trojan_Win32_Wacatac_B_ml
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-05-25T06:03:00Z UTC
Last seen:
2026-05-27T00:32:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Python.Rodico.gen HEUR:Trojan.Python.Pytr.bi
Result
Threat name:
Discord Token Stealer, RedTiger Stealer
Detection:
malicious
Classification:
troj.spyw.evad
Score:
80 / 100
Signature
Found many strings related to Crypto-Wallets (likely being stolen)
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal communication platform credentials (via file / registry access)
Yara detected Discord Token Stealer
Yara detected RedTiger Stealer
Behaviour
Behavior Graph:
Score:
98%
Verdict:
Malware
File Type:
PE
Gathering data
Verdict:
Malicious
Threat:
Family.REDTIGER
Threat name:
Win64.Trojan.RedTiger
Status:
Malicious
First seen:
2026-05-23 16:24:26 UTC
File Type:
PE+ (Exe)
Extracted files:
2699
AV detection:
10 of 24 (41.67%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
redtiger_stealer
Score:
10/10
Tags:
family:redtiger_stealer credential_access discovery execution pyinstaller spyware stealer
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Browser Information Discovery
Accesses cryptocurrency files/wallets, possible credential harvesting
Command and Scripting Interpreter: PowerShell
Contacts third-party web service commonly abused for C2
Looks up external IP address via web service
Loads dropped DLL
Reads user/profile data of web browsers
Unsecured Credentials: Credentials In Files
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
No further information available
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.