🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bc1363062c4f4aff514d71fd85fc9a5a08ad7fc2ea9a40298bb8865d041b8a3f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedTigerStealer


Vendor detections: 14


Intelligence 14 IOCs YARA File information Comments

SHA256 hash: bc1363062c4f4aff514d71fd85fc9a5a08ad7fc2ea9a40298bb8865d041b8a3f
SHA3-384 hash: fb7d850542d86fd76ed12453e861981a254883d8b9520fb5c85d766dc91a8aacac192287cb64d0878c76e341962091f0
SHA1 hash: a885a46b11f6795960f595317a64b8d2c0ffb648
MD5 hash: 33cc51d4e64c95c356a8492e0af68d0e
humanhash: burger-cold-alabama-fanta
File name:atrmenu.exe
Download: download sample
Signature RedTigerStealer
File size:80'603'204 bytes
First seen:2026-05-25 09:01:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash dcaf48c1f10b0efa0a4472200f3850ed (716 x Efimer, 60 x BlankGrabber, 23 x SalatStealer)
ssdeep 1572864:3TIA70sr8rE+vWlM9ojCrD4WWJvKSc/JUNnzrxq0oZVDq5e4/wLGodwfy:3Z0frzelKbDSc/iFzlqhee47
TLSH T1E90833848E807C4BF85DD13A8BE29D11D97BA86D2A425E4F23A005753FB77CC447EA72
TrID 70.9% (.EXE) InstallShield setup (43053/19/16)
10.7% (.EXE) Win64 Executable (generic) (6522/11/2)
8.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
3.3% (.EXE) OS/2 Executable (generic) (2029/13)
3.3% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon c6c2ccc4f4e0e0f8 (49 x PythonStealer, 32 x Adware.Yogi, 29 x SVCStealer)
Reporter burger
Tags:exe RedTigerStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
171
Origin country :
SE SE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
atrmenu.exe
Verdict:
Malicious activity
Analysis date:
2026-05-25 08:59:22 UTC
Tags:
evasion ip-check python stealer discord pyinstaller generic redtiger rust openssl tool

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
96.5%
Tags:
extens virus sage
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Restart of the analyzed sample
Creating a window
Running batch commands
Creating a process with a hidden window
DNS request
Connection attempt
Delayed reading of the file
Sending a custom TCP request
Sending an HTTP GET request
Launching a process
Using the Windows Management Instrumentation requests
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug expand installer-heuristic lolbin microsoft_visual_cc overlay packed packed packed pyinstaller pyinstaller reconnaissance similar-threat
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-05-25T06:03:00Z UTC
Last seen:
2026-05-27T00:32:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Python.Rodico.gen HEUR:Trojan.Python.Pytr.bi
Result
Threat name:
Discord Token Stealer, RedTiger Stealer
Detection:
malicious
Classification:
troj.spyw.evad
Score:
80 / 100
Signature
Found many strings related to Crypto-Wallets (likely being stolen)
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal communication platform credentials (via file / registry access)
Yara detected Discord Token Stealer
Yara detected RedTiger Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1918138 Sample: atrmenu.exe Startdate: 25/05/2026 Architecture: WINDOWS Score: 80 44 store4.gofile.io 2->44 46 ip-api.com 2->46 48 3 other IPs or domains 2->48 56 Multi AV Scanner detection for submitted file 2->56 58 Yara detected RedTiger Stealer 2->58 60 Yara detected Discord Token Stealer 2->60 62 Joe Sandbox ML detected suspicious sample 2->62 9 atrmenu.exe 269 2->9         started        signatures3 process4 file5 36 C:\Users\...\_quoting_c.cp314-win_amd64.pyd, PE32+ 9->36 dropped 38 C:\Users\user\AppData\...\win32trace.pyd, PE32+ 9->38 dropped 40 C:\Users\user\AppData\Local\...\win32pdh.pyd, PE32+ 9->40 dropped 42 121 other files (none is malicious) 9->42 dropped 12 atrmenu.exe 1 9 9->12         started        process6 dnsIp7 50 ip-api.com 208.95.112.1, 49690, 80 TUT-AS-TotalUptimeTechnologiesLLCUS United States 12->50 52 store4.gofile.io 45.112.123.230, 443, 49696 GOFILEFR France 12->52 54 3 other IPs or domains 12->54 64 Found many strings related to Crypto-Wallets (likely being stolen) 12->64 66 Tries to harvest and steal browser information (history, passwords, etc) 12->66 68 Tries to steal communication platform credentials (via file / registry access) 12->68 16 powershell.exe 11 12->16         started        18 powershell.exe 11 12->18         started        20 powershell.exe 11 12->20         started        22 3 other processes 12->22 signatures8 process9 process10 24 conhost.exe 16->24         started        26 conhost.exe 18->26         started        28 conhost.exe 20->28         started        30 conhost.exe 22->30         started        32 conhost.exe 22->32         started        34 conhost.exe 22->34         started       
Gathering data
Threat name:
Win64.Trojan.RedTiger
Status:
Malicious
First seen:
2026-05-23 16:24:26 UTC
File Type:
PE+ (Exe)
Extracted files:
2699
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
redtiger_stealer
Score:
  10/10
Tags:
family:redtiger_stealer credential_access discovery execution pyinstaller spyware stealer
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Browser Information Discovery
Accesses cryptocurrency files/wallets, possible credential harvesting
Command and Scripting Interpreter: PowerShell
Contacts third-party web service commonly abused for C2
Looks up external IP address via web service
Loads dropped DLL
Reads user/profile data of web browsers
Unsecured Credentials: Credentials In Files
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments