MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bc99d1bb9a12367979fcd24b696af85816f730c968f4e99df1c506ca99fa709f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedLineStealer


Vendor detections: 7


Intelligence 7 IOCs 1 YARA 1 File information Comments

SHA256 hash: bc99d1bb9a12367979fcd24b696af85816f730c968f4e99df1c506ca99fa709f
SHA3-384 hash: bc75e16f53a201ad38604780ac7b0b8e9ca38e4504ba23cb3e08b1cf97fcafacfd78b17634b1aee70787c24bb60d4ae7
SHA1 hash: 4c248a332eb42ec2628fd559fbd12d5cf3de49c8
MD5 hash: 1333e94811c5c6684944da819a330524
humanhash: mexico-salami-virginia-lactose
File name:Ghost_VPN_Free_setup.zip
Download: download sample
Signature RedLineStealer
File size:955'887 bytes
First seen:2023-03-29 18:11:00 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:T6PGPdzLz0VA6AcGkFZSC8K4a6A8d6wXdKVhv4jRdIus:7PhYGbEC9K4aUXtM4ps
TLSH T1AA15024DE578B45BF4C00376AA8A1CF7DB2C8E705B4DBCA7CA3524856987B1E1B3A431
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter abuse_ch
Tags:file-pumped malvertising RedLineStealer zip


Avatar
abuse_ch
RedLineStealer C2:
82.115.223.46:57672

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
37.220.87.13:48790 https://threatfox.abuse.ch/ioc/1060542/

Intelligence


File Origin
# of uploads :
1
# of downloads :
97
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Ghost_VPN_Free_setup.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:839'289'857 bytes
SHA256 hash: 4556643b2e3a495d9a11e054688f706fcde07aa49d103b9993c7ef98090e003f
MD5 hash: 3c00627a91193bc8e85f4301d2d0541e
De-pumped file size:429'056 bytes (Vs. original size of 839'289'857 bytes)
De-pumped SHA256 hash: cf114d3202b860e9422df3e940801187999bf463de63cd09c75b63a946e5e3b3
De-pumped MD5 hash: f3a3933c6b9331b81955d7105445367e
MIME type:application/x-dosexec
Signature RedLineStealer
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
ZIP File - Malicious
Behaviour
SuspiciousEmbeddedObjects detected
Gathering data
Threat name:
Win32.Trojan.RedLine
Status:
Malicious
First seen:
2023-03-29 19:04:54 UTC
AV detection:
10 of 36 (27.78%)
Threat level:
  5/5
Result
Malware family:
redline
Score:
  10/10
Tags:
family:redline infostealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Suspicious use of SetThreadContext
RedLine
Malware Config
C2 Extraction:
37.220.87.13:48790
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:PK_PUMP_AND_DUMP
Author:Will Metcalf @node5
Description:Walks Zip Central Directory filename entries looking for abused extension then checks for a file that's at least 25M and then check to see how much uncompressed size is vs compressed size

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RedLineStealer

zip bc99d1bb9a12367979fcd24b696af85816f730c968f4e99df1c506ca99fa709f

(this sample)

  
Delivery method
Distributed via web download

Comments