MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 be39a79adbc892815b56c1734f0af24ec909a58616a248b06e34de82de92a976. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedLineStealer


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments 1

SHA256 hash: be39a79adbc892815b56c1734f0af24ec909a58616a248b06e34de82de92a976
SHA3-384 hash: 98a1b9dc650d76f68c05eb0ef45fa60e5f8cb0e63aacac0d1250d6e4c3c7c232369ffe6a1ba939ff0fdf814f65127f22
SHA1 hash: d8a93ad1a7ec0e0bf284d5af70ea9293daf13c72
MD5 hash: 315aa85f34781196e0364a19e3b48bf4
humanhash: robert-fish-pip-muppet
File name:315aa85f34781196e0364a19e3b48bf4
Download: download sample
Signature RedLineStealer
File size:285'696 bytes
First seen:2021-11-17 12:41:00 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 79ff4954c9c3b349f13286a4d023397c (4 x RedLineStealer, 2 x ArkeiStealer)
ssdeep 6144:QnIh3luMhU1ys6ZXp1wno/0wfjgl5IOryKpXC4kDCLyqNQ63Ru5tS:Qnq3lYX6ZXp1So/0wfjgLI8yKBm+fQ63
TLSH T17354F04037F29832E2A71B311472C6B19A3AB9727934CD5A338413DE9EF12E15975BE3
File icon (PE):PE icon
dhash icon fcfcf4f4d4d4d8c8 (8 x RedLineStealer, 4 x RaccoonStealer, 1 x SystemBC)
Reporter zbetcheckin
Tags:32 exe RedLineStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
118
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
315aa85f34781196e0364a19e3b48bf4
Verdict:
Malicious activity
Analysis date:
2021-11-17 13:49:50 UTC
Tags:
trojan rat redline

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
DNS request
Using the Windows Management Instrumentation requests
Creating a window
Reading critical registry keys
Sending a TCP request to an infection source
Stealing user critical data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
greyware lockbit packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Generic Malware
Verdict:
Malicious
Result
Threat name:
RedLine
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Detected unpacking (overwrites its own PE header)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Yara detected RedLine Stealer
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Midie
Status:
Malicious
First seen:
2021-11-17 12:41:05 UTC
AV detection:
22 of 28 (78.57%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Result
Malware family:
redline
Score:
  10/10
Tags:
family:redline botnet:pubdate discovery infostealer spyware stealer
Behaviour
Suspicious use of AdjustPrivilegeToken
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Reads user/profile data of web browsers
RedLine
RedLine Payload
Malware Config
C2 Extraction:
193.56.146.64:65441
Unpacked files
SH256 hash:
f3aa79927b30615e01019b5f94aba8d01e36a1688b8f3b4e7219e54b98918a6f
MD5 hash:
50b186e2f2a4a84585bdff72bf9912f2
SHA1 hash:
ce9bd4eed7d01dbaa5f9304d8bddddbeb3128636
SH256 hash:
dc5a3c97f97c7790a830b8f4f1c563c9c1a80051e1c4a106ea880c141ff76162
MD5 hash:
0dbd81ba734c8db1a420f8811680a73e
SHA1 hash:
ca4ad363b91aa39ab10ad5e38c52ebeafd85ab04
SH256 hash:
1524efca52a61f257ef08940b9764a5fb616e37adc69ba7db938ad1e27105f89
MD5 hash:
7ec77274daf4b22fd1e7191ebf7fcc97
SHA1 hash:
46922459d1ba09528b3b04d611fea7171bb917b1
SH256 hash:
be39a79adbc892815b56c1734f0af24ec909a58616a248b06e34de82de92a976
MD5 hash:
315aa85f34781196e0364a19e3b48bf4
SHA1 hash:
d8a93ad1a7ec0e0bf284d5af70ea9293daf13c72
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RedLineStealer

Executable exe be39a79adbc892815b56c1734f0af24ec909a58616a248b06e34de82de92a976

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2021-11-17 12:41:02 UTC

url : hxxp://193.56.146.36/Pubdate.exe