MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 be6102a7a30977132f9f8307f73d42031441f467a8717d5072fddca9ed53603e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedLineStealer


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: be6102a7a30977132f9f8307f73d42031441f467a8717d5072fddca9ed53603e
SHA3-384 hash: a3f1ed574a594fb521b200e5d9228429d1d77973ac34f155e337161d739d77a5e3825bc2236c853239f7be1e2c3274d2
SHA1 hash: 76e39597d5070d72e6237808de0f23c167a9c484
MD5 hash: a4aa0e51a1218b07426f6f1079cd6012
humanhash: purple-salami-delta-bravo
File name:PGMB7666799210001PDF.IMG
Download: download sample
Signature RedLineStealer
File size:1'245'184 bytes
First seen:2020-10-20 06:27:51 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:sOpBGG2zyi6PsOIUGS2PSBn3fIG6Cd6SfoeX+euXomoo:V2wP1x0IgG6CsSfB
TLSH 77453982B05E315CF6EF02FBB4E9995452F31C4E19079E0C29A43FD17F27A815B906EA
Reporter abuse_ch
Tags:img RedLineStealer


Avatar
abuse_ch
Malspam distributing RedLineStealer:

HELO: usegreenco.com
Sending IP: 50.78.187.17
From: Lydia Yonkers<sales@usegreenco.com>
Subject: Quote Request
Attachment: PGMB7666799210001PDF.IMG (contains "PGMB7666799210001PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RedLineStealer

img be6102a7a30977132f9f8307f73d42031441f467a8717d5072fddca9ed53603e

(this sample)

  
Dropping
RedLineStealer
  
Delivery method
Distributed via e-mail attachment

Comments