MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c0cde7089d6c966e87c1f3bb030296c5618011644e7afa90c0849852b8f8f946. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RedLineStealer
Vendor detections: 18
| SHA256 hash: | c0cde7089d6c966e87c1f3bb030296c5618011644e7afa90c0849852b8f8f946 |
|---|---|
| SHA3-384 hash: | d942ac5f31f04243c174fe58e1b9ceee441572821242355038b35f10c680083faf1cd14f39fce84fc4af2ba6b1987f23 |
| SHA1 hash: | 436b7d014b5e5b9319d845e9e9ebdff09c518833 |
| MD5 hash: | 58b1fe202df404578803fad452142337 |
| humanhash: | venus-helium-skylark-kilo |
| File name: | 58b1fe202df404578803fad452142337 |
| Download: | download sample |
| Signature | RedLineStealer |
| File size: | 796'672 bytes |
| First seen: | 2023-06-03 23:44:18 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 646167cce332c1c252cdcb1839e0cf48 (8'473 x RedLineStealer, 4'851 x Amadey, 290 x Smoke Loader) |
| ssdeep | 12288:XMrRy90VLBL88227l8lOR30QixhEpLXKSYsiJHga41G2ZtvTkDzA6AUv5:CyKl8X2ZgOR3XpOJY1G2ZtvwI6P5 |
| Threatray | 576 similar samples on MalwareBazaar |
| TLSH | T19A052352A6DD8422CCB223B058F702C71A39BDE1997C831F3B5AED1A1C725C4787676B |
| TrID | 70.4% (.CPL) Windows Control Panel Item (generic) (197083/11/60) 11.1% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 5.9% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5) 3.7% (.EXE) Win64 Executable (generic) (10523/12/4) 2.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) |
| File icon (PE): | |
| dhash icon | f8f0f4c8c8c8d8f0 (8'803 x RedLineStealer, 5'078 x Amadey, 288 x Smoke Loader) |
| Reporter | |
| Tags: | 32 exe RedLineStealer |
Intelligence
File Origin
FRVendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
1ac9a4c7e4f6008f099af1dc88b00df6304fdae5f27e8aade1d757b0a20eb31d
60c410e59852be7e8b91f73a67b1f70f1059a827921df73d3f4b0e062ec5cc2c
dced09999f640c0a63a7a60fbefc685b5891c67336d7c88ca79cb74ad49068de
bc88f0b6c0d5675f7ed9b30bc01cab6ec8d39e2e80ba0ee01caab557c679c84a
85655400afd7f45818453b92d14f5bf91e0734abc6cf94de3301bfa08e5c9f72
5330f5956dda9f4531291237e81b4ed6d9a7321a936eecda109c3bede5e89140
f845e9d8bad6f1cada0619c5f033c4e3cb7a5c3f55886eef9b2a0ebecd17df6a
c0cde7089d6c966e87c1f3bb030296c5618011644e7afa90c0849852b8f8f946
f61eba6af7d997de710cf9dab046d6eab1e536b5c9e5d987223dea0c66101ae7
60bb3e66aead037051760813844818c37fd1194d1a1e285e25fc0ded8201d56f
9e62f416edd15fa68e734e71379188ecb5edc80e8ebd37fb31acd2a58e05e7ac
9816209effe1c3adeda70b2e28cd87f4fd74c61aa9487dcf037f00eeab9f8393
cded1e1e75ce2d506ce7223d894e1726c9a9b17fb727172ba68cb94770702c56
94a8206d3c9d14e05831b13bbda45a5cdff9d4a32ba9d4fc17f6a01fd976b12e
1ac9a4c7e4f6008f099af1dc88b00df6304fdae5f27e8aade1d757b0a20eb31d
cdf833d90bc19a3de2de7e6725b60ee4c22fd62fa275ac218bae2fd72840e598
60c410e59852be7e8b91f73a67b1f70f1059a827921df73d3f4b0e062ec5cc2c
dced09999f640c0a63a7a60fbefc685b5891c67336d7c88ca79cb74ad49068de
bc88f0b6c0d5675f7ed9b30bc01cab6ec8d39e2e80ba0ee01caab557c679c84a
aa6215e591b97e76a40393ddf3175d1c46dbedab9ab1282b00b0b0d7cd24f71b
85655400afd7f45818453b92d14f5bf91e0734abc6cf94de3301bfa08e5c9f72
7becbd225d65be7dfda500f924bfb9070d068ecf3a34f6ba490fa0e1ba6497f0
33cb98a8ac1563b26ba8ff842135d488fa2d3cdbdb7de0f05ca4fcac63155ff7
74b102111f7d344a2c0cb7a77d73c968aff7f6a4b67c3457643d9a61c12d2aef
5330f5956dda9f4531291237e81b4ed6d9a7321a936eecda109c3bede5e89140
1ec5ecec7452379c2d19c80bb25effff79414ab2faf5c32d0dada42e1935be50
8ebdfe232d4dc11a79f43b420f9bd26e8d8e6c13dac0ddc1144c432c9e8c2db0
c0cde7089d6c966e87c1f3bb030296c5618011644e7afa90c0849852b8f8f946
e9bc1461c10946308fa4a0fb16f274108d80c351068ca95b5698a5a51d3b6de7
d7e1af2362cb778e3ba97174915da73fcd8fb4df49363fb09267eb28db27e77b
c4400514befd38c4870a6adba9e55b862bb249d791fae3cc6aae2666bacf0f04
60bb3e66aead037051760813844818c37fd1194d1a1e285e25fc0ded8201d56f
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_EXE_Packed_ConfuserEx |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables packed with ConfuserEx Mod |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefender |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables embedding registry key / value combination indicative of disabling Windows Defedner features |
| Rule name: | MALWARE_Win_RedLine |
|---|---|
| Author: | ditekSHen |
| Description: | Detects RedLine infostealer |
| Rule name: | pe_imphash |
|---|
| Rule name: | redline_stealer_1 |
|---|---|
| Author: | Nikolaos 'n0t' Totosis |
| Description: | RedLine Stealer Payload |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.url : hxxp://77.91.124.20/DSC01491/foto124.exe