MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc79cf72d90edccbc4fda4e80ac4a9ea04962bfab100f03165066c4f04008176. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedLineStealer


Vendor detections: 15


Intelligence 15 IOCs YARA 2 File information Comments

SHA256 hash: cc79cf72d90edccbc4fda4e80ac4a9ea04962bfab100f03165066c4f04008176
SHA3-384 hash: d0258763ee289b53fd42f54db2d74691218aad1bc93b28d60ffe28a4f10b864849aa87a820a61782efdad98a46414c8e
SHA1 hash: 783daa73622f5c35fc0e9bf64800e4308389f59f
MD5 hash: 9ff0d3a6d7c3983c9f6b3356848567ed
humanhash: six-wisconsin-diet-princess
File name:9ff0d3a6d7c3983c9f6b3356848567ed.exe
Download: download sample
Signature RedLineStealer
File size:179'200 bytes
First seen:2023-01-19 14:35:46 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 04b805471fc62700f7dfdfc04af9df90 (3 x RedLineStealer, 2 x Smoke Loader, 1 x Rhadamanthys)
ssdeep 3072:DXERTud9G2bdL79q+El5gJXYUQUSyVVyohL2nisa5sLNUEGf:7AS9A+EIJGUQohLii4Lz
Threatray 4'281 similar samples on MalwareBazaar
TLSH T10B04DF2272D3C073C05744315831DBE12A7BB87271B1999B37A81BBD9FB43D1AB6A346
TrID 37.3% (.EXE) Win64 Executable (generic) (10523/12/4)
17.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
16.0% (.EXE) Win32 Executable (generic) (4505/5/1)
7.3% (.ICL) Windows Icons Library (generic) (2059/9)
7.2% (.EXE) OS/2 Executable (generic) (2029/13)
File icon (PE):PE icon
dhash icon 00080c210b0e3322 (1 x RedLineStealer)
Reporter abuse_ch
Tags:exe RedLineStealer


Avatar
abuse_ch
RedLineStealer C2:
89.163.146.82:25313