MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d8422e68f6bc3b3564efac25e147168494be5cacfb3d1695945f9935fb1045a4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedLineStealer


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: d8422e68f6bc3b3564efac25e147168494be5cacfb3d1695945f9935fb1045a4
SHA3-384 hash: c3a9e0cfcbf6ee513b307ddb4cf735576095f9eb8932365b68d1b4e4b74a6780cbd1cfba08bd82b0dfbbaf42d69aac74
SHA1 hash: c4f129b2829c1bf66df3a2b15dd999aadcc4abb7
MD5 hash: bdbe710ad7a14be139d1a51c1187f1d7
humanhash: neptune-early-november-july
File name:bdbe710ad7a14be139d1a51c1187f1d7.exe
Download: download sample
Signature RedLineStealer
File size:300'032 bytes
First seen:2021-10-07 08:58:56 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 01c64e8a0bf942eae9e15adaebb52144 (4 x RaccoonStealer, 2 x ArkeiStealer, 2 x Smoke Loader)
ssdeep 6144:/Ry7rQW58XN54l6TJsGK3pFCMP1oijNdEWCOY5z2Rr:pOrj58XN5HJspCwi6epOYZ2R
Threatray 2'404 similar samples on MalwareBazaar
TLSH T1BD54DF1131F0C531F7A75A3049368AA54A7B7CB69C70A58F2BE4266EDF722D29B24307
File icon (PE):PE icon
dhash icon 167248d448730ecc (1 x RedLineStealer)
Reporter abuse_ch
Tags:exe RedLineStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
131
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
bdbe710ad7a14be139d1a51c1187f1d7.exe
Verdict:
Malicious activity
Analysis date:
2021-10-07 09:11:08 UTC
Tags:
trojan rat redline

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Launching a service
Using the Windows Management Instrumentation requests
Reading critical registry keys
Connection attempt to an infection source
Sending a TCP request to an infection source
Query of malicious DNS domain
Stealing user critical data
Result
Threat name:
RedLine
Detection:
malicious
Classification:
troj.spyw.evad
Score:
92 / 100
Signature
Connects to many ports of the same IP (likely port scanning)
Detected unpacking (overwrites its own PE header)
Found many strings related to Crypto-Wallets (likely being stolen)
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Yara detected RedLine Stealer
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.RedLineStealer
Status:
Malicious
First seen:
2021-10-07 08:59:10 UTC
AV detection:
22 of 45 (48.89%)
Threat level:
  5/5
Result
Malware family:
redline
Score:
  10/10
Tags:
family:redline botnet:build discovery infostealer spyware stealer
Behaviour
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Reads user/profile data of web browsers
RedLine
RedLine Payload
Malware Config
C2 Extraction:
185.244.182.136:51832
Unpacked files
SH256 hash:
d69488503bf512756faa49354372bb35aed5ba2a9dc3bd181554d3c273d65995
MD5 hash:
6ad3c76df4cba6c036ca74ed464f581e
SHA1 hash:
4472891e860d86c81d3759682e16caaa638df034
SH256 hash:
15d14a003f8b6be1ee658007edc8e38e69656893ed9daf7c0b4949873d7bb460
MD5 hash:
2aff3249b907d9fef2d9c3be2a7a3d5c
SHA1 hash:
381dc99ef44d498d3116922ae6171d31df38725b
SH256 hash:
063d9ee6c86d83556a6aed308514fb317d9459be3b02ff854d4b45000c17e417
MD5 hash:
44157ec3ff1419c651ef4aaaf7c9cff3
SHA1 hash:
207f0b23450643d12ae5f66239e54b6bb9a2448a
SH256 hash:
d8422e68f6bc3b3564efac25e147168494be5cacfb3d1695945f9935fb1045a4
MD5 hash:
bdbe710ad7a14be139d1a51c1187f1d7
SHA1 hash:
c4f129b2829c1bf66df3a2b15dd999aadcc4abb7
Malware family:
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RedLineStealer

Executable exe d8422e68f6bc3b3564efac25e147168494be5cacfb3d1695945f9935fb1045a4

(this sample)

  
Delivery method
Distributed via web download

Comments