MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 db66fc3c896813280ef60ba06dd03d7a7ba5b554ae4f18472168e868a4a6ccb3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedLineStealer


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: db66fc3c896813280ef60ba06dd03d7a7ba5b554ae4f18472168e868a4a6ccb3
SHA3-384 hash: 44be10152d7b7998be582be0c58d091ab5741901553d3657734a66bed5fe8fc4d839f4c11e1090546f668ee887163e80
SHA1 hash: 1709b65696a5c73a0f4acbac2c2e16be05bbfc54
MD5 hash: cbf937f2765f81fc3d24d433edc434ef
humanhash: oregon-oven-maine-purple
File name:89633589.exe
Download: download sample
Signature RedLineStealer
File size:44'340 bytes
First seen:2022-03-17 06:30:57 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:yH75lLfSG3uLLE87jt6aCmuwkHLuTRzNOfhwOdrurdXXFjsca6wuQ8oTRO8kwIbU:yH75BSG3Iomjt7Cmjlh+wRCEwuW08fcU
TLSH T19913F265BDF19E44076BD593F48062DF814ADCAE6EB8303D92C9B152494CAB47C1FA1C
Reporter adm1n_usa32
Tags:rar RedLineStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
193
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated replace.exe stealer
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Infostealer.RedLine
Status:
Malicious
First seen:
2022-03-03 14:38:31 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
25 of 42 (59.52%)
Threat level:
  5/5
Result
Malware family:
redline
Score:
  10/10
Tags:
family:redline botnet:firefox infostealer
Behaviour
RedLine
RedLine Payload
Malware Config
C2 Extraction:
45.77.42.218:1753
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RedLineStealer

rar db66fc3c896813280ef60ba06dd03d7a7ba5b554ae4f18472168e868a4a6ccb3

(this sample)

  
Delivery method
Distributed via web download

Comments