🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dfb1f00592d6264a6bf3ad8b02187dfad62d1526fa5b32e667cd6bf884d4db85. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedLineStealer


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: dfb1f00592d6264a6bf3ad8b02187dfad62d1526fa5b32e667cd6bf884d4db85
SHA3-384 hash: 75bd374fba5f6f9c15b507e46fa6e00701b01007db61616c9c2c9e3bec9924f97517b196c1f235c396290c29441c2528
SHA1 hash: 184bab164050233a8d72541decbc4437f2122843
MD5 hash: 111ad964219b61522ae20b036702d096
humanhash: princess-cat-rugby-earth
File name:111ad964219b61522ae20b036702d096.exe
Download: download sample
Signature RedLineStealer
File size:979'968 bytes
First seen:2020-07-19 09:55:05 UTC
Last seen:2020-07-19 11:11:32 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 17a9323ceec7e60993fa67c3b5e8f267 (2 x RedLineStealer)
ssdeep 24576:VMw+l/xQjn5SbmU/HNK//mBHRujtOamjB:VMDlZQobh/wWN4jEam
TLSH 0B25233236C2C831DB5266308E56D6704EBFBC7819768AD33F846ADD4F353A18B0675A
Reporter abuse_ch
Tags:exe RedLineStealer


Avatar
abuse_ch
RedLineStealer C2:
http://45.67.229.57:81/IRemotePanel

Intelligence


File Origin
# of uploads :
2
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a custom TCP request
Launching a process
Creating a file
Connection attempt
Running batch commands
Using the Windows Management Instrumentation requests
Searching for the window
Forced system process termination
Launching a tool to kill processes
Unauthorized injection to a system process
Result
Threat name:
RedLine
Detection:
malicious
Classification:
troj.spyw.evad
Score:
80 / 100
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 247031 Sample: OQ5clujGVv.exe Startdate: 19/07/2020 Architecture: WINDOWS Score: 80 29 Multi AV Scanner detection for submitted file 2->29 31 Yara detected RedLine Stealer 2->31 33 Yara detected MSIL Crypter 2->33 35 2 other signatures 2->35 8 OQ5clujGVv.exe 1 2->8         started        process3 file4 25 C:\Users\user\AppData\...\OQ5clujGVv.exe.log, ASCII 8->25 dropped 37 Detected unpacking (overwrites its own PE header) 8->37 12 RegAsm.exe 15 2 8->12         started        15 RegAsm.exe 8->15         started        signatures5 process6 dnsIp7 27 45.67.229.57, 81 ALEXHOSTMD Moldova Republic of 12->27 17 cmd.exe 1 12->17         started        process8 process9 19 taskkill.exe 1 17->19         started        21 conhost.exe 17->21         started        23 choice.exe 1 17->23         started       
Threat name:
Win32.Ransomware.Sodinokibi
Status:
Malicious
First seen:
2020-07-18 21:42:48 UTC
AV detection:
26 of 29 (89.66%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Kills process with taskkill
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Program crash
Suspicious use of SetThreadContext
Suspicious use of NtCreateProcessExOtherParentProcess
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RedLineStealer

Executable exe dfb1f00592d6264a6bf3ad8b02187dfad62d1526fa5b32e667cd6bf884d4db85

(this sample)

  
Delivery method
Distributed via web download

Comments