MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e7e80971b8546cfa111076ee756302e04a81a01d5972043382fd18a22e8bf2be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RedLineStealer
Vendor detections: 16
| SHA256 hash: | e7e80971b8546cfa111076ee756302e04a81a01d5972043382fd18a22e8bf2be |
|---|---|
| SHA3-384 hash: | 9844158f2fff66c7c36a9e0f897119c849c177420ec43ea5de6bbb955580c7bc9fcd281d84b8facb596b0e125ded8941 |
| SHA1 hash: | 79a87c677810ee840676346a221781739a78dc80 |
| MD5 hash: | f08029e777d5c09f5786194b40e4d133 |
| humanhash: | august-july-jig-connecticut |
| File name: | file |
| Download: | download sample |
| Signature | RedLineStealer |
| File size: | 2'180'884 bytes |
| First seen: | 2023-02-11 12:25:16 UTC |
| Last seen: | 2023-02-12 14:26:40 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 00be6e6c4f9e287672c8301b72bdabf3 (116 x RedLineStealer, 70 x AsyncRAT, 55 x AgentTesla) |
| ssdeep | 49152:V5Or7fBDx4kFaNQ5m7tqcEdHO7LGQd+D7uEkujw:V5y7Jd4TQ5AqhdHO76CQCcjw |
| TLSH | T1AFA52342BF918972D5234D32066D9B5A60BCBE701F18DFAEB7EC2E6DDA30091B510763 |
| TrID | 32.2% (.EXE) Win64 Executable (generic) (10523/12/4) 20.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 15.4% (.EXE) Win16 NE executable (generic) (5038/12/1) 13.7% (.EXE) Win32 Executable (generic) (4505/5/1) 6.2% (.EXE) OS/2 Executable (generic) (2029/13) |
| File icon (PE): | |
| dhash icon | 9494b494d4aeaeac (832 x DCRat, 172 x RedLineStealer, 134 x CryptOne) |
| Reporter | |
| Tags: | exe RedLineStealer |
andretavare5
Sample downloaded from https://vk.com/doc10773776_659285988?hash=n9sdMubSywrezd9Sf4FkNUmxoREIJTaqRLqCqsWkwfX&dl=GEYDONZTG43TM:1676117577:zU9cjBiIMl85en9ybDslCs56Pj6cGZlVioMlyn8wg6s&api=1&no_preview=1#1Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
e3a4162f8febe90116fb9aa1e7335d8e352ee63fb8791a367a2bb105dcd89b47
4705cd053d069d919229c4bae91b6b527e217230030611def357f89dc19e7c1d
112228bb45cb316716980da0224845e0a9fa7d57674c2a0a799983edebdd8da7
659c330844f219ac0e3fd86bbeffc6d5d4756811854dbdc917698a9dbc27f498
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | MALWARE_Win_RedLine |
|---|---|
| Author: | ditekSHen |
| Description: | Detects RedLine infostealer |
| Rule name: | pdb_YARAify |
|---|---|
| Author: | @wowabiy314 |
| Description: | PDB |
| Rule name: | pe_imphash |
|---|
| Rule name: | Redline_Hunter |
|---|---|
| Author: | Potato |
| Description: | Unpacked RedLine Hunter |
| Rule name: | sfx_pdb |
|---|---|
| Author: | @razvialex |
| Description: | Detect interesting files containing sfx with pdb paths. |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Win32_Trojan_RedLineStealer |
|---|---|
| Author: | Netskope Threat Labs |
| Description: | Identifies RedLine Stealer samples |
| Reference: | deb95cae4ba26dfba536402318154405 |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.