MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ebf6e0a476b8d884253e4c5ca8f5408f9d896e507494f7f1ca5bdaa08904a701. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RedLineStealer
Vendor detections: 11
| SHA256 hash: | ebf6e0a476b8d884253e4c5ca8f5408f9d896e507494f7f1ca5bdaa08904a701 |
|---|---|
| SHA3-384 hash: | 1b9951cf62f6e7c5177d4617eca076207d06d3f4c534ad39a578d59a4446a46c1474a46b9954aec7e41e413130901dc8 |
| SHA1 hash: | c1932d793664abe454dec07d17b8ce608d911a53 |
| MD5 hash: | f6658570028e2799e10754c7a80a161d |
| humanhash: | snake-network-social-saturn |
| File name: | file |
| Download: | download sample |
| Signature | RedLineStealer |
| File size: | 300'032 bytes |
| First seen: | 2023-12-06 06:31:56 UTC |
| Last seen: | 2023-12-06 13:15:16 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | b610b1ff2dfb4b84acc0b3fb1474f9f2 (10 x RedLineStealer, 2 x Vidar, 1 x LummaStealer) |
| ssdeep | 6144:JDeYkIr3muIKm4UmKbQbIF8IwzsXCYQy0f7z:JDedIr3muIsTrEF8cXCYJ0f7 |
| TLSH | T15054295A78D28A58CBF2D1FC0E0C665BE5BAB4393B940DFA32B135BD25B0D481B125CD |
| TrID | 45.5% (.EXE) Win16 NE executable (generic) (5038/12/1) 18.3% (.EXE) OS/2 Executable (generic) (2029/13) 18.0% (.EXE) Generic Win/DOS Executable (2002/3) 18.0% (.EXE) DOS Executable Generic (2000/1) |
| Reporter | |
| Tags: | exe RedLineStealer |
Intelligence
File Origin
USVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Unpacked files
fcb96d7f049cde3e1e82c7e9d4baa21e1cac81a1143de79e3dea03eef4af1f31
933e03068aefe5bfdadff629fff86a20dbccf7d961f0eca1297b084b5a1d26b5
b33ef15a2be180a13a45a7ffc78b715bc9588aa5e360b8dc7b28cdbc1a3ec19c
ebf6e0a476b8d884253e4c5ca8f5408f9d896e507494f7f1ca5bdaa08904a701
498eacbcf67486245f6a5ef60f9fbae419d2362f1eb783718648c34b85964632
2291965dc164bcb583972b38ed7624e00da9624fae8a8dbd923b291c0e16ce5c
483ade9aec3485169a01a388187e6e9875eaa7e78720c12c2d83daf6cf9e5e92
94aec8db65815948a4438a4cb9ed2dcedf30352098f5422dece6bbcb6fa44f70
c5948555709a13047c850a4500b95484ad67d528cd9afe42b3aae77c0a23137a
0efd7c24a813ce2e438805ff274f5ccfbd560d57865e3d989dda0ccb97b9ae95
53ae2b3c9be44058709ae883312d954fbdaf932b8416bebe266cd1b57cb5d7ab
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | INDICATOR_EXE_Packed_ConfuserEx |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables packed with ConfuserEx Mod |
| Rule name: | maldoc_find_kernel32_base_method_1 |
|---|---|
| Author: | Didier Stevens (https://DidierStevens.com) |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | pe_no_import_table |
|---|---|
| Description: | Detect pe file that no import table |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.