General
-
Target
d4c1ec7a4e97f271de8f43a7c42c0309.bin
-
Size
581KB
-
Sample
230620-b5wmfaae3t
-
MD5
fd8ef958e63aeb14f7e97ab7ffd6d2a7
-
SHA1
2aba3a5217c4ef02f8d485d44421929e46b686c5
-
SHA256
82b645f2e2f82a70c585bb70f35e7fa3cb96a8202a3428e925a59fbe46eaaf2e
-
SHA512
4768440fc6339850eada3affb24deed60dbe8d000fb03e5c68a0fd5c1910c2a1c4b98a6c037806c8b93b5ae2687baa0e4dd60ab772d35fcefa554e643ea3f288
-
SSDEEP
12288:zUpLc53XsvtAlpig9sZn1ol7IA0Q1s/Hb2Mfm8Eg8c:ec53Ovn12UNp72YV9
Static task
static1
Behavioral task
behavioral1
Sample
7a681f53ed33db87b62ae308fe287a5626758529ea7696c91b42fb5b8c97a165.exe
Resource
win7-20230220-en
Malware Config
Extracted
redline
jason
83.97.73.129:19071
-
auth_value
87d1dc01751f148e9bec02edc71c5d94
Extracted
redline
duza
83.97.73.129:19071
-
auth_value
787a4e3bbc78fd525526de1098cb0621
Extracted
amadey
3.84
77.91.68.63/doma/net/index.php
Targets
-
-
Target
7a681f53ed33db87b62ae308fe287a5626758529ea7696c91b42fb5b8c97a165.exe
-
Size
625KB
-
MD5
d4c1ec7a4e97f271de8f43a7c42c0309
-
SHA1
e1f5ed783f5cddd76ddf8baef6d01c70671d29f4
-
SHA256
7a681f53ed33db87b62ae308fe287a5626758529ea7696c91b42fb5b8c97a165
-
SHA512
9bac89a31934431355b87ae5e9acebeea86a40d6ba0fd19e7ab0ac283cdfb923fd1765bc5621be034ac1888329a3097cb6b5f7cfba287075c0e244d66fc35151
-
SSDEEP
12288:rMrty905aorAhsz077vp78UIi7h75qzrOrKH5FigN5wtbfr:uysZAhVd7WO72U25eRr
-
RedLine
RedLine Stealer is a malware family written in C#, first appearing in early 2020.
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Executes dropped EXE
-
Loads dropped DLL
-
Adds Run key to start application
-
Checks installed software on the system
Looks up Uninstall key entries in the registry to enumerate software on the system.
-