General
-
Target
7f6d418a109af57826bd328c3df57bd9.bin
-
Size
540KB
-
Sample
230620-bs6xmsad6s
-
MD5
b2b7e7d6fdf6bb0313a7e945531e058f
-
SHA1
f18ee9c2fe426a3ab078f2874042f9e82ee264a0
-
SHA256
c3f52dd4d7eeddf2791c84636e3e25d6e2c3557bb4a89f281d5c71066dcd94e0
-
SHA512
50e0b78f945496e7a1b59c81d72e8ec6a3486f541565ba5a2c0fb297fdb2bbb3404ad78bb4b8243118d7623849a5b7ca14292d91fcfa62428e56df5084f15580
-
SSDEEP
12288:ASS+Q08q32xElmtPlbt1dCXSV18dPBx2pmiRkCOphAPiXOmW:ASbQzq3+EAnD8sa9rCmiR3lKXOmW
Static task
static1
Behavioral task
behavioral1
Sample
58ea163a29ce693a1d145dc052090e346d8f4c98ef984865084814e8fc75c7c1.exe
Resource
win7-20230220-en
Malware Config
Extracted
redline
jason
83.97.73.129:19071
-
auth_value
87d1dc01751f148e9bec02edc71c5d94
Extracted
redline
duza
83.97.73.129:19071
-
auth_value
787a4e3bbc78fd525526de1098cb0621
Extracted
amadey
3.84
77.91.68.63/doma/net/index.php
Targets
-
-
Target
58ea163a29ce693a1d145dc052090e346d8f4c98ef984865084814e8fc75c7c1.exe
-
Size
583KB
-
MD5
7f6d418a109af57826bd328c3df57bd9
-
SHA1
512f2aa22121244e0f924f7eb4ad5c392f01d741
-
SHA256
58ea163a29ce693a1d145dc052090e346d8f4c98ef984865084814e8fc75c7c1
-
SHA512
486f5faadfc37692b6faf2c0d8c0b0a9bdb0a30ed4744786955fba44e23d81e1e582c3ac1bb705351f30df270ca11f05515b7d967dbcd8beccd3874802bfa1ea
-
SSDEEP
12288:kMrdy90Lpp3mlcMH0xTGhJWx4aS75v/hnJyS+cLgvc2cwGDR:By330JG/j575XhJyIjL7
-
RedLine
RedLine Stealer is a malware family written in C#, first appearing in early 2020.
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Executes dropped EXE
-
Loads dropped DLL
-
Adds Run key to start application
-
Checks installed software on the system
Looks up Uninstall key entries in the registry to enumerate software on the system.
-