General
-
Target
81cb68cc154f39f8e7e7446424c77684.bin
-
Size
540KB
-
Sample
230620-btawlahc69
-
MD5
df122d46f4a66a1923db365d1eade76f
-
SHA1
eac21d0e09419a4a5239b92beb5f3eac8b1aeac9
-
SHA256
077f443815f6df002fc3f473cd3afc6f49de84535e6135543c24f36d207543b7
-
SHA512
5b3fe815a0d108718cded013b91c8e2eee0b7e7b39816d364fcc2e61c0e5a5956cd2cffe0161c14eab6536c2fcd3b7513a2823f36cf8bc578d0c91821972d8e7
-
SSDEEP
12288:mA26LscORNdiJaQAlsVdanpoUlSjW/DSV0QQO7aawnWiS:NnLs5DdOqOV6prlvGee7aDWiS
Static task
static1
Behavioral task
behavioral1
Sample
164b7bcce9d3b679eda6efe23601b7d9a4871814a397e93966efda4fb05fe2b1.exe
Resource
win7-20230220-en
Malware Config
Extracted
redline
jason
83.97.73.129:19071
-
auth_value
87d1dc01751f148e9bec02edc71c5d94
Extracted
redline
duza
83.97.73.129:19071
-
auth_value
787a4e3bbc78fd525526de1098cb0621
Extracted
amadey
3.84
77.91.68.63/doma/net/index.php
Targets
-
-
Target
164b7bcce9d3b679eda6efe23601b7d9a4871814a397e93966efda4fb05fe2b1.exe
-
Size
584KB
-
MD5
81cb68cc154f39f8e7e7446424c77684
-
SHA1
ade46a8a8d42b63dfe759cfc6187b37e112b64a2
-
SHA256
164b7bcce9d3b679eda6efe23601b7d9a4871814a397e93966efda4fb05fe2b1
-
SHA512
3cf91da442398424a7edcfe650d4840a9a5d9e58af1340815e62b373c6f82c063d7611fda9b43d3fa37482599b527a4be92bfad9aeeadc13af87cb4135884f9c
-
SSDEEP
12288:pMrDy90t0LkKJC96PJgiVB8eFMS+L59rUphq0TI3HBTCm:mys04K86pt2UDZ83sm
-
RedLine
RedLine Stealer is a malware family written in C#, first appearing in early 2020.
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Executes dropped EXE
-
Loads dropped DLL
-
Adds Run key to start application
-
Checks installed software on the system
Looks up Uninstall key entries in the registry to enumerate software on the system.
-