General

  • Target

    0x000a000000014365-58.dat

  • Size

    173KB

  • MD5

    f13f64ae964a654035bddbbc3c25a2b7

  • SHA1

    82de0ca6f8ddd5c9c8340773847270ce6c0c41cd

  • SHA256

    6afed915967fee4ea0955776cf95d85d9b7309c37f1e9ca8ca921c55e04cf3d0

  • SHA512

    852ad609e495537b39fe5938eb8b9e20f6e9f1a44cd34612693c1fa9d1e24df57bf4f9932f84f194a90db6f18fabf2bc3a307b31871ce3690702c98f1e5932de

  • SSDEEP

    3072:HWKe1kiJtebRavRJxNv4nFkbgWoHn8e8hI:HWcUt1RZbgWoHn

Score
10/10

Malware Config

Extracted

Family

redline

Botnet

duza

C2

83.97.73.129:19071

Attributes
  • auth_value

    787a4e3bbc78fd525526de1098cb0621

Signatures

  • Redline family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 0x000a000000014365-58.dat
    .exe windows x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections