General

  • Target

    92373c134cbf9fc4a98ed7c80f244c8655b3852d3a1f1983fc4a7b3a00bf1370

  • Size

    493KB

  • Sample

    240627-22358axamd

  • MD5

    92c01627961859a84ffa633327c5d7f9

  • SHA1

    5b406c39f81f67e2b2e263137c7059718e4af007

  • SHA256

    92373c134cbf9fc4a98ed7c80f244c8655b3852d3a1f1983fc4a7b3a00bf1370

  • SHA512

    f31f9d45d7783441866faa0e684412040dd74c2878adfc6e5a874626e291b3e3cae7746cb62e2388d4183e615d9b919178fa409f2e12b3d0cf478c59450d3439

  • SSDEEP

    12288:AxJVyE3e2Uo4a3Tq7c85n93zxAdiFZ3wWxc:An93aOMn5n9DxOiFZ3T

Malware Config

Extracted

Family

redline

Botnet

LiveTraffic

C2

4.184.236.127:1110

Targets

    • Target

      92373c134cbf9fc4a98ed7c80f244c8655b3852d3a1f1983fc4a7b3a00bf1370

    • Size

      493KB

    • MD5

      92c01627961859a84ffa633327c5d7f9

    • SHA1

      5b406c39f81f67e2b2e263137c7059718e4af007

    • SHA256

      92373c134cbf9fc4a98ed7c80f244c8655b3852d3a1f1983fc4a7b3a00bf1370

    • SHA512

      f31f9d45d7783441866faa0e684412040dd74c2878adfc6e5a874626e291b3e3cae7746cb62e2388d4183e615d9b919178fa409f2e12b3d0cf478c59450d3439

    • SSDEEP

      12288:AxJVyE3e2Uo4a3Tq7c85n93zxAdiFZ3wWxc:An93aOMn5n9DxOiFZ3T

    • RedLine

      RedLine Stealer is a malware family written in C#, first appearing in early 2020.

    • RedLine payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks