General

  • Target

    1da56a5f2bbdc5215305e5e397bd3ed926f44520e145aa7bf2e6785b33f381e6.exe

  • Size

    516KB

  • Sample

    240628-bjxmlsvfrl

  • MD5

    0c341e00d3027a4a6ea5438f37f06677

  • SHA1

    60717e853262eeae53ccc87da6940adb73aa9ce2

  • SHA256

    1da56a5f2bbdc5215305e5e397bd3ed926f44520e145aa7bf2e6785b33f381e6

  • SHA512

    2209fc9c45f7f985250f0aa31229a9c75e72ad6619e38474717cb8b041f59f43b2aa66a125268c41dafe80508588a1bc5a2f87fe69b5b0acdbb47338da36ab46

  • SSDEEP

    12288:hPyRu80u5xzuq1GFsJl6pzndWxkgzPxnFYO:Byyu3zXSNd/gz7

Malware Config

Targets

    • Target

      1da56a5f2bbdc5215305e5e397bd3ed926f44520e145aa7bf2e6785b33f381e6.exe

    • Size

      516KB

    • MD5

      0c341e00d3027a4a6ea5438f37f06677

    • SHA1

      60717e853262eeae53ccc87da6940adb73aa9ce2

    • SHA256

      1da56a5f2bbdc5215305e5e397bd3ed926f44520e145aa7bf2e6785b33f381e6

    • SHA512

      2209fc9c45f7f985250f0aa31229a9c75e72ad6619e38474717cb8b041f59f43b2aa66a125268c41dafe80508588a1bc5a2f87fe69b5b0acdbb47338da36ab46

    • SSDEEP

      12288:hPyRu80u5xzuq1GFsJl6pzndWxkgzPxnFYO:Byyu3zXSNd/gz7

    • RedLine

      RedLine Stealer is a malware family written in C#, first appearing in early 2020.

    • RedLine payload

    • Detects executables packed with Babel

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

Collection

Data from Local System

1
T1005

Tasks