General

  • Target

    CrackedSony_Vegas.exe

  • Size

    512KB

  • Sample

    240628-dfj88azgkk

  • MD5

    d016d5420cb03bfaa4241fa58c0da051

  • SHA1

    c679a55514a1cf8b1e6597d5fa2f3967e2c852ac

  • SHA256

    1dfd369a1525add9e113444ea99f88fcf0eb2b5228079d3747dc1dedd05aeb8e

  • SHA512

    648de2b28d3683ad96cade02aeaaf261e4d2c394a8018a173e2411b5c5ce120605853588c82c2aa98ea6f1679bc53dfbd5ff48ea4dcd811df53b2ee7b5e43613

  • SSDEEP

    12288:hZAzp54v/8/yqMea43KK+nxJrxydVEqdv0NVqbQpeIdi:h4O/8aqMTaXUnCv0NV0Qpl

Malware Config

Extracted

Family

redline

Botnet

@xcdaxfszx

C2

94.228.166.68:80

Targets

    • Target

      CrackedSony_Vegas.exe

    • Size

      512KB

    • MD5

      d016d5420cb03bfaa4241fa58c0da051

    • SHA1

      c679a55514a1cf8b1e6597d5fa2f3967e2c852ac

    • SHA256

      1dfd369a1525add9e113444ea99f88fcf0eb2b5228079d3747dc1dedd05aeb8e

    • SHA512

      648de2b28d3683ad96cade02aeaaf261e4d2c394a8018a173e2411b5c5ce120605853588c82c2aa98ea6f1679bc53dfbd5ff48ea4dcd811df53b2ee7b5e43613

    • SSDEEP

      12288:hZAzp54v/8/yqMea43KK+nxJrxydVEqdv0NVqbQpeIdi:h4O/8aqMTaXUnCv0NV0Qpl

    • RedLine

      RedLine Stealer is a malware family written in C#, first appearing in early 2020.

    • RedLine payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks