Resubmissions
28-06-2024 08:16
240628-j6lgvssdjp 10Analysis
-
max time kernel
24s -
max time network
24s -
platform
windows7_x64 -
resource
win7-20240220-en -
resource tags
arch:x64arch:x86image:win7-20240220-enlocale:en-usos:windows7-x64system -
submitted
28-06-2024 08:16
Behavioral task
behavioral1
Sample
VPN.exe
Resource
win7-20240220-en
3 signatures
150 seconds
Behavioral task
behavioral2
Sample
VPN.exe
Resource
win10v2004-20240508-en
3 signatures
150 seconds
General
-
Target
VPN.exe
-
Size
426KB
-
MD5
26e59e7cf9436beec765505fdd4e0d46
-
SHA1
2e1e68a4dd9204d984d7e38ad7d39a903a9325ff
-
SHA256
e46a9e520de05d8eb717d49e9f3b9581692ec2690a5413f677aa8da435483284
-
SHA512
99e7acd86a277b60bb266729ce6062fdbc72c96382c012ba8576b246c79b36df0ac4d5615ca77b4fb1593d3bceffc788895bd3cb7d0a41c51829d55a0cca5c1e
-
SSDEEP
6144:U7LkMU8Plp9fUQToEpgRc+8D1x2kqqDJQbmIiMPWrpIlOa3OIcGUyI:0QMU2lvRTHp8c+02hqdQopIlOaeIop
Score
10/10
Malware Config
Signatures
-
RedLine
RedLine Stealer is a malware family written in C#, first appearing in early 2020.
-
RedLine payload 1 IoCs
Processes:
resource yara_rule behavioral1/memory/2280-1-0x0000000001110000-0x0000000001180000-memory.dmp family_redline -
Suspicious use of AdjustPrivilegeToken 41 IoCs
Processes:
VPN.exedescription pid process Token: SeDebugPrivilege 2280 VPN.exe Token: SeBackupPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeBackupPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeBackupPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeBackupPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeBackupPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeBackupPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeBackupPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeBackupPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe Token: SeSecurityPrivilege 2280 VPN.exe
Processes
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/2280-0-0x000000007443E000-0x000000007443F000-memory.dmpFilesize
4KB
-
memory/2280-1-0x0000000001110000-0x0000000001180000-memory.dmpFilesize
448KB
-
memory/2280-2-0x0000000074430000-0x0000000074B1E000-memory.dmpFilesize
6.9MB
-
memory/2280-3-0x0000000000390000-0x00000000003B0000-memory.dmpFilesize
128KB
-
memory/2280-4-0x000000007443E000-0x000000007443F000-memory.dmpFilesize
4KB
-
memory/2280-5-0x0000000074430000-0x0000000074B1E000-memory.dmpFilesize
6.9MB