General

  • Target

    BrightVPN-Setup-1.422.634-fb2e56b7.exe

  • Size

    1.8MB

  • Sample

    240628-kan4jszcpg

  • MD5

    1ca12c1ddbbc4547fef82491c23913f4

  • SHA1

    e2e057825a10e8ba97c0185f7c01da6b449f7023

  • SHA256

    2b1b91075512986f811a419c62fe115d5cc8880d8126b9f94386861f82b2c995

  • SHA512

    476a0404a1a70dd99bc4f15432c653d6734cf67f7fda8282010791430c0cc9e496f68a1b29089fbc772a6dc22cb3c63b1cf09d0a9dd9bd5edca34a051c789d81

  • SSDEEP

    24576:+TbBv5rUlISzVzCZ4Ebn64Aez4qz+2Sl3UWAeVIk5P4x0C6Rqi4NODM5MFdFmCht:ABRSzVzWbn6LqehUiP4xLIZ4IPDhmh6

Score
10/10

Malware Config

Targets

    • Target

      BrightVPN-Setup-1.422.634-fb2e56b7.exe

    • Size

      1.8MB

    • MD5

      1ca12c1ddbbc4547fef82491c23913f4

    • SHA1

      e2e057825a10e8ba97c0185f7c01da6b449f7023

    • SHA256

      2b1b91075512986f811a419c62fe115d5cc8880d8126b9f94386861f82b2c995

    • SHA512

      476a0404a1a70dd99bc4f15432c653d6734cf67f7fda8282010791430c0cc9e496f68a1b29089fbc772a6dc22cb3c63b1cf09d0a9dd9bd5edca34a051c789d81

    • SSDEEP

      24576:+TbBv5rUlISzVzCZ4Ebn64Aez4qz+2Sl3UWAeVIk5P4x0C6Rqi4NODM5MFdFmCht:ABRSzVzWbn6LqehUiP4xLIZ4IPDhmh6

    Score
    10/10
    • RedLine

      RedLine Stealer is a malware family written in C#, first appearing in early 2020.

    • RedLine payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks