General

  • Target

    SivaV2.exe

  • Size

    356KB

  • Sample

    240628-qyx91svfpq

  • MD5

    f9742d4c0fd17e9bb51b38a4014ac254

  • SHA1

    4b2236586231f271e3296ae4e5a9758f64791604

  • SHA256

    0a9ecee73d6b9634f10e72bbce2bbab8661ad29da393bc309e4f20cf5fd3f9e2

  • SHA512

    bcf8c4597c3a2baef024e5fd4f582a8d6fa08ba33014e298954743615945cae284407dc8dd101dead4715edaec0da0304356f17dfeba2f659dfbfe95c4659ac7

  • SSDEEP

    6144:D/YJ0Pw7T3cAkIRPxEzbC0PwwZZE97TQSdx63MVxDlVyxiqT5N9kTbTtlA5rB0nm:7YJOw3aePxSbrPS5x63MVxDlVyxiqT5p

Malware Config

Extracted

Family

redline

C2

185.196.9.26:6302

Targets

    • Target

      SivaV2.exe

    • Size

      356KB

    • MD5

      f9742d4c0fd17e9bb51b38a4014ac254

    • SHA1

      4b2236586231f271e3296ae4e5a9758f64791604

    • SHA256

      0a9ecee73d6b9634f10e72bbce2bbab8661ad29da393bc309e4f20cf5fd3f9e2

    • SHA512

      bcf8c4597c3a2baef024e5fd4f582a8d6fa08ba33014e298954743615945cae284407dc8dd101dead4715edaec0da0304356f17dfeba2f659dfbfe95c4659ac7

    • SSDEEP

      6144:D/YJ0Pw7T3cAkIRPxEzbC0PwwZZE97TQSdx63MVxDlVyxiqT5N9kTbTtlA5rB0nm:7YJOw3aePxSbrPS5x63MVxDlVyxiqT5p

    • RedLine

      RedLine Stealer is a malware family written in C#, first appearing in early 2020.

    • RedLine payload

    • Loads dropped DLL

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Collection

Data from Local System

1
T1005

Tasks