Analysis

  • max time kernel
    103s
  • max time network
    105s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240611-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system
  • submitted
    28-06-2024 13:40

General

  • Target

    SivaV2.exe

  • Size

    356KB

  • MD5

    f9742d4c0fd17e9bb51b38a4014ac254

  • SHA1

    4b2236586231f271e3296ae4e5a9758f64791604

  • SHA256

    0a9ecee73d6b9634f10e72bbce2bbab8661ad29da393bc309e4f20cf5fd3f9e2

  • SHA512

    bcf8c4597c3a2baef024e5fd4f582a8d6fa08ba33014e298954743615945cae284407dc8dd101dead4715edaec0da0304356f17dfeba2f659dfbfe95c4659ac7

  • SSDEEP

    6144:D/YJ0Pw7T3cAkIRPxEzbC0PwwZZE97TQSdx63MVxDlVyxiqT5N9kTbTtlA5rB0nm:7YJOw3aePxSbrPS5x63MVxDlVyxiqT5p

Malware Config

Extracted

Family

redline

C2

185.196.9.26:6302

Signatures

  • RedLine

    RedLine Stealer is a malware family written in C#, first appearing in early 2020.

  • RedLine payload 1 IoCs
  • Loads dropped DLL 1 IoCs
  • Accesses cryptocurrency files/wallets, possible credential harvesting 2 TTPs
  • Suspicious use of SetThreadContext 1 IoCs
  • Suspicious behavior: EnumeratesProcesses 3 IoCs
  • Suspicious use of AdjustPrivilegeToken 1 IoCs
  • Suspicious use of WriteProcessMemory 8 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\SivaV2.exe
    "C:\Users\Admin\AppData\Local\Temp\SivaV2.exe"
    1⤵
    • Loads dropped DLL
    • Suspicious use of SetThreadContext
    • Suspicious use of WriteProcessMemory
    PID:3680
    • C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
      "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"
      2⤵
      • Suspicious behavior: EnumeratesProcesses
      • Suspicious use of AdjustPrivilegeToken
      PID:1864

Network

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Collection

Data from Local System

1
T1005

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\Roaming\d3d9.dll
    Filesize

    418KB

    MD5

    ffa49acb11fb9aaa1ab804cae9491af8

    SHA1

    a1c5ab231195ca006a530881a20457cacc60c49e

    SHA256

    7fcee0a2c857711e9e195a8e17c3540dcb25bb9147f47e8b19d276b8a05c613d

    SHA512

    ee509d1afc521f970b5bf4d70a4a2ef7a41dba367955f1a42b7d1a87f03a47d4802ac6bcd144c876a3fcec2de624e35e88116df0bd1f6582fb570ed940d7a185

  • memory/1864-21-0x0000000004EA0000-0x0000000004EDC000-memory.dmp
    Filesize

    240KB

  • memory/1864-23-0x0000000005750000-0x00000000057B6000-memory.dmp
    Filesize

    408KB

  • memory/1864-18-0x0000000005C70000-0x0000000006288000-memory.dmp
    Filesize

    6.1MB

  • memory/1864-9-0x0000000000360000-0x00000000003B0000-memory.dmp
    Filesize

    320KB

  • memory/1864-17-0x0000000004D60000-0x0000000004D6A000-memory.dmp
    Filesize

    40KB

  • memory/1864-28-0x0000000074F40000-0x00000000756F0000-memory.dmp
    Filesize

    7.7MB

  • memory/1864-13-0x0000000074F40000-0x00000000756F0000-memory.dmp
    Filesize

    7.7MB

  • memory/1864-14-0x00000000050A0000-0x0000000005644000-memory.dmp
    Filesize

    5.6MB

  • memory/1864-19-0x0000000004F10000-0x000000000501A000-memory.dmp
    Filesize

    1.0MB

  • memory/1864-16-0x0000000074F40000-0x00000000756F0000-memory.dmp
    Filesize

    7.7MB

  • memory/1864-26-0x0000000007180000-0x00000000076AC000-memory.dmp
    Filesize

    5.2MB

  • memory/1864-25-0x0000000006880000-0x0000000006A42000-memory.dmp
    Filesize

    1.8MB

  • memory/1864-15-0x0000000004BD0000-0x0000000004C62000-memory.dmp
    Filesize

    584KB

  • memory/1864-20-0x0000000004E40000-0x0000000004E52000-memory.dmp
    Filesize

    72KB

  • memory/1864-24-0x0000000006660000-0x00000000066B0000-memory.dmp
    Filesize

    320KB

  • memory/1864-22-0x0000000005020000-0x000000000506C000-memory.dmp
    Filesize

    304KB

  • memory/3680-2-0x0000000002C70000-0x0000000002C76000-memory.dmp
    Filesize

    24KB

  • memory/3680-0-0x0000000074F4E000-0x0000000074F4F000-memory.dmp
    Filesize

    4KB

  • memory/3680-1-0x0000000000830000-0x0000000000892000-memory.dmp
    Filesize

    392KB

  • memory/3680-29-0x0000000074F40000-0x00000000756F0000-memory.dmp
    Filesize

    7.7MB

  • memory/3680-12-0x0000000074F40000-0x00000000756F0000-memory.dmp
    Filesize

    7.7MB

  • memory/3680-11-0x00000000779E1000-0x0000000077B01000-memory.dmp
    Filesize

    1.1MB