General

  • Target

    a23d1f07dfef6b5fda6381ecf6866746d624dbc1e510073d83f431124bf7d556.exe

  • Size

    913KB

  • Sample

    240630-bp9jcs1flb

  • MD5

    75d4b2f64dde3fc89adf5c39891111af

  • SHA1

    cad9e02a08dda87d0e2b88ac3c96ce1b1de5740e

  • SHA256

    a23d1f07dfef6b5fda6381ecf6866746d624dbc1e510073d83f431124bf7d556

  • SHA512

    462f1de721d5005b0d89168f7b5b1937b7b16f0edf99430104a60505b33a65eaf02f03b36b839e1b5633bc45eaf9f03bd5ccff121e7302f431d263a99d586203

  • SSDEEP

    24576:v4TiFiWXYwSv6ZNuzcB3mNO0Uoq0NDQDd:v4gbM0+k8p60Kd

Score
10/10

Malware Config

Extracted

Family

redline

Botnet

foz

C2

147.45.45.3:1912

Targets

    • Target

      a23d1f07dfef6b5fda6381ecf6866746d624dbc1e510073d83f431124bf7d556.exe

    • Size

      913KB

    • MD5

      75d4b2f64dde3fc89adf5c39891111af

    • SHA1

      cad9e02a08dda87d0e2b88ac3c96ce1b1de5740e

    • SHA256

      a23d1f07dfef6b5fda6381ecf6866746d624dbc1e510073d83f431124bf7d556

    • SHA512

      462f1de721d5005b0d89168f7b5b1937b7b16f0edf99430104a60505b33a65eaf02f03b36b839e1b5633bc45eaf9f03bd5ccff121e7302f431d263a99d586203

    • SSDEEP

      24576:v4TiFiWXYwSv6ZNuzcB3mNO0Uoq0NDQDd:v4gbM0+k8p60Kd

    Score
    10/10
    • RedLine

      RedLine Stealer is a malware family written in C#, first appearing in early 2020.

    • RedLine payload

    • Detects executables packed with SmartAssembly

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks