General

  • Target

    1240-356-0x00000000001A0000-0x00000000001F0000-memory.dmp

  • Size

    320KB

  • MD5

    8200bc039c97326447e895f667a16cfa

  • SHA1

    725501ac745c45997a9ee52f460376c5098281d6

  • SHA256

    117d4e2d772be77f156f505663cfc3a309ec375a14c3f4704c9b05392e302f87

  • SHA512

    463e54f5cabe137b44f7c0c86e20c1efdcc06042a573ef355182611a62768efdba830baae1aa70431503387b67a633d37a433dafe6fc42e77b801d9af661a3a4

  • SSDEEP

    3072:JqFFrqwIOGTNyHESF9D4XpeSQ2BXUhdT5TZboHIRcZqf7D34NeqiOLCbBO1:YBIOG6CpcdlTZEccZqf7DI3L

Score
10/10

Malware Config

Extracted

Family

redline

Botnet

newbuild

C2

185.215.113.67:40960

Signatures

  • RedLine payload 1 IoCs
  • Redline family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 1240-356-0x00000000001A0000-0x00000000001F0000-memory.dmp
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections