General

  • Target

    StrangeOstrumV2.exe

  • Size

    356KB

  • Sample

    240701-cmplvashnb

  • MD5

    d16418fbada8f2a6f41b58b0666c2bda

  • SHA1

    918047757fafd633f111fc9c47b90e5611341aab

  • SHA256

    6d8fc5485484ff3a0efee3b5961dd07882f7ab55b472b5884a0a5199ca26f68e

  • SHA512

    0bc4daeb51b6596e248e861b3c293a0d58ffeb46746dd16db42c337fb3b415648d79975af298ea0043393f0063ff43b938ab6097690c756723ce26ef04725fd1

  • SSDEEP

    6144:XYLVGAk69fIESPUSyvC3WvwKP2XYvy07e1hQRpsJQlGNc8NJRxx+G8WM1ofwipTs:XrAk69fNSGpMYP7uh2sJQlGNc8NJRxxE

Score
10/10

Malware Config

Extracted

Family

redline

C2

185.196.9.26:6302

Targets

    • Target

      StrangeOstrumV2.exe

    • Size

      356KB

    • MD5

      d16418fbada8f2a6f41b58b0666c2bda

    • SHA1

      918047757fafd633f111fc9c47b90e5611341aab

    • SHA256

      6d8fc5485484ff3a0efee3b5961dd07882f7ab55b472b5884a0a5199ca26f68e

    • SHA512

      0bc4daeb51b6596e248e861b3c293a0d58ffeb46746dd16db42c337fb3b415648d79975af298ea0043393f0063ff43b938ab6097690c756723ce26ef04725fd1

    • SSDEEP

      6144:XYLVGAk69fIESPUSyvC3WvwKP2XYvy07e1hQRpsJQlGNc8NJRxx+G8WM1ofwipTs:XrAk69fNSGpMYP7uh2sJQlGNc8NJRxxE

    Score
    10/10
    • RedLine

      RedLine Stealer is a malware family written in C#, first appearing in early 2020.

    • RedLine payload

    • Loads dropped DLL

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks