General

  • Target

    d01fe3dbc995e4b5b209631e5ae30b792d88a78676f695127f8a5db9bf59b48c

  • Size

    3.2MB

  • Sample

    240701-fsz7bazhmj

  • MD5

    e671a39ffdad8e262a45ef77d97a14f4

  • SHA1

    d451ad059bf52c22ff5de8ed7968991bbc169828

  • SHA256

    d01fe3dbc995e4b5b209631e5ae30b792d88a78676f695127f8a5db9bf59b48c

  • SHA512

    1352b04ffd300060e9abcc2880e53c4957a2b128b006603a20a08793a57b766b6579f5c53325b3fccc57db660fb7f14b93b7259e9fd0e1f2a78c53be026f3a20

  • SSDEEP

    49152:27vtm1geO0RDX0/BxBL6V2nM5PsKGPGatU8H+f7z0VBeNPswBr:27VmdOMeBvLa2nVKG+aZ20BSP3

Malware Config

Extracted

Family

redline

Botnet

YT&TEAM CLOUD

C2

185.172.128.33:8970

Targets

    • Target

      d01fe3dbc995e4b5b209631e5ae30b792d88a78676f695127f8a5db9bf59b48c

    • Size

      3.2MB

    • MD5

      e671a39ffdad8e262a45ef77d97a14f4

    • SHA1

      d451ad059bf52c22ff5de8ed7968991bbc169828

    • SHA256

      d01fe3dbc995e4b5b209631e5ae30b792d88a78676f695127f8a5db9bf59b48c

    • SHA512

      1352b04ffd300060e9abcc2880e53c4957a2b128b006603a20a08793a57b766b6579f5c53325b3fccc57db660fb7f14b93b7259e9fd0e1f2a78c53be026f3a20

    • SSDEEP

      49152:27vtm1geO0RDX0/BxBL6V2nM5PsKGPGatU8H+f7z0VBeNPswBr:27VmdOMeBvLa2nVKG+aZ20BSP3

    • RedLine

      RedLine Stealer is a malware family written in C#, first appearing in early 2020.

    • RedLine payload

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Collection

Data from Local System

2
T1005

Tasks