Overview
overview
10Static
static
10Redline_20_2.zip
windows7-x64
1Redline_20_2.zip
windows10-2004-x64
1Redline_20...er.exe
windows7-x64
1Redline_20...er.exe
windows10-2004-x64
1Redline_20...config
windows7-x64
3Redline_20...config
windows10-2004-x64
3Redline_20...er.pdb
windows7-x64
3Redline_20...er.pdb
windows10-2004-x64
3Redline_20...db.dll
windows7-x64
1Redline_20...db.dll
windows10-2004-x64
1Redline_20...db.pdb
windows7-x64
3Redline_20...db.pdb
windows10-2004-x64
3Redline_20...db.dll
windows7-x64
1Redline_20...db.dll
windows10-2004-x64
1Redline_20...db.pdb
windows7-x64
3Redline_20...db.pdb
windows10-2004-x64
3Redline_20...ks.dll
windows7-x64
1Redline_20...ks.dll
windows10-2004-x64
1Redline_20...ks.pdb
windows7-x64
3Redline_20...ks.pdb
windows10-2004-x64
3Redline_20...il.dll
windows7-x64
1Redline_20...il.dll
windows10-2004-x64
1Redline_20...il.pdb
windows7-x64
3Redline_20...il.pdb
windows10-2004-x64
3Redline_20...ub.exe
windows7-x64
10Redline_20...ub.exe
windows10-2004-x64
10Redline_20...st.exe
windows7-x64
1Redline_20...st.exe
windows10-2004-x64
1Redline_20...config
windows7-x64
3Redline_20...config
windows10-2004-x64
3Redline_20...CF.dll
windows7-x64
1Redline_20...CF.dll
windows10-2004-x64
1Analysis
-
max time kernel
121s -
max time network
126s -
platform
windows7_x64 -
resource
win7-20240611-en -
resource tags
arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system -
submitted
02-07-2024 08:26
Behavioral task
behavioral1
Sample
Redline_20_2.zip
Resource
win7-20240220-en
Behavioral task
behavioral2
Sample
Redline_20_2.zip
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Kurome.Builder.exe
Resource
win7-20240508-en
Behavioral task
behavioral4
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Kurome.Builder.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral5
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Kurome.Builder.exe.config
Resource
win7-20240419-en
Behavioral task
behavioral6
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Kurome.Builder.exe.config
Resource
win10v2004-20240226-en
Behavioral task
behavioral7
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Kurome.Builder.pdb
Resource
win7-20240221-en
Behavioral task
behavioral8
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Kurome.Builder.pdb
Resource
win10v2004-20240611-en
Behavioral task
behavioral9
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Mdb.dll
Resource
win7-20240508-en
Behavioral task
behavioral10
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Mdb.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral11
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Mdb.pdb
Resource
win7-20240611-en
Behavioral task
behavioral12
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Mdb.pdb
Resource
win10v2004-20240508-en
Behavioral task
behavioral13
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Pdb.dll
Resource
win7-20240611-en
Behavioral task
behavioral14
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Pdb.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral15
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Pdb.pdb
Resource
win7-20240611-en
Behavioral task
behavioral16
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Pdb.pdb
Resource
win10v2004-20240611-en
Behavioral task
behavioral17
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Rocks.dll
Resource
win7-20231129-en
Behavioral task
behavioral18
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Rocks.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral19
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Rocks.pdb
Resource
win7-20240419-en
Behavioral task
behavioral20
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Rocks.pdb
Resource
win10v2004-20240508-en
Behavioral task
behavioral21
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.dll
Resource
win7-20240508-en
Behavioral task
behavioral22
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral23
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.pdb
Resource
win7-20240220-en
Behavioral task
behavioral24
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.pdb
Resource
win10v2004-20240508-en
Behavioral task
behavioral25
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/stub.exe
Resource
win7-20240508-en
Behavioral task
behavioral26
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/stub.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral27
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Host/Kurome.Host.exe
Resource
win7-20240611-en
Behavioral task
behavioral28
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Host/Kurome.Host.exe
Resource
win10v2004-20240226-en
Behavioral task
behavioral29
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Host/Kurome.Host.exe.config
Resource
win7-20231129-en
Behavioral task
behavioral30
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Host/Kurome.Host.exe.config
Resource
win10v2004-20240508-en
Behavioral task
behavioral31
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Host/Kurome.WCF.dll
Resource
win7-20240419-en
Behavioral task
behavioral32
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Host/Kurome.WCF.dll
Resource
win10v2004-20240611-en
General
-
Target
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Mdb.pdb
-
Size
18KB
-
MD5
073d9d6c9c71f66151b84a376ede4a9d
-
SHA1
2101dfe180528b00af6596cc04af7d6d70eae943
-
SHA256
891251514aa16f94485263c52faba51bb5bb3495b9fad382c74f6c9da78718dd
-
SHA512
4135cbce4eebf255b143f3ef03525a0f9e0322a7a682584ec87b025aeaeb9c2d7294394bc9aacc87313047ac71c5b3b83429a93af4f4549f596c5a32b6587779
-
SSDEEP
384:uqgdBvkE/zECNLuSW5oAs+yj7tVcV6uGK2tmrNvnmBXizuXNYpkUkBqukOVOtq/y:NABvkE/znuSEMj7t++F9BquYKoZ
Malware Config
Signatures
-
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Modifies registry class 9 IoCs
Processes:
rundll32.exedescription ioc process Key created \REGISTRY\USER\S-1-5-21-2812790648-3157963462-487717889-1000_CLASSES\.pdb rundll32.exe Set value (str) \REGISTRY\USER\S-1-5-21-2812790648-3157963462-487717889-1000_CLASSES\.pdb\ = "pdb_auto_file" rundll32.exe Key created \REGISTRY\USER\S-1-5-21-2812790648-3157963462-487717889-1000_CLASSES\pdb_auto_file\shell\Read rundll32.exe Key created \REGISTRY\USER\S-1-5-21-2812790648-3157963462-487717889-1000_CLASSES\pdb_auto_file\shell rundll32.exe Set value (str) \REGISTRY\USER\S-1-5-21-2812790648-3157963462-487717889-1000_CLASSES\pdb_auto_file\shell\Read\command\ = "\"C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\AcroRd32.exe\" \"%1\"" rundll32.exe Key created \REGISTRY\USER\S-1-5-21-2812790648-3157963462-487717889-1000_Classes\Local Settings rundll32.exe Key created \REGISTRY\USER\S-1-5-21-2812790648-3157963462-487717889-1000_CLASSES\pdb_auto_file rundll32.exe Set value (str) \REGISTRY\USER\S-1-5-21-2812790648-3157963462-487717889-1000_CLASSES\pdb_auto_file\ rundll32.exe Key created \REGISTRY\USER\S-1-5-21-2812790648-3157963462-487717889-1000_CLASSES\pdb_auto_file\shell\Read\command rundll32.exe -
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 2652 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 2 IoCs
Processes:
AcroRd32.exepid process 2652 AcroRd32.exe 2652 AcroRd32.exe -
Suspicious use of WriteProcessMemory 7 IoCs
Processes:
cmd.exerundll32.exedescription pid process target process PID 2212 wrote to memory of 2764 2212 cmd.exe rundll32.exe PID 2212 wrote to memory of 2764 2212 cmd.exe rundll32.exe PID 2212 wrote to memory of 2764 2212 cmd.exe rundll32.exe PID 2764 wrote to memory of 2652 2764 rundll32.exe AcroRd32.exe PID 2764 wrote to memory of 2652 2764 rundll32.exe AcroRd32.exe PID 2764 wrote to memory of 2652 2764 rundll32.exe AcroRd32.exe PID 2764 wrote to memory of 2652 2764 rundll32.exe AcroRd32.exe
Processes
-
C:\Windows\system32\cmd.execmd /c C:\Users\Admin\AppData\Local\Temp\Redline_20_2\Redline_20_2_stealer-main\Kurome.Builder\Mono.Cecil.Mdb.pdb1⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\rundll32.exe"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\Admin\AppData\Local\Temp\Redline_20_2\Redline_20_2_stealer-main\Kurome.Builder\Mono.Cecil.Mdb.pdb2⤵
- Modifies registry class
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\Redline_20_2\Redline_20_2_stealer-main\Kurome.Builder\Mono.Cecil.Mdb.pdb"3⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD57bb6dc82d0b4bda2da611531cb52f5be
SHA140cbe54834dda330a8c9aec2321280b1af530d5e
SHA2566f2de60ccdfe7ad0b1fcfacca3f9c916bb80fcae07d0f02587bce0ef529b001b
SHA512abe681ffdbcb217bfa3f749f0c783dc1f0c0a90315d2039fccb683ec54a77329fd9fc60518c0cef654af83d324f7d63efb3bdeae463baf87879cb5e9d6551f52