Resubmissions

05-07-2024 16:54

240705-vesbwavapf 10

05-07-2024 16:49

240705-vb469ssamr 7

04-07-2024 16:17

240704-trmrgs1eja 10

04-07-2024 16:14

240704-tpl26syfqj 7

04-07-2024 16:11

240704-tmx2na1dne 10

General

  • Target

    https://gofile.io/d/SRT9tP

  • Sample

    240704-tmx2na1dne

Malware Config

Extracted

Family

redline

Botnet

s6murai on telegram

C2

178.40.160.213:3333

Targets

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks