General

  • Target

    92c01627961859a84ffa633327c5d7f9.bin

  • Size

    401KB

  • Sample

    240707-d5nypssgjp

  • MD5

    45f81bffb04da2f5738fd125a20fe29b

  • SHA1

    7e12a7cabdc8f8019ff26f4cca0a5a5ec5188454

  • SHA256

    189a64cc0f04d36f5830dc2bbb982a7c85aed89cb9c17227c862df3a3e3dcadc

  • SHA512

    556e511813af602a4b830d0d46d2a59079749bbb1fc3146015f822d2528871cf1b21d7b28ddd85e1085f01849898bef1d202459effb3e23a79b072c6e49656fe

  • SSDEEP

    12288:OOHq6HNgrTSAiNUU5Q8DAhWDnVmYh5OcKqxX:AviAGUU5VDRDnVN5lKQ

Malware Config

Extracted

Family

redline

Botnet

LiveTraffic

C2

4.184.236.127:1110

Targets

    • Target

      92373c134cbf9fc4a98ed7c80f244c8655b3852d3a1f1983fc4a7b3a00bf1370.exe

    • Size

      493KB

    • MD5

      92c01627961859a84ffa633327c5d7f9

    • SHA1

      5b406c39f81f67e2b2e263137c7059718e4af007

    • SHA256

      92373c134cbf9fc4a98ed7c80f244c8655b3852d3a1f1983fc4a7b3a00bf1370

    • SHA512

      f31f9d45d7783441866faa0e684412040dd74c2878adfc6e5a874626e291b3e3cae7746cb62e2388d4183e615d9b919178fa409f2e12b3d0cf478c59450d3439

    • SSDEEP

      12288:AxJVyE3e2Uo4a3Tq7c85n93zxAdiFZ3wWxc:An93aOMn5n9DxOiFZ3T

    • RedLine

      RedLine Stealer is a malware family written in C#, first appearing in early 2020.

    • RedLine payload

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks