Sample name: | 17300326279186e286d8011f3b538be5fe09fea96cf622736b029b36a16f125b2e18b135f5130.dat-decoded.exe |
Analysis ID: | 1543228 |
MD5: | f4ee3982121972780a4666680cf24fa5 |
SHA1: | a894dfc5474469226cef8f660f9f4a2b0e4b0cd5 |
SHA256: | 60e3c682298d5a701939cf96defd2329d1fbb2dfb1209496a05058eb669ed983 |
Tags: | base64-decodedexeuser-abuse_ch |
Infos: | |
Errors
|
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
RedLine Stealer | RedLine Stealer is a malware available on underground forums for sale apparently as a standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as the username, location data, hardware configuration, and information regarding installed security software. More recent versions of RedLine added the ability to steal cryptocurrency. FTP and IM clients are also apparently targeted by this family, and this malware has the ability to upload and download files, execute commands, and periodically send back information about the infected computer. | No Attribution |
|
AV Detection |
---|
Source: |
Malware Configuration Extractor: |
Source: |
Joe Sandbox ML: |
Source: |
Static PE information: |
Source: |
Static PE information: |
Networking |
---|
Source: |
URLs: |
Source: |
String found in binary or memory: |
Source: |
Static PE information: |
Source: |
Binary or memory string: |
Source: |
Static PE information: |
Source: |
Classification label: |
Source: |
Static PE information: |
Source: |
Static file information: |
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Static PE information: |
Stealing of Sensitive Information |
---|
Source: |
File source: |
Remote Access Functionality |
---|
Source: |
File source: |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
|
unknown |