Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
RedLine Stealer | RedLine Stealer is a malware available on underground forums for sale apparently as a standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as the username, location data, hardware configuration, and information regarding installed security software. More recent versions of RedLine added the ability to steal cryptocurrency. FTP and IM clients are also apparently targeted by this family, and this malware has the ability to upload and download files, execute commands, and periodically send back information about the infected computer. | No Attribution |
|
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
XWorm | Malware with wide range of capabilities ranging from RAT to ransomware. | No Attribution |
|
AV Detection |
|
---|
Source: |
Avira: |
Source: |
Avira URL Cloud: |
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
||
Source: |
Avira: |
Source: |
Malware Configuration Extractor: |
||
Source: |
Malware Configuration Extractor: |
Source: |
Virustotal: |
Perma Link | ||
Source: |
ReversingLabs: |
Source: |
Integrated Neural Analysis Model: |
Source: |
String decryptor: |
||
Source: |
String decryptor: |
||
Source: |
String decryptor: |
||
Source: |
String decryptor: |
||
Source: |
String decryptor: |
||
Source: |
String decryptor: |
||
Source: |
String decryptor: |
||
Source: |
String decryptor: |
Source: |
Static PE information: |
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
Spreading |
|
---|
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
|||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
|||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
|||
Source: |
System file written: |
|||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
|||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
|||
Source: |
System file written: |
|||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
|||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
|||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior | ||
Source: |
System file written: |
Jump to behavior |
Source: |
Code function: |
0_2_0046445A | |
Source: |
Code function: |
0_2_0046C6D1 | |
Source: |
Code function: |
0_2_0046C75C | |
Source: |
Code function: |
0_2_0046EF95 | |
Source: |
Code function: |
0_2_0046F0F2 | |
Source: |
Code function: |
0_2_0046F3F3 | |
Source: |
Code function: |
0_2_004637EF | |
Source: |
Code function: |
0_2_00463B12 | |
Source: |
Code function: |
0_2_0046BCBC |
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior |
Networking |
|
---|
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
Source: |
URLs: |
||
Source: |
URLs: |
Source: |
TCP traffic: |
Source: |
DNS traffic detected: |
Source: |
Network traffic detected: |
Source: |
TCP traffic: |
Source: |
IP Address: |
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
Source: |
Code function: |
0_2_004722EE |
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
Source: |
HTTP traffic detected: |
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |