RedLine Malware Analizi
Dosya Ozellikleri
SHA256: e4aa13a28d8809b5fbc58400d02f0c3dee7f99b884b935c68059254c992948a1
MD5: 4619f014958049156d3668c3cf71b0d8
Dosya Tipi: exe
Boyut: 1,292,288 byte
Ilk Gorulme: 2023-10-03
AV Imzasi: RedLineStealer
Imphash: f34d5f2d4577ed6d9ceec516c1f5a744
Raporlayan: x3ph1
Etiketler: exe, Redline, RedLineStealer
Statik analiz: metadata tabanli (ornek indirilmedi)
RedLine — 악성코드 프로필
RedLine Stealer. QUOTATION lure. PCRE regex library. Form-grabbing. Credential theft.
기술 세부 정보
.NET, gRPC C2 protokolu, browser credential theft (tum Chromium/Firefox tabanlılar), cryptocurrency wallet stealer, VPN credential stealer, Discord/Steam token stealer
귀속 / 위협 행위자
Rusca konusulan gelistirici/operatorler; MaaS modeli ile cok sayida musteriye hizmet. 2024 Operasyon Magnus'ta birden fazla sunucu operatoru gozaltina alinmistir.
기능 및 동작
IOC 목록 (1 개 지표)
# FILEPATH
e4aa13a28d8809b5fbc58400d02f0c3dee7f99b884b935c68059254c992948a1
| 유형 | 값 | 메모 |
|---|---|---|
| filepath | e4aa13a28d8809b5fbc58400d02f0c3dee7f99b884b935c68059254c992948a1 | PDB |
C2 서버 (이 패밀리에 대해 8개의 서버 기록)
| 주소 | 유형 | 포트 | 프로토콜 | 상태 | 국가 |
|---|---|---|---|---|---|
| github.com | domain | — | HTTP | active | — |
| 185.220.101.47 | ip | 80 | HTTP | active | DE |
| 103.224.241.163 | ip | 443 | HTTPS | inactive | SG |
| 45.142.212.100 | ip | 11821 | TCP | inactive | — |
| 193.56.255.42 | ip | 15000 | TCP | inactive | — |
| 5.188.87.39 | ip | 30000 | TCP | inactive | — |
| 46.205.202.219 | ip | 1912 | TCP | inactive | — |
| 217.65.2.14 | ip | 1912 | TCP | inactive | — |
C2 주소는 KEYDAL 팀이 수동으로 검증한 악성코드 샘플에서만 제공됩니다. 상업적 사용은 금지됩니다.