Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
32
Global rank
37 infographic chevron month
Month rank
30 infographic chevron week
Week rank
0
IOCs

RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.

Stealer
Type
ex-USSR
Origin
1 March, 2020
First seen
28 August, 2026
Last seen
Also known as
RedLine

How to analyze RedLine Stealer with ANY.RUN

Type
ex-USSR
Origin
1 March, 2020
First seen
28 August, 2026
Last seen

IOCs

IP addresses
139.99.85.213
154.91.34.165
188.114.97.3
75.119.193.253
149.154.166.110
2.16.241.205
213.180.204.127
208.95.112.1
45.141.233.69
132.148.178.5
150.171.22.17
132.226.247.73
185.121.177.177
150.171.28.11
2.59.254.111
176.65.144.23
217.78.234.145
74.120.9.233
192.178.183.94
185.156.72.2
Hashes
82042ec4e11fffbf1b0b5e6721afce8ac960267b2061c1ca2b30ebc2e58f4d17
f91dbb7c64b4582f529c968c480d2dce1c8727390482f31e4355a27bb3d9b450
5e32f16d52a5577a937f2c8513ca35c9e6be351a7a0fbb74278407df504d86a5
0dda9a17d54e586598a6200db854be52654d3e9def07363cd1e837569af88974
0c5490ca2f6d61c2d410e7907be97b3bc36b3e4de614e1f5431278dbccad4c79
69cb93351b7b2b3c33fa6826be062c454924a34bae7dd812de27eb70767843f1
3935a289417a1f1584f163ae93bddac534a69f69af224dbd4a434300ced93382
a5c1700269d33046833d6165b026dbaf1305ad612a892dff4ba3fa6701744027
fb75d593076ef30f9ba4601a09bf5ea50bcf9c84f8dd0750d113429a71104a13
1091a5225a1cce78601515acec1f2d35976158852bb1a263d9b4ceb6506990f5
a7055562772c30feadf7fccf3f22da1acda82d995d536b7ff91cfef3551d9789
82eaf8e8bc7275aeaf5834f57b8cf4d53cbbe5d551a561bedd0de43ff3786708
d2ac55b4450b3d379ec28eddc138eeab49584c0c8a9328fb5158cd35bfa9e03f
96e670b631a8e0520dcbfd8067d75ef4b167df8dc3c4bb42d9e62023259adc51
dbcb1915cd4d696290d550b5c3169b9be00931df18c06b7dd157206220cab1f9
39e641a906d7f511496c49a711976117946bdfd05f8ddc6a8c495c32cb50c990
d4b23edc5e796b44c8f86e88445068bd5456ecd5d719f5b65138b682fe8a161f
fbb710d9e5dfd5037d2f5d382497c4cd36bd48d76889bc244457442e38da9d65
02546eb94be966d89abb363ff318fc1414a86a8de222654d9419d221687b8e11
ba1639606ec3b0f61526d08d8ec2efd83dc0d6327c385b80698e8898e9bf9550
Domains
reallyfreegeoip.org
www.dontlookhere.com
s3.timeweb.cloud
api.telegram.org
ip-api.com
dontlookhere.com
gstatic.com
www.bing.com
api.pcloud.com
config.edge.skype.com
mail.dhakahome.com
edge.microsoft.com
checkip.dyndns.org
google.com
cloud-api.yandex.net
login.live.com
iplogger.org
settings-win.data.microsoft.com
slscr.update.microsoft.com
grabify.link
URLs
https://gstatic.com/generate_204
https://api.pcloud.com/listfolder?path=/
https://cloud-api.yandex.net/v1/disk/resources?path=/&limit=500
http://ip-api.com/json/
http://checkip.dyndns.org/
http://ip-api.com/line/?fields=hosting
https://edge.microsoft.com/serviceexperimentation/v2/
https://config.edge.skype.com/config/v1/edge/109.0.1518.115?clientid=-626569875466424637&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfull=0&scpguard=1&scpfre=0&scpver=18&osarch=x86&osver=6.1.7601&wu=0&devicefamily=desktop&uma=1&sessionid=17&mngd=0&installdate=1604373552&edu=0&bphint=0
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x86&os_arch=x86&nacl_arch=x86-32&prod=edgecrx&prodchannel=&prodversion=109.0.1518.115&lang=en-us&acceptformat=crx3&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d837%2526e%253d1
https://reallyfreegeoip.org/xml/85.203.47.38
https://api.telegram.org/bot/sendmessage?chat_id=&text=%20%0d%0a%0d%0apc%20name:user-pc%0d%0adate%20and%20time:%208/28/2026%20/%205:37:26%20pm%0d%0acountry%20name:%20%0d%0a%5b%20user-pc%20clicked%20on%20the%20file%20if%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5d
https://dontlookhere.com/
http://www.dontlookhere.com/blog
http://dontlookhere.com/blog
https://dontlookhere.com/blog/
http://dontlookhere.com/blog/
https://api.telegram.org/bot7950066405:aae5kuvk04df6lzjfoe-yzt3f12hjhmziqg/senddocument?chat_id=-4703613545&caption=%20pc%20name:%20admin%20%7c%20/%20vip%20recovery%20%5c%0d%0a%0d%0apw%20%7c%20admin%20%7c%20vip%20recovery
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
https://gateway.discord.gg/?v=9&encording=json
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 3153
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 8509
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 11265
comments 0

What is RedLine Stealer?

RedLine Stealer or RedLine is malware that can collect users’ confidential information and deliver other malicious programs. The availability and flexibility of the stealer cause financial loss, data leakage, targeting both enterprise and personal devices. Healthcare and manufacturing sectors suffer the most from these attacks.

The malware appeared in March 2020 according to the Proofpoint investigation. Since then RedLine has just gained steam. It was on the rise during the COVID-19 pandemic and is still active. On July 1st, 2021 the malware was found on the legit-looking website that provides privacy tools. However, based on the payload analysis, only malware can be found there.

General description of RedLine malware

RedLine is an infostealer that takes information about users from browsers, systems instant messaging, and file transfer protocol clients. The main target is passwords, credit card information, username, location, autofill data, cookies, software set, and even hardware configuration like keyboard layout, UAC settings, etc. The virus is also capable of stealing cryptocurrency.

The malicious program acts as a typical stealer such as Raccoon or Pony: it uploads and downloads files, executes commands, and reports information about the infected machine. Moreover, attackers make use of RedLine to deliver ransomware, RATs, trojans, and miners.

The infostealer is quite popular as there is no problem finding it. Underground forums, C&C panels offer different options such as malware-as-a-service versions or a subscription. The price varies from $100 to $200.

One cannot tell that RedLine Stealer is a sophisticated malware like ransomware. It has the usual features typical for this family. However, it is .Net malware written in C# and the code quality is high enough to reveal an experienced programmer behind it. Cybercriminals also work hard to update malware, like downloading secondary payloads and advanced filtering features.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

RedLine malware analysis

ANY.RUN allows researchers to perform the analysis and watch the RedLine in action in an interactive sandbox simulation

redline stealer process graph

Figure 1: Displays the lifecycle of RedLine in a visual form as a process graph generated by ANY.RUN

redline stealer report

Figure 2: A customizable text report generated by ANY.RUN allows users to take an even deeper look at the malware and helps to share the research results.

RedLine Stealer execution process

Typically the execution process of that stealer is plain and straightforward. Based on the analysis, the main binary launches itself and the parent process stops. It also may be dropped from another binary or be the main binary itself. When a child process is created, the main malicious activity starts – RedLine collects information from the infected system such as passwords and others, and sends it to the Command & Control panel. When all information is collected and sent, the stealer just quits execution. Stolen information is sent in both non-encrypted and base64 encoded formats.

Distribution of RedLine

Attackers are not very creative with the delivery method of the virus. However, as the ransomware story, the method works perfectly – social engineering for different email campaigns including business email compromise, spam, fake updates, ads in Google result in malicious attachments or links. We can notice the big variety of file formats here:

  • Office
  • PDF
  • RAR and ZIP
  • Executable files
  • JavaScript

If you open the files in the attachment, RedLine will download other malicious programs.

How to detect RedLine infostealer using ANY.RUN?

At the moment, analysts can quickly recognize the info stealer because it will be tagged after Suricata IDS rules are triggered. Since the malicious program sends the stolen info to its panel just right after the start of the execution, it won't take a lot of time.

Conclusion

The best way to protect your organization or device from RedLine is to be cautious with suspicious files and links that get into your email. Your staff should be aware that even trustworthy sources can lead to infection and password or other credentials’ theft. It won’t take long to check a file in a sandbox such as ANY.RUN. Several minutes will be enough to detect RedLine and you will be good to go. Stay safe.

HAVE A LOOK AT

FlowerStorm screenshot
FlowerStorm
flowerstorm
FlowerStorm is a phishing-as-a-service (PhaaS) platform used by cybercriminals to steal Microsoft 365 credentials and bypass multi-factor authentication (MFA) protections through adversary-in-the-middle (AiTM) attacks. Emerging after the disruption of Rockstar2FA in late 2024, FlowerStorm rapidly gained popularity among attackers targeting enterprises across North America and Europe.
Read More
Pulsar RAT screenshot
Pulsar RAT
pulsar
Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.
Read More
Crocodilus screenshot
Crocodilus
crocodilus
Crocodilus is a highly sophisticated Android banking Trojan that emerged in March 2025, designed for full device takeover. Disguised as legitimate apps, it steals banking credentials, cryptocurrency wallet data, and enables remote control, rapidly evolving into a global threat targeting financial users across Europe, South America, and Asia.
Read More
Cerber screenshot
Cerber
cerber
Cerber is a Ransomware-as-a-Service (RaaS) that appeared in 2016, spread quickly and has been evolving since. It became well-known for its file encryption, offline capabilities, and sophisticated evasion techniques. It primarily targets enterprises, financial institutions, and government entities, encrypting their data and demanding ransom payments in Bitcoin. It also targets everyday users encrypting personal files (photos, documents) with the risk of their permanent loss.
Read More
DonutLoader screenshot
DonutLoader
donutloader donut
DonutLoader is a versatile, open-source-based in-memory loader that turns .NET assemblies, executables, DLLs, and scripts into position-independent shellcode for execution entirely in RAM. Originally derived from the popular Donut tool, it enables threat actors to bypass traditional antivirus and EDR solutions by avoiding disk writes and injecting payloads directly into legitimate Windows processes.
Read More
Mallox screenshot
Mallox
mallox
Mallox is a ransomware strain that emerged in 2021, known for its ability to encrypt files and target database servers using vulnerabilities like RDP. Often distributed through phishing campaigns and exploiting exposed SQL servers, it locks victims' data and demands a ransom. Mallox operates as a Ransomware-as-a-Service (RaaS), making it accessible to affiliates who use it to conduct attacks.
Read More