Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
31
Global rank
28 infographic chevron month
Month rank
32 infographic chevron week
Week rank
0
IOCs

RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.

Stealer
Type
ex-USSR
Origin
1 March, 2020
First seen
14 September, 2026
Last seen
Also known as
RedLine

How to analyze RedLine Stealer with ANY.RUN

Type
ex-USSR
Origin
1 March, 2020
First seen
14 September, 2026
Last seen

IOCs

IP addresses
34.117.223.223
48.209.133.15
104.18.38.233
34.54.20.80
34.159.85.52
40.126.31.129
45.138.55.61
88.221.169.205
185.111.111.157
104.20.22.186
142.251.13.132
34.111.24.1
85.214.83.151
34.160.176.28
2.21.239.136
142.251.14.102
142.250.154.95
2.22.50.145
35.166.67.196
23.50.131.214
Hashes
cf5f5184c1441a1660aa52526328e9d5c2793e77b6d8d3a3ad654bdb07ab8424
a54dc8488f8193bf30c3820cf6f261f911f9d328d699e1a1b8042641554cec70
59727f7a256b7a70971f2e62b43b0a923937f85689fc3aa4ae50e4fbfbf83499
f49a2735886ec0a1199973160b88ac88dee576588f4c0a211ed5ebf44c566067
f155f8f66833bdc8e0479656256bfac1d66a9ec9df4aa56292308f522b4e3fa7
f854ae8aabc0404652b48a2b3bf7f21ec174c69d73f5596934c20884eb0639ef
c3aed6a54154090685df3bbcd72e7a84943a4f3d5e5491bc6446a0b2d538c493
656e11ea18f7fb862f6625469b822583f3c08e986b3a24962d74737ebf6927e6
e668af8c73a38a66a1e8951d14ec24e7582fee5254dd6c3dae488a416d105d5f
7732fa42ebc8652ee3300a086a068f6aa5008cfa0d14948b144e4b06c82efda7
331b34c5d939627eb370fe4250beaec0d0fb5edbf687b0c3631930385026cf7c
7c3794f6aa18b133dc86045d00f3d5894682084692a959ce521982eed4554f37
5eca2c8028dee3a4728012bc60a763f69205325d0eb75b344cb7e10a788faa96
ed72ce2b51ee58f117e5a021e2e04af158857f40269fbc03491f0b2a99dbcc96
08bebda80b178f4b558faed4e52930f66e855614e4dfae15a436733b4712e041
634788199f33637e3cc36c61e5272f72ccbdab87be0c07eaaaf487c5f4f1ce82
e89251cdaaf385d93f74b819412217e47a7a06cd65115a1f87eedda0dffb2947
bdd96967d9b60683a91e086651ec03eed0d4ba142b37993111a0b1a608f8a05d
a9c42b959825bce9b7c72a7b0797a41580cb21f407b73e08168fb1ed1db438c4
d988d5362ea432d8c8ad9f05af876ba9409eb1ebad8c34b899fc9cc8c7ea5311
Domains
ib.adnxs.com
citigroup.com
honzik.avcdn.net
android.clients.google.com
edge.microsoft.com
ajax.aspnetcdn.com
urlite.ff.avast.com
emupdate.bav.avcdn.net
ipm.avcdn.net
update.googleapis.com
live.com
uploadnow.io
pancakeswap.finance
bradescoprime.com.br
netrep.svc.avast.com
www.bing.com
cdn-av-download.avgbrowser.com
ajax.googleapis.com
connectivitycheck.android.com
redditblog.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:lu4y_qae10smaz1kxiyssjw0fnhueg5ig5jlf-lzoiu&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://uploadnow.io/f/0bcds7g
https://uploadnow.io/en/share?utm_source=0bcds7g
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://cdn.uploadnow.io/_next/static/css/cda03e3a1ab65c17.css
https://cdn.uploadnow.io/_next/static/css/df97d9751ec3abda.css
https://cdn.uploadnow.io/_next/static/css/ae110469aab9e883.css
https://cdn.uploadnow.io/_next/static/css/5ded0d5ca9ecc5c1.css
https://cdn.uploadnow.io/_next/static/chunks/framework-b6335179e7eea00c.js
https://cdn.uploadnow.io/_next/static/chunks/webpack-541c27ed8494cc3b.js
https://cdn.uploadnow.io/_next/static/chunks/main-86f0684c1b20f38d.js
https://cdn.uploadnow.io/_next/static/chunks/pages/_app-a7a0c0b843b84887.js
https://cdn.uploadnow.io/_next/static/chunks/62867-950590631f5ceb03.js
https://cdn.uploadnow.io/_next/static/chunks/38993-a4121c3c0d1b9d33.js
https://cdn.uploadnow.io/_next/static/chunks/41480-7aa8c357827879bd.js
Last Seen at
Last Seen at

Recent blog posts

post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 4780
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 9604
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 11523
comments 0

What is RedLine Stealer?

RedLine Stealer or RedLine is malware that can collect users’ confidential information and deliver other malicious programs. The availability and flexibility of the stealer cause financial loss, data leakage, targeting both enterprise and personal devices. Healthcare and manufacturing sectors suffer the most from these attacks.

The malware appeared in March 2020 according to the Proofpoint investigation. Since then RedLine has just gained steam. It was on the rise during the COVID-19 pandemic and is still active. On July 1st, 2021 the malware was found on the legit-looking website that provides privacy tools. However, based on the payload analysis, only malware can be found there.

General description of RedLine malware

RedLine is an infostealer that takes information about users from browsers, systems instant messaging, and file transfer protocol clients. The main target is passwords, credit card information, username, location, autofill data, cookies, software set, and even hardware configuration like keyboard layout, UAC settings, etc. The virus is also capable of stealing cryptocurrency.

The malicious program acts as a typical stealer such as Raccoon or Pony: it uploads and downloads files, executes commands, and reports information about the infected machine. Moreover, attackers make use of RedLine to deliver ransomware, RATs, trojans, and miners.

The infostealer is quite popular as there is no problem finding it. Underground forums, C&C panels offer different options such as malware-as-a-service versions or a subscription. The price varies from $100 to $200.

One cannot tell that RedLine Stealer is a sophisticated malware like ransomware. It has the usual features typical for this family. However, it is .Net malware written in C# and the code quality is high enough to reveal an experienced programmer behind it. Cybercriminals also work hard to update malware, like downloading secondary payloads and advanced filtering features.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

RedLine malware analysis

ANY.RUN allows researchers to perform the analysis and watch the RedLine in action in an interactive sandbox simulation

redline stealer process graph

Figure 1: Displays the lifecycle of RedLine in a visual form as a process graph generated by ANY.RUN

redline stealer report

Figure 2: A customizable text report generated by ANY.RUN allows users to take an even deeper look at the malware and helps to share the research results.

RedLine Stealer execution process

Typically the execution process of that stealer is plain and straightforward. Based on the analysis, the main binary launches itself and the parent process stops. It also may be dropped from another binary or be the main binary itself. When a child process is created, the main malicious activity starts – RedLine collects information from the infected system such as passwords and others, and sends it to the Command & Control panel. When all information is collected and sent, the stealer just quits execution. Stolen information is sent in both non-encrypted and base64 encoded formats.

Distribution of RedLine

Attackers are not very creative with the delivery method of the virus. However, as the ransomware story, the method works perfectly – social engineering for different email campaigns including business email compromise, spam, fake updates, ads in Google result in malicious attachments or links. We can notice the big variety of file formats here:

  • Office
  • PDF
  • RAR and ZIP
  • Executable files
  • JavaScript

If you open the files in the attachment, RedLine will download other malicious programs.

How to detect RedLine infostealer using ANY.RUN?

At the moment, analysts can quickly recognize the info stealer because it will be tagged after Suricata IDS rules are triggered. Since the malicious program sends the stolen info to its panel just right after the start of the execution, it won't take a lot of time.

Conclusion

The best way to protect your organization or device from RedLine is to be cautious with suspicious files and links that get into your email. Your staff should be aware that even trustworthy sources can lead to infection and password or other credentials’ theft. It won’t take long to check a file in a sandbox such as ANY.RUN. Several minutes will be enough to detect RedLine and you will be good to go. Stay safe.

HAVE A LOOK AT

BQTLock screenshot
BQTLock
bqtlock baqiyatlock
BQTLock is a ransomware-as-a-service (RaaS) malware family that emerged in 2025 and quickly gained attention due to its combination of file encryption, credential theft, and data exfiltration. BQTLock encrypts files using a hybrid AES-256 and RSA-4096 encryption scheme, demands payment in Monero cryptocurrency, and performs data theft and system reconnaissance.
Read More
Lynx screenshot
Lynx
lynx
Lynx is a double extortion ransomware: attackers encrypt important and sensitive data and demand a ransom for decryption simultaneously threatening to publish or sell the data. Active since mid-2024. Among techniques are terminating processes and services, privilege escalation, deleting shadow copies. Distribution by phishing, malvertising, exploiting vulnerabilities.
Read More
Black Basta screenshot
Black Basta
blackbasta
Black Basta is a ransomware-as-a-service operated by Storm-1811. It emerged in 2022 and uses double extortion tactics, encrypting data and stealing it for ransom. The malware often gains access through spear-phishing and uses tools like QakBot and Cobalt Strike. It's known for exploiting system vulnerabilities and using advanced obfuscation techniques.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More
Jigsaw screenshot
Jigsaw
jigsaw
The Jigsaw ransomware, initially detected in 2016, encrypts files on compromised systems and requires a ransom payment in Bitcoin. If the ransom is not paid, the malware starts deleting files, increasing the pressure on victims to comply. Its source code is publicly accessible, allowing various threat actors to customize and repurpose the malware for different objectives.
Read More
Mirage2FA screenshot
Mirage2FA
mirage2fa
Mirage2FA is a Phishing-as-a-Service toolkit designed to compromise Microsoft 365 accounts and bypass conventional MFA through Adversary-in-the-Middle attacks. It uses malicious HTML, XHTML, and SVG files to deliver JavaScript loaders that connect victims to attacker-controlled phishing infrastructure. The toolkit relays authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies. It also uses browser fingerprinting, WebSockets, obfuscation, and rotating infrastructure to evade detection and maintain access to compromised accounts.
Read More