Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

RisePro

94
Global rank
67 infographic chevron month
Month rank
85 infographic chevron week
Week rank

RisePro, an information-stealing malware, targets a wide range of sensitive data, including credit cards, passwords, and cryptocurrency wallets. By compromising infected devices, RisePro can steal valuable information and potentially cause significant financial and personal losses for victims.

Stealer
Type
ex-USSR
Origin
1 December, 2022
First seen
9 October, 2026
Last seen

How to analyze RisePro with ANY.RUN

Type
ex-USSR
Origin
1 December, 2022
First seen
9 October, 2026
Last seen

IOCs

IP addresses
23.3.89.120
48.209.138.168
40.126.31.0
23.48.23.179
172.211.123.248
23.52.181.212
20.165.94.63
135.233.95.135
116.131.226.149
149.154.167.99
64.89.163.22
98.176.183.1
172.65.251.78
131.108.28.2
185.199.108.133
38.111.25.1
194.162.19.1
220.234.104.2
59.110.104.183
167.171.57.3
Hashes
22b46a99bfb9233d2e72d392e4b1d36c9c61ae30fe56334ff1b2b0ccb0dca607
9a1b4e8fb16d69690e52748aac601ace68dc9c1186e2d886fa26220cb8486be1
035db4bb1698e67eed83c217b196e342dc8ab8bb6ace3c2960f413a2bfab3158
e30e97c4b7cbf75398d58f9ebed0e74a5cbfb4399f26cb44601389b396fad62a
31d33d4422f4f999229daadd7568080386b24db6b0056d9980c9c9cbd1e4482d
12b3f85402e82cb1715bcf8cd46fe7b892474053ebe795f8f6d1f2e2b62bb3ba
1750155044c10b1c64ca937d63ca527125c96a800925949ff6985e1d2bc34544
96377a795983e69fe28484ef7f5050449b5e27595bbc0b60194ff560199c8196
989093a6ce396fb6c2c9e45fe6e6673c006301911309ef4a3ef51ec5d7bcb762
a5ed948822ec81ce137834bbd077fd976340c828e7ac02d11a95bad63bbc4089
b916cfe14071304b960ecaa893e2f4cc7526d3203bb3170993768be43f24efa7
9884e9d1b4f8a873ccbd81f8ad0ae257776d2348d027d811a56475e028360d87
ceebae7b8927a3227e5303cf5e0f1f7b34bb542ad7250ac03fbcde36ec2f1508
3ad2dc318056d0a2024af1804ea741146cfc18cc404649a44610cbf8b2056cf2
ded5adaa94341e6c62aea03845762591666381dca30eb7c17261dd154121b83e
a594fc6fa4851b3095279f6dc668272ee975e7e03b850da4945f49578abe48cb
275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f
593f94ef1405422b3e453f4422b22c990d84303668d60344c6fd257318e92428
573e3260eed63604f24f6f10ce5294e25e22fda9e5bfd9010134de6e684bab98
9ae4a96bf2a349667e844acc1e2ac4f89361a6182268438f4d063df3a6fc47bc
Domains
client.wns.windows.com
slscr.update.microsoft.com
www.microsoft.com
fe3cr.delivery.mp.microsoft.com
google.com
settings-win.data.microsoft.com
self.events.data.microsoft.com
ecs.office.com
login.live.com
crl.microsoft.com
visam.info
drive.usercontent.google.com
rdrcfgwugqswg.org
acrislegt.su
redirector.gvt1.com
ae888688.com
tcwaueqxgdocv.net
fz.tiansys.cn
sanghyun.nfile.net
raw.githubusercontent.com
URLs
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://crl.microsoft.com/pki/crl/products/microoceraut_2010-06-23.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.2.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.2.crl
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20signing%20ca%202.1.crl
http://195.177.94.235/wtyt1562/secured_stub.ps1
http://23.132.164.15/fast/geen.ps1
http://23.132.164.15/fast/gg.ps1
http://23.132.164.15/fast/secured_stub.ps1
http://23.132.164.15/fast/ttessttt.ps1
http://23.132.164.15/fast/ss.ps1
http://107.175.82.242:9000/wilow/runner_ilove.exe
http://23.146.242.101/bin/screenconnect.clientsetup.exe
Last Seen at
Last Seen at

Recent blog posts

post image
Making Threat Intelligence Work for SOC Teams...
watchers 4611
comments 0
post image
5 Critical Pain Points of Modern US SOCs and...
watchers 6582
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 9728
comments 0

What is RisePro malware?

RisePro is a malware program primarily designed to exfiltrate sensitive information from compromised devices. It is often distributed through deceptive methods, such as fake cracks sites or malicious email attachments. Once installed, RisePro infiltrates the target system and silently collects a variety of personal and financial data.

First detected in late 2022, the malware continues to be actively updated and developed by its creators. It is sold openly online, including via a Telegram bot, where users can choose a preferred subscription plan and control the malware.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Technical details of the RisePro malicious software

RisePro's underlying architecture is similar to Vidar’s, another well-known password-stealing malware. It employs a system of embedded DLL dependencies to achieve its malicious goals.

The malware's typically focuses on stealing the following types of information:

  • Web browser credentials: RisePro can steal login credentials and cookies from various web browsers, including Google Chrome, Mozilla Firefox, and Microsoft Edge.
  • Crypto wallets: The malware can identify and steal cryptocurrency wallet addresses and private keys, granting attackers access to victims' digital assets.
  • Credit card information: RisePro may collect credit card numbers, expiration dates, and CVV codes.

Additionally, RisePro gathers information about the compromised system, including operating system, installed software, and hardware specifications. It can also capture screenshots of the victim's desktop, providing attackers with visual insights into their activities.

Once collected, the stolen data is bundled and sent to the attacker's command and control (C2) server. As mentioned, RisePro is constantly evolving, as its creators continue to enhance its capabilities. In a recent development, the malware has transitioned from HTTP-based C2 communication to a custom TCP protocol.

Check out a comprehensive analysis of RisePro’s C2 communication.

RisePro employs various obfuscation techniques to evade detection by security software, making it more challenging for antivirus and anti-malware solutions to identify and neutralize the threat.

Execution process of RisePro

To see how RisePro behaves on an actual system, let’s upload its sample to ANY.RUN sandbox for detailed analysis.

Like most malware, RisePro's execution chain can vary significantly even within one version. It can be either a single process performing all malicious activities or multiple processes involving the operating system's system utilities.

In our case, using the Static discovering function, we can see that a macro launches a process named crome.exe, which was downloaded from a remote server with the address 89.23.98.22.

Subsequently, we can use Script Tracer to verify this information and ensure that this process was also launched after the download. The WINWORD process, through macros, downloaded and initiated the crome process, which was the RisePro stealer, and carried out the main malicious activity. Additionally, the malware added itself to the Task Scheduler to ensure persistence on the infected system.

RisePro process graph shown in ANY.RUN RisePro`s process graph demonstrated in ANY.RUN

Distribution methods of the RisePro malware

RisePro is often spread by a loader called PrivateLoader. PrivateLoader is a pay-per-install service that charges malware distributors for each installation of their harmful software.

PrivateLoader's most common tactic is to disguise itself as pirated software. This means that they create websites that look like they are offering free downloads of popular programs.

One way that PrivateLoader makes its websites look legitimate is by using SEO poisoning. This is a technique that involves manipulating search engines to rank websites higher in search results.

Conclusion

As RisePro is constantly changing, it's important for individuals and organizations to take steps to protect themselves from its attacks. To make sure you avoid downloading any suspicious files or clicking links, it’s crucial you check them in a malware analysis sandbox.

ANY.RUN helps you identify if a suspicious file or link is safe by analyzing it in seconds. It provides detailed threat reports with all the necessary information, such as indicators of compromise (IOCs), for effective prevention and incident response.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

GravityRAT screenshot
GravityRAT
gravity
GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.
Read More
DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
SSLoad screenshot
SSLoad
ssload
SSLoad is a malicious loader or downloader that is used to infiltrate target systems through phishing emails, perform reconnaissance and transmit it back to its operators delivering malicious payloads. To avoid detection, SSLoad employs various encryption methods and delivery techniques highlighting its versatile nature and complexity. It is believed to be a part of Malware-as-a-Service (MaaS) operation given its diverse delivery methods and implemented techniques.
Read More
Bert Ransomware screenshot
Bert Ransomware is a newly emerged ransomware group that has been active since April 2025. It deploys variants targeting both Windows and Linux systems, focusing on critical sectors like healthcare, technology, and event services across the US, Asia, and Europe.
Read More
SmartLoader screenshot
SmartLoader
smartloader
SmartLoader is a Windows malware loader that uses multi-stage execution to deliver secondary payloads. It supports system discovery, screenshot capture, persistence through scheduled tasks, C2 communication, and anti-analysis techniques.
Read More
DarkTortilla screenshot
DarkTortilla
darktortilla
DarkTortilla is a crypter used by attackers to spread harmful software. It can modify system files to stay hidden and active. DarkTortilla is a multi-stage crypter that relies on several components to operate. It is often distributed through phishing sites that look like real services.
Read More