Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

RisePro

109
Global rank
85 infographic chevron month
Month rank
58 infographic chevron week
Week rank
0
IOCs

RisePro, an information-stealing malware, targets a wide range of sensitive data, including credit cards, passwords, and cryptocurrency wallets. By compromising infected devices, RisePro can steal valuable information and potentially cause significant financial and personal losses for victims.

Stealer
Type
ex-USSR
Origin
1 December, 2022
First seen
31 August, 2026
Last seen

How to analyze RisePro with ANY.RUN

Type
ex-USSR
Origin
1 December, 2022
First seen
31 August, 2026
Last seen

IOCs

IP addresses
74.178.76.128
154.91.34.165
147.185.221.20
139.99.85.213
82.29.67.160
103.171.35.26
107.174.192.179
190.251.70.118
154.23.184.57
104.26.9.202
208.95.112.1
45.141.233.69
149.154.167.99
158.101.44.242
34.229.166.50
23.59.17.18
162.159.133.234
40.126.31.1
88.221.169.205
48.209.138.168
Hashes
df3f619804a92fdb4057192dc43dd748ea778adc52bc498ce80524c014b81119
67401342192babc27e62d4c1e0940409cc3f2bd28f77399e71d245eae8d3f63c
704d28223a4320a853df4a19d48c7015cf79d56a5317cc3475b6305fa43dcc05
8f05bafd61f29998ca102b333f853628502d4e45d53cff41148d6dd15f011792
81970dbe581373d14fbd451ac4b3f96e5f69b79645f1ee1ca715cff3af0bf20d
d7446e2f307027c9bda2a92d1df1c13c376581372f6ae8708f4d5baccb2e6813
cd2c00ce027687ce4a8bdc967f26a8ab82f651c9becd703658ba282ec49702bd
9efa735bbf7b61c3f94281e925ee48ce4cc659d267c0255d54e4700f4404eec0
73526ddb1d23d595680badd6bd87f5dd82869606a7cf7e8707758d48d848257e
c5011367a4453096122fe72bb89f2940293cb61e973522ff140cdfe05227b1f3
f3a7e5e59e883a3ef6c99967766a546d55dd7a767fadb9f4d433cedf0555e992
11acf49eb9f3cb68fa7a3bb8568cef2eb0f125700c8edcbcd108b5810761770f
2487221a75a52b4f8aa6d2e62f1c0a55a5cd5240b1cb7aafa66fbb2042590b06
057784451e3442f381f6a8af931a7050f88d19bda6bc939d37607532a353da1c
e7f8eae310e8ace3b3b0be3bb145ec8c2bbcaa66c9337218dc4cbef633374f95
c13743567fcfc4fa77b66e79447edab2d1ecc97d4da32b655d92ae90968f2b0b
7c0719b9b312a531cf41cd08affacceef6de084619808238fec0f0247955f26e
bffbebedccb4bfd8e849bb3b577eaf0bc821bd45be29905017e667034e5b25be
9d6ee11f048b734a4edf01acda39d1390b0e1e88756919991c242073723b9c21
5ac3e308c8bef5ed42463929a1be5f519f56a0785fd8c2aed6f85073cc5f98fc
Domains
gateway.discord.gg
ocsp.digicert.com
ip-api.com
steamcommunity.com
fe3cr.delivery.mp.microsoft.com
self.events.data.microsoft.com
slscr.update.microsoft.com
api.pcloud.com
crl.microsoft.com
grabify.link
go.microsoft.com
officeclient.microsoft.com
www.microsoft.com
www.bing.com
oneocsp.microsoft.com
api.telegram.org
watson.events.data.microsoft.com
s3.timeweb.cloud
t.me
activation-v2.sls.microsoft.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://gateway.discord.gg/?v=9&encording=json
https://t.me/m00f3r
https://gstatic.com/generate_204
https://api.pcloud.com/listfolder?path=/
https://steamcommunity.com/profiles/76561199851454339
https://cloud-api.yandex.net/v1/disk/resources?path=/&limit=500
https://t.me/asdawfq
http://ip-api.com/line/?fields=hosting
http://checkip.dyndns.org/
https://grabify.link/zatfqo
https://narrathfpt.top/tekq
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
https://steamcommunity.com/profiles/76561199845513035
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://ip-api.com/json/
https://login.live.com/ppsecure/deviceaddcredential.srf
https://login.live.com/rst2.srf
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 4905
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 11329
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 13623
comments 0

What is RisePro malware?

RisePro is a malware program primarily designed to exfiltrate sensitive information from compromised devices. It is often distributed through deceptive methods, such as fake cracks sites or malicious email attachments. Once installed, RisePro infiltrates the target system and silently collects a variety of personal and financial data.

First detected in late 2022, the malware continues to be actively updated and developed by its creators. It is sold openly online, including via a Telegram bot, where users can choose a preferred subscription plan and control the malware.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Technical details of the RisePro malicious software

RisePro's underlying architecture is similar to Vidar’s, another well-known password-stealing malware. It employs a system of embedded DLL dependencies to achieve its malicious goals.

The malware's typically focuses on stealing the following types of information:

  • Web browser credentials: RisePro can steal login credentials and cookies from various web browsers, including Google Chrome, Mozilla Firefox, and Microsoft Edge.
  • Crypto wallets: The malware can identify and steal cryptocurrency wallet addresses and private keys, granting attackers access to victims' digital assets.
  • Credit card information: RisePro may collect credit card numbers, expiration dates, and CVV codes.

Additionally, RisePro gathers information about the compromised system, including operating system, installed software, and hardware specifications. It can also capture screenshots of the victim's desktop, providing attackers with visual insights into their activities.

Once collected, the stolen data is bundled and sent to the attacker's command and control (C2) server. As mentioned, RisePro is constantly evolving, as its creators continue to enhance its capabilities. In a recent development, the malware has transitioned from HTTP-based C2 communication to a custom TCP protocol.

Check out a comprehensive analysis of RisePro’s C2 communication.

RisePro employs various obfuscation techniques to evade detection by security software, making it more challenging for antivirus and anti-malware solutions to identify and neutralize the threat.

Execution process of RisePro

To see how RisePro behaves on an actual system, let’s upload its sample to ANY.RUN sandbox for detailed analysis.

Like most malware, RisePro's execution chain can vary significantly even within one version. It can be either a single process performing all malicious activities or multiple processes involving the operating system's system utilities.

In our case, using the Static discovering function, we can see that a macro launches a process named crome.exe, which was downloaded from a remote server with the address 89.23.98.22.

Subsequently, we can use Script Tracer to verify this information and ensure that this process was also launched after the download. The WINWORD process, through macros, downloaded and initiated the crome process, which was the RisePro stealer, and carried out the main malicious activity. Additionally, the malware added itself to the Task Scheduler to ensure persistence on the infected system.

RisePro process graph shown in ANY.RUN RisePro`s process graph demonstrated in ANY.RUN

Distribution methods of the RisePro malware

RisePro is often spread by a loader called PrivateLoader. PrivateLoader is a pay-per-install service that charges malware distributors for each installation of their harmful software.

PrivateLoader's most common tactic is to disguise itself as pirated software. This means that they create websites that look like they are offering free downloads of popular programs.

One way that PrivateLoader makes its websites look legitimate is by using SEO poisoning. This is a technique that involves manipulating search engines to rank websites higher in search results.

Conclusion

As RisePro is constantly changing, it's important for individuals and organizations to take steps to protect themselves from its attacks. To make sure you avoid downloading any suspicious files or clicking links, it’s crucial you check them in a malware analysis sandbox.

ANY.RUN helps you identify if a suspicious file or link is safe by analyzing it in seconds. It provides detailed threat reports with all the necessary information, such as indicators of compromise (IOCs), for effective prevention and incident response.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

Black Basta screenshot
Black Basta
blackbasta
Black Basta is a ransomware-as-a-service operated by Storm-1811. It emerged in 2022 and uses double extortion tactics, encrypting data and stealing it for ransom. The malware often gains access through spear-phishing and uses tools like QakBot and Cobalt Strike. It's known for exploiting system vulnerabilities and using advanced obfuscation techniques.
Read More
Oblivion RAT screenshot
Oblivion RAT
oblivion
Oblivion RAT is a sophisticated Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on cybercrime forums for as little as $300 per month. It equips even novice attackers with a complete toolkit, including a web-based APK builder, dropper generator mimicking Google Play updates, and a real-time C2 panel. The RAT enables full device takeover, data theft, and financial fraud through deceptive social engineering and Accessibility Service abuse.
Read More
RedLine screenshot
RedLine
redline stealer redline stealer malware
RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.
Read More
Gunra screenshot
Gunra
gunra
Gunra ransomware, a financially motivated threat actor that emerged in April 2025, deploys double-extortion tactics to encrypt victims' data and threaten leaks of exfiltrated information, primarily targeting Windows and Linux systems across healthcare, manufacturing, and other sectors worldwide.
Read More
 screenshot
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
GREENBLOOD screenshot
GREENBLOOD
greenblood
GREENBLOOD is a Go-based ransomware that uses concurrent ChaCha8 encryption to lock entire Windows environments in under a minute while systematically destroying backups, disabling defenses, and threatening double extortion through a Tor-based data leak site.
Read More