File name:

Galaxy Swapper v2.exe

Full analysis: https://app.any.run/tasks/84f34a05-1179-41ae-970d-66d84f7fb18f
Verdict: Malicious activity
Threats:

RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.

Analysis date: February 12, 2024, 06:37:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
stealer
redline
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

DE662C216C9CBEA5B53AD30D412D606E

SHA1:

0D7D74B5F9B401DFC5C8CD3F34E275E57D042E63

SHA256:

1FD12B4B8AF2ECD380B8FA3CBBD97C1B1B33BE6902EC5D6ECBB3BD536B482BDA

SSDEEP:

12288:+cSXm2+pPeyPodRxQlTztbWLd8GWWVmpugf2tr6d0GHui0TXdKex:+gZGqodRxQlTztbW58GW4tr5Qui0TYc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • runas.exe (PID: 3672)
    • REDLINE has been detected (YARA)

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 3612)
      • Galaxy Swapper v2.exe (PID: 3216)
    • REDLINE has been detected (SURICATA)

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 3612)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 4008)
    • Connects to the CnC server

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 3612)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 4008)
    • Actions looks like stealing of personal data

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 4008)
      • Galaxy Swapper v2.exe (PID: 3612)
    • Steals credentials from Web Browsers

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 3612)
      • Galaxy Swapper v2.exe (PID: 4008)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 2320)
      • taskmgr.exe (PID: 1404)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 4008)
      • Galaxy Swapper v2.exe (PID: 3612)
    • Reads settings of System Certificates

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 4008)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 3612)
    • Searches for installed software

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 4008)
      • Galaxy Swapper v2.exe (PID: 3612)
    • Reads browser cookies

      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 4008)
      • Galaxy Swapper v2.exe (PID: 3612)
    • Application launched itself

      • taskmgr.exe (PID: 1404)
  • INFO

    • Checks supported languages

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 3612)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 4008)
    • Reads the computer name

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 3612)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 4008)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 4020)
    • Reads the machine GUID from the registry

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 3612)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 4008)
    • Reads Environment values

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 4008)
      • Galaxy Swapper v2.exe (PID: 3612)
    • Reads the software policy settings

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 4008)
      • Galaxy Swapper v2.exe (PID: 3612)
    • Reads product name

      • Galaxy Swapper v2.exe (PID: 2848)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 3216)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 4008)
      • Galaxy Swapper v2.exe (PID: 3612)
    • Manual execution by a user

      • Galaxy Swapper v2.exe (PID: 2320)
      • Galaxy Swapper v2.exe (PID: 4080)
      • taskmgr.exe (PID: 1404)
      • Galaxy Swapper v2.exe (PID: 3492)
      • Galaxy Swapper v2.exe (PID: 908)
      • Galaxy Swapper v2.exe (PID: 2792)
      • Galaxy Swapper v2.exe (PID: 3612)
      • Galaxy Swapper v2.exe (PID: 2928)
      • Galaxy Swapper v2.exe (PID: 4020)
      • Galaxy Swapper v2.exe (PID: 3664)
      • Galaxy Swapper v2.exe (PID: 3700)
      • Galaxy Swapper v2.exe (PID: 4008)
      • Galaxy Swapper v2.exe (PID: 3216)
    • Reads security settings of Internet Explorer

      • taskmgr.exe (PID: 1404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

RedLine

(PID) Process(2848) Galaxy Swapper v2.exe
C2 (1)45.15.156.167:80
Botnet@mass1vexdd
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorRateably
(PID) Process(2792) Galaxy Swapper v2.exe
C2 (1)45.15.156.167:80
Botnet@mass1vexdd
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorRateably
(PID) Process(2320) Galaxy Swapper v2.exe
C2 (1)45.15.156.167:80
Botnet@mass1vexdd
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorRateably
(PID) Process(4080) Galaxy Swapper v2.exe
C2 (1)45.15.156.167:80
Botnet@mass1vexdd
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorRateably
(PID) Process(3492) Galaxy Swapper v2.exe
C2 (1)45.15.156.167:80
Botnet@mass1vexdd
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorRateably
(PID) Process(3216) Galaxy Swapper v2.exe
C2 (1)45.15.156.167:80
Botnet@mass1vexdd
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorRateably
(PID) Process(3612) Galaxy Swapper v2.exe
C2 (1)45.15.156.167:80
Botnet@mass1vexdd
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorRateably
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:02:08 20:01:16+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.38
CodeSize: 72192
InitializedDataSize: 381952
UninitializedDataSize: -
EntryPoint: 0x44f2
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
74
Monitored processes
16
Malicious processes
14
Suspicious processes
0

Behavior graph

Click at the process to see the details
start runas.exe no specs #REDLINE galaxy swapper v2.exe #REDLINE galaxy swapper v2.exe #REDLINE galaxy swapper v2.exe taskmgr.exe no specs taskmgr.exe #REDLINE galaxy swapper v2.exe #REDLINE galaxy swapper v2.exe #REDLINE galaxy swapper v2.exe #REDLINE galaxy swapper v2.exe #REDLINE galaxy swapper v2.exe #REDLINE galaxy swapper v2.exe #REDLINE galaxy swapper v2.exe #REDLINE galaxy swapper v2.exe #REDLINE galaxy swapper v2.exe #REDLINE galaxy swapper v2.exe

Process information

PID
CMD
Path
Indicators
Parent process
908"C:\Users\admin\Desktop\Galaxy Swapper v2.exe" C:\Users\admin\Desktop\Galaxy Swapper v2.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\galaxy swapper v2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1404"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2320"C:\Users\admin\Desktop\Galaxy Swapper v2.exe" C:\Users\admin\Desktop\Galaxy Swapper v2.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\galaxy swapper v2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
RedLine
(PID) Process(2320) Galaxy Swapper v2.exe
C2 (1)45.15.156.167:80
Botnet@mass1vexdd
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorRateably
2792"C:\Users\admin\Desktop\Galaxy Swapper v2.exe" C:\Users\admin\Desktop\Galaxy Swapper v2.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\galaxy swapper v2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
RedLine
(PID) Process(2792) Galaxy Swapper v2.exe
C2 (1)45.15.156.167:80
Botnet@mass1vexdd
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorRateably
2848"C:\Users\admin\Desktop\Galaxy Swapper v2.exe"C:\Users\admin\Desktop\Galaxy Swapper v2.exe
runas.exe
User:
Administrator
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\galaxy swapper v2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
RedLine
(PID) Process(2848) Galaxy Swapper v2.exe
C2 (1)45.15.156.167:80
Botnet@mass1vexdd
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorRateably
2928"C:\Users\admin\Desktop\Galaxy Swapper v2.exe" C:\Users\admin\Desktop\Galaxy Swapper v2.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\galaxy swapper v2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3216"C:\Users\admin\Desktop\Galaxy Swapper v2.exe" C:\Users\admin\Desktop\Galaxy Swapper v2.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\galaxy swapper v2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
RedLine
(PID) Process(3216) Galaxy Swapper v2.exe
C2 (1)45.15.156.167:80
Botnet@mass1vexdd
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorRateably
3492"C:\Users\admin\Desktop\Galaxy Swapper v2.exe" C:\Users\admin\Desktop\Galaxy Swapper v2.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\galaxy swapper v2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
RedLine
(PID) Process(3492) Galaxy Swapper v2.exe
C2 (1)45.15.156.167:80
Botnet@mass1vexdd
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorRateably
3504"C:\Windows\system32\taskmgr.exe" /1C:\Windows\System32\taskmgr.exe
taskmgr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3612"C:\Users\admin\Desktop\Galaxy Swapper v2.exe" C:\Users\admin\Desktop\Galaxy Swapper v2.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\galaxy swapper v2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
RedLine
(PID) Process(3612) Galaxy Swapper v2.exe
C2 (1)45.15.156.167:80
Botnet@mass1vexdd
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorRateably
Total events
74 302
Read events
73 947
Write events
278
Delete events
77

Modification events

(PID) Process:(2848) Galaxy Swapper v2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Galaxy Swapper v2_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2848) Galaxy Swapper v2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Galaxy Swapper v2_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2848) Galaxy Swapper v2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Galaxy Swapper v2_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(2848) Galaxy Swapper v2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Galaxy Swapper v2_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(2848) Galaxy Swapper v2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Galaxy Swapper v2_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(2848) Galaxy Swapper v2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Galaxy Swapper v2_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(2848) Galaxy Swapper v2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Galaxy Swapper v2_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2848) Galaxy Swapper v2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Galaxy Swapper v2_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2848) Galaxy Swapper v2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Galaxy Swapper v2_RASMANCS
Operation:writeName:FileTracingMask
Value:
(PID) Process:(2848) Galaxy Swapper v2.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Galaxy Swapper v2_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
30
DNS requests
1
Threats
109

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2848
Galaxy Swapper v2.exe
45.15.156.167:80
Galaxy LLC
RU
malicious
2848
Galaxy Swapper v2.exe
172.67.75.172:443
api.ip.sb
CLOUDFLARENET
US
unknown
2792
Galaxy Swapper v2.exe
45.15.156.167:80
Galaxy LLC
RU
malicious
2792
Galaxy Swapper v2.exe
172.67.75.172:443
api.ip.sb
CLOUDFLARENET
US
unknown
2320
Galaxy Swapper v2.exe
45.15.156.167:80
Galaxy LLC
RU
malicious
2320
Galaxy Swapper v2.exe
172.67.75.172:443
api.ip.sb
CLOUDFLARENET
US
unknown
4080
Galaxy Swapper v2.exe
45.15.156.167:80
Galaxy LLC
RU
malicious

DNS requests

Domain
IP
Reputation
api.ip.sb
  • 172.67.75.172
  • 104.26.12.31
  • 104.26.13.31
whitelisted

Threats

PID
Process
Class
Message
2848
Galaxy Swapper v2.exe
Potentially Bad Traffic
ET INFO Microsoft net.tcp Connection Initialization Activity
2848
Galaxy Swapper v2.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC Activity
2848
Galaxy Swapper v2.exe
A Network Trojan was detected
ET MALWARE [ANY.RUN] RedLine Stealer/MetaStealer Family Related (MC-NMF Authorization)
2848
Galaxy Swapper v2.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC - Id1Response
2848
Galaxy Swapper v2.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC - Id1Response
2848
Galaxy Swapper v2.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC Activity
2848
Galaxy Swapper v2.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC Activity
2792
Galaxy Swapper v2.exe
Potentially Bad Traffic
ET INFO Microsoft net.tcp Connection Initialization Activity
2792
Galaxy Swapper v2.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC Activity
2792
Galaxy Swapper v2.exe
A Network Trojan was detected
ET MALWARE [ANY.RUN] RedLine Stealer/MetaStealer Family Related (MC-NMF Authorization)
14 ETPRO signatures available at the full report
No debug info