File name: | Redline_2021_stealer-main.rar |
Full analysis: | https://app.any.run/tasks/0c7adbcd-2be8-4dc9-94e9-1b893d779395 |
Verdict: | Malicious activity |
Analysis date: | January 30, 2022, 18:59:24 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v5 |
MD5: | 5834A2F9DD05A8FBF390B133D618CF77 |
SHA1: | 1F9DEC6D14B58878024C5360E4A3F013CD019866 |
SHA256: | 4B0BCA466528875369A4934E92A1156F68F4919A0B99872788B65A0315881873 |
SSDEEP: | 393216:VoIxpiFTnpx1eJ/p4kZZc9RosoKm6NMaEcqpHVtckzM:ZpGnv0JptZc9RoymgMaEcqeJ |
.rar | | | RAR compressed archive (v5.0) (61.5) |
---|---|---|
.rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
496 | "C:\Users\admin\Desktop\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Loader\Kurome.Loader.exe" | C:\Users\admin\Desktop\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Loader\Kurome.Loader.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: Kurome.Loader Exit code: 2148734720 Version: 1.0.0.0 Modules
| |||||||||||||||
576 | "C:\Users\admin\Desktop\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Builder\Kurome.Builder.exe" | C:\Users\admin\Desktop\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Builder\Kurome.Builder.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: Kurome.Builder Exit code: 2148734720 Version: 1.0.0.0 Modules
| |||||||||||||||
652 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Redline_2021_stealer-main\Redline_2021_stealer-main\ReadMe.txt | C:\Windows\system32\NOTEPAD.EXE | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1604 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Redline_2021_stealer-main.rar" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
1656 | C:\Windows\Explorer.EXE | C:\Windows\Explorer.EXE | — | — | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2168 | C:\Users\admin\AppData\Local\Temp\GUM8CCD.tmp\GoogleUpdate.exe /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={147E1A31-5E49-ACD4-7646-E2EE6FA22B56}&lang=ru&browser=3&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&installdataindex=empty" | C:\Users\admin\AppData\Local\Temp\GUM8CCD.tmp\GoogleUpdate.exe | — | Chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Installer Exit code: 2147747856 Version: 1.3.34.11 Modules
| |||||||||||||||
2508 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /handoff "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={147E1A31-5E49-ACD4-7646-E2EE6FA22B56}&lang=ru&browser=3&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&installdataindex=empty" /installsource taggedmi /sessionid "{DAB74A2B-F34A-4039-B13C-15F044EE0030}" | C:\Program Files\Google\Update\GoogleUpdate.exe | GoogleUpdate.exe | ||||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 2147747856 Version: 1.3.33.23 Modules
| |||||||||||||||
2580 | "C:\Users\admin\Desktop\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Host\Kurome.Host.exe" | C:\Users\admin\Desktop\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Host\Kurome.Host.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: Kurome.Host Exit code: 2148734720 Version: 1.0.0.0 Modules
| |||||||||||||||
2676 | "C:\Program Files\GUM9161.tmp\GoogleUpdate.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={147E1A31-5E49-ACD4-7646-E2EE6FA22B56}&lang=ru&browser=3&usagestats=0&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&installdataindex=empty" /installelevated | C:\Program Files\GUM9161.tmp\GoogleUpdate.exe | — | GoogleUpdateSetup.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Installer Exit code: 2147747856 Version: 1.3.34.11 Modules
| |||||||||||||||
2696 | "C:\Users\admin\Desktop\Redline_2021_stealer-main\Redline_2021_stealer-main\Panel\RedLine_20_2\Tools\Chrome.exe" | C:\Users\admin\Desktop\Redline_2021_stealer-main\Redline_2021_stealer-main\Panel\RedLine_20_2\Tools\Chrome.exe | Explorer.EXE | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Update Setup Exit code: 2147747856 Version: 1.3.34.11 Modules
|
(PID) Process: | (1656) Explorer.EXE | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (1604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (1604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (1604) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (1604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (1604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (1604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Redline_2021_stealer-main.rar | |||
(PID) Process: | (1604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (1604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (1604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1604 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1604.33445\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Builder\Kurome.Builder.exe | executable | |
MD5:CF38A4BDE3FE5456DCAF2B28D3BFB709 | SHA256:C47B78E566425FC4165A83B2661313E41EE8D66241F7BEA7723304A6A751595E | |||
1604 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1604.33445\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Builder\Mono.Cecil.dll | executable | |
MD5:DE69BB29D6A9DFB615A90DF3580D63B1 | SHA256:F66F97866433E688ACC3E4CD1E6EF14505F81DF6B26DD6215E376767F6F954BC | |||
1604 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1604.33445\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Builder\Mono.Cecil.Mdb.pdb | binary | |
MD5:073D9D6C9C71F66151B84A376EDE4A9D | SHA256:891251514AA16F94485263C52FABA51BB5BB3495B9FAD382C74F6C9DA78718DD | |||
1604 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1604.33445\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Builder\Mono.Cecil.Pdb.dll | executable | |
MD5:6D5EB860C2BE5DBEB470E7D3F3E7DDA4 | SHA256:447EDE1984BB4ACD73BD97C0EC57A11C079CEE8301C91FB199CA98C1906D3CC4 | |||
1604 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1604.33445\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Builder\Kurome.Builder.pdb | pdb | |
MD5:E0468434C2489D74199641856A9C2265 | SHA256:713276677BCFB9FED27D545AB0B3591BF11FA9D6DD22739A00D43CB916A1A73F | |||
1604 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1604.33445\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Builder\Mono.Cecil.Mdb.dll | executable | |
MD5:1C6ACA0F1B1FA1661FC1E43C79334F7C | SHA256:411F8ED8C49738FA38A56ED8F991D556227D13602E83186E66AE1C4F821C940B | |||
1604 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1604.33445\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Builder\Mono.Cecil.pdb | binary | |
MD5:9A345FCE8746876DB39AA5622A771163 | SHA256:ECF13638359A5A9FE271966924CF543C4B440C2DC274E9D94069EF50BBC95482 | |||
1604 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1604.33445\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Builder\Mono.Cecil.Pdb.pdb | binary | |
MD5:711C5F65BD140E72EE30B33F14FBF100 | SHA256:7C3A6B12EF0676D3DC80A4E2B790F3DEC4D7FDAA182B2181C3F6EE283B118A9E | |||
1604 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1604.33445\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Builder\Mono.Cecil.Rocks.dll | executable | |
MD5:6E7F0F4FFF6C49E3F66127C23B7F1A53 | SHA256:2E2623319BDC362974A78EA4A43F4893011EC257884D24267F4594142FCD436E | |||
1604 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1604.33445\Redline_2021_stealer-main\Redline_2021_stealer-main\Kurome.Builder\Mono.Cecil.Rocks.pdb | binary | |
MD5:4C98B54BF658DB95DFB4D1AE6BED2565 | SHA256:5FCF9491B8D73F1F90A83EE7BDA9097043903BA18822F1F22EACF92338B0D619 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
924 | svchost.exe | HEAD | 403 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome/jskl2vqav7llvnpswum2rlzxee_97.0.4692.99/97.0.4692.99_chrome_installer.exe | US | — | — | whitelisted |
924 | svchost.exe | HEAD | 302 | 142.250.186.142:80 | http://redirector.gvt1.com/edgedl/release2/chrome/jskl2vqav7llvnpswum2rlzxee_97.0.4692.99/97.0.4692.99_chrome_installer.exe | US | — | — | whitelisted |
924 | svchost.exe | GET | — | 173.194.5.203:80 | http://r5---sn-aigl6n76.gvt1.com/edgedl/release2/chrome/jskl2vqav7llvnpswum2rlzxee_97.0.4692.99/97.0.4692.99_chrome_installer.exe?cms_redirect=yes&mh=Pg&mip=185.217.117.59&mm=28&mn=sn-aigl6n76&ms=nvh&mt=1643568539&mv=u&mvi=5&pl=25&rmhost=r3---sn-aigl6n76.gvt1.com&shardbypass=yes&smhost=r3---sn-aigl6ns6.gvt1.com | US | — | — | whitelisted |
2508 | GoogleUpdate.exe | GET | 403 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome/jskl2vqav7llvnpswum2rlzxee_97.0.4692.99/97.0.4692.99_chrome_installer.exe | US | text | 37 b | whitelisted |
924 | svchost.exe | HEAD | 200 | 173.194.5.203:80 | http://r5---sn-aigl6n76.gvt1.com/edgedl/release2/chrome/jskl2vqav7llvnpswum2rlzxee_97.0.4692.99/97.0.4692.99_chrome_installer.exe?cms_redirect=yes&mh=Pg&mip=185.217.117.59&mm=28&mn=sn-aigl6n76&ms=nvh&mt=1643568539&mv=u&mvi=5&pl=25&rmhost=r3---sn-aigl6n76.gvt1.com&shardbypass=yes&smhost=r3---sn-aigl6ns6.gvt1.com | US | — | — | whitelisted |
924 | svchost.exe | HEAD | 403 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome/jskl2vqav7llvnpswum2rlzxee_97.0.4692.99/97.0.4692.99_chrome_installer.exe | US | — | — | whitelisted |
2508 | GoogleUpdate.exe | GET | 403 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome/jskl2vqav7llvnpswum2rlzxee_97.0.4692.99/97.0.4692.99_chrome_installer.exe | US | text | 37 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3364 | GoogleUpdate.exe | 142.250.185.99:443 | update.googleapis.com | Google Inc. | US | whitelisted |
2508 | GoogleUpdate.exe | 142.250.185.99:443 | update.googleapis.com | Google Inc. | US | whitelisted |
924 | svchost.exe | 34.104.35.123:80 | edgedl.me.gvt1.com | — | US | whitelisted |
2508 | GoogleUpdate.exe | 34.104.35.123:80 | edgedl.me.gvt1.com | — | US | whitelisted |
924 | svchost.exe | 142.250.186.142:80 | redirector.gvt1.com | Google Inc. | US | whitelisted |
924 | svchost.exe | 173.194.5.203:80 | r5---sn-aigl6n76.gvt1.com | Google Inc. | US | whitelisted |
3576 | GoogleUpdate.exe | 142.250.185.99:443 | update.googleapis.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
update.googleapis.com |
| whitelisted |
edgedl.me.gvt1.com |
| whitelisted |
redirector.gvt1.com |
| whitelisted |
r5---sn-aigl6n76.gvt1.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
— | — | Misc activity | ET INFO EXE - Served Attached HTTP |