File name:

file

Full analysis: https://app.any.run/tasks/5cb71308-2348-4b64-83d6-eac32b0b13e8
Verdict: Malicious activity
Threats:

RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.

Analysis date: December 02, 2023, 22:05:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
stealer
redline
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

68E2805D7119C9B5B7949FD2C5911DFD

SHA1:

29FD3AB681EBCE74BB5D9405B718726798DBBEF4

SHA256:

622C4D7DE8F68D445B84F9D3A4B07247519033C1F18A4A69BE435B448EB42DA2

SSDEEP:

3072:Pe9HH6YpY1Rb1m/xXBEDFzsw98cNc+g0umienpvEG1DhqX/aiEKvjXy:G9HaYpkb1EBEDFzsXLr0uMnFEgqSTKe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • file.exe (PID: 2128)
    • REDLINE has been detected (SURICATA)

      • file.exe (PID: 2128)
    • Actions looks like stealing of personal data

      • file.exe (PID: 2128)
  • SUSPICIOUS

    • Searches for installed software

      • file.exe (PID: 2128)
    • Reads browser cookies

      • file.exe (PID: 2128)
    • Connects to unusual port

      • file.exe (PID: 2128)
  • INFO

    • Checks supported languages

      • file.exe (PID: 2128)
    • Reads the computer name

      • file.exe (PID: 2128)
    • Reads Environment values

      • file.exe (PID: 2128)
    • Reads the machine GUID from the registry

      • file.exe (PID: 2128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (42.6)
.exe | Win16/32 Executable Delphi generic (19.5)
.exe | Generic Win/DOS Executable (18.9)
.exe | DOS Executable Generic (18.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: -
CodeSize: -
InitializedDataSize: -
UninitializedDataSize: -
EntryPoint: 0x5561
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows command line
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #REDLINE file.exe

Process information

PID
CMD
Path
Indicators
Parent process
2128"C:\Users\admin\AppData\Local\Temp\file.exe" C:\Users\admin\AppData\Local\Temp\file.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\file.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
2 970
Read events
2 970
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
5

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
2128
file.exe
176.123.10.211:47430
Alexhost Srl
MD
malicious
324
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

PID
Process
Class
Message
2128
file.exe
Potentially Bad Traffic
ET INFO Microsoft net.tcp Connection Initialization Activity
2128
file.exe
A Network Trojan was detected
ET MALWARE [ANY.RUN] RedLine Stealer Family Related (MC-NMF Authorization)
2128
file.exe
A Network Trojan was detected
ET MALWARE Redline Stealer Family Activity (Response)
2128
file.exe
Successful Credential Theft Detected
SUSPICIOUS [ANY.RUN] Clear Text Password Exfiltration Atempt
2128
file.exe
Successful Credential Theft Detected
SUSPICIOUS [ANY.RUN] Clear Text Password Exfiltration Atempt
No debug info