| File name: | Redline stealer 2022 Crack.zip |
| Full analysis: | https://app.any.run/tasks/ff52c2f8-e76f-4961-9478-2a0ea839ea0d |
| Verdict: | Malicious activity |
| Threats: | AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions. |
| Analysis date: | November 23, 2023, 13:07:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 9F2B4AFA22391D606B3577CB8DFAC6FE |
| SHA1: | 51F3E0D2CF684B8246F500534929706D61B6B842 |
| SHA256: | 91FDDF7CDF9462984D929296EB1F0ADD771532117E921EF85272FC12BC796C9E |
| SSDEEP: | 98304:w+T6a7NCbD+Zr3of0LNhXvJIXrAFqHnpsezuW33p4dfx+MkuVV84mzmP76Yf2nZz:QqHRRvkP |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2023:09:12 20:59:58 |
| ZipCRC: | 0x4e87ef64 |
| ZipCompressedSize: | 90 |
| ZipUncompressedSize: | 107 |
| ZipFileName: | Redline stealer 2022 Crack/gbpast - Login.url |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 304 | "C:\Windows\system32\msconfig.exe" | C:\Windows\System32\msconfig.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: System Configuration Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 368 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 608 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Local\Temp\svchost.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | Build.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 756 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Local\Temp\utorrent.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | Build.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1344 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Local\Temp\cfmon.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | Build.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1356 | "C:\Users\admin\AppData\Local\Temp\svchost.exe" | C:\Users\admin\AppData\Local\Temp\svchost.exe | Build.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 3.6.0.0 Modules
| |||||||||||||||
| 1852 | "C:\Users\admin\AppData\Local\Temp\utorrent.exe" | C:\Users\admin\AppData\Local\Temp\utorrent.exe | Build.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 2148734499 Version: 6.0.1 Modules
| |||||||||||||||
| 2028 | "C:\Users\admin\AppData\Local\Temp\cfmon.exe" | C:\Users\admin\AppData\Local\Temp\cfmon.exe | Build.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3200 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3236 | "C:\Users\admin\Desktop\Loader.exe" | C:\Users\admin\Desktop\Loader.exe | — | Build.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3440) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3440) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3440) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3440) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3440) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3440) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3440) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3440) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3440) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3440) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3440 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Libraries\builder.exe | executable | |
MD5:DE6F68CDF350FCE9BE13803D84BE98C4 | SHA256:51BBC69942823B84C2A1F0EFDB9D63FB04612B223E86AF8A83B4B307DD15CD24 | |||
| 3440 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Home - cybergoons.url | binary | |
MD5:EF51820E228C5BBCF9AABE92E747782E | SHA256:59AC2D12EA4559253FA25F2D367F75B7689BB7B772965101903063F646AE9B4D | |||
| 3440 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Home - blankhack.url | binary | |
MD5:4A4418C24D2F2A9DEEE8046363BDD28F | SHA256:55DFE247F8FD6A8B0B66B3CB61FEEAE96D0B357338CD95771E89897AAC1A6839 | |||
| 3440 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\learn all kind of hacking.url | binary | |
MD5:7ADE4A739CBD8F44D0EF52A2F1BC6E7B | SHA256:CC7649ED53C65E4851ACE414529564FE16801BB2BED4CB15588BFD6B4AC13616 | |||
| 3440 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\gbpast - Login.url | binary | |
MD5:4A4F5BE9370E206241BB73BFC2367F3C | SHA256:210F2EE620FE51ACDBE59BBA7BB4ACBDE397034818B09156F6F0874B016A5B18 | |||
| 3440 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Libraries\builder.pdb | binary | |
MD5:418DC008EF956465E179EC29D3C3C245 | SHA256:8C7E21B37540211D56C5FDBB7E731655A96945AA83F2988E33D5ADB8AA7C8DF1 | |||
| 3440 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Libraries\Bunifu_UI_v1.52.dll | executable | |
MD5:5ECA94D909F1BA4C5F3E35AC65A49076 | SHA256:DE0E530D46C803D85B8AEB6D18816F1B09CB3DAFEFB5E19FDFA15C9F41E0F474 | |||
| 3440 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Libraries\GuiLib.dll | executable | |
MD5:EAF9C55793CD26F133708714ED3A5397 | SHA256:87CFC70BEC2D2A37BCD5D46F9E6F0051F82E015FF96E8F2BC2D81B85F2632F15 | |||
| 3440 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Libraries\Loader.exe | executable | |
MD5:CFF63E16C0F61DA3CF1329EBCF462773 | SHA256:E3BD0202BA4C688CA4C5917BC6892808089246968FACF6FF8AF52028FB0FFF6E | |||
| 3440 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3440.32452\Redline stealer 2022 Crack\Libraries\MetroSet UI.dll | binary | |
MD5:F13DC3CFFEF729D26C4DA102674561CF | SHA256:D490C04E6E89462FD46099D3454985F319F57032176C67403B3B92C86CA58BCB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
828 | svchost.exe | OPTIONS | — | 185.235.129.102:80 | http://blankhack.com/ | NL | — | — | unknown |
828 | svchost.exe | PROPFIND | 200 | 185.235.129.102:80 | http://blankhack.com/ | NL | html | 35.5 Kb | unknown |
828 | svchost.exe | PROPFIND | 200 | 185.235.129.102:80 | http://blankhack.com/ | NL | html | 35.5 Kb | unknown |
828 | svchost.exe | PROPFIND | — | 185.235.129.102:80 | http://blankhack.com/ | NL | — | — | unknown |
828 | svchost.exe | PROPFIND | 200 | 185.235.129.102:80 | http://blankhack.com/ | NL | html | 35.5 Kb | unknown |
828 | svchost.exe | PROPFIND | — | 185.235.129.102:80 | http://blankhack.com/ | NL | — | — | unknown |
1356 | svchost.exe | GET | 200 | 23.53.40.73:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d0ed9152b953db0d | DE | compressed | 61.6 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1356 | svchost.exe | 206.123.140.95:3232 | — | M247 Ltd | DE | malicious |
1356 | svchost.exe | 23.53.40.73:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
2028 | cfmon.exe | 206.123.140.95:7000 | — | M247 Ltd | DE | malicious |
828 | svchost.exe | 185.235.129.102:80 | blankhack.com | Zomro B.V. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
ctldl.windowsupdate.com |
| whitelisted |
blankhack.com |
| unknown |
dns.msftncsi.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
1356 | svchost.exe | Domain Observed Used for C2 Detected | REMOTE [ANY.RUN] AsyncRAT SSL certificate |
1356 | svchost.exe | Malware Command and Control Activity Detected | REMOTE [ANY.RUN] AsyncRAT Successful Connection |
2028 | cfmon.exe | Malware Command and Control Activity Detected | SUSPICIOUS [ANY.RUN] Possible Xworm Network Packet |
2028 | cfmon.exe | Malware Command and Control Activity Detected | SUSPICIOUS [ANY.RUN] Possible Xworm Network Packet |
Process | Message |
|---|---|
utorrent.exe | CLR: Managed code called FailFast without specifying a reason.
|