File name:

cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe

Full analysis: https://app.any.run/tasks/291569ba-dcaa-4491-8f40-68f185f781e0
Verdict: Malicious activity
Threats:

RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.

Analysis date: May 16, 2025, 03:03:57
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto
stealer
redline
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

BFCDF54C80930C5AFA8861D57C60E173

SHA1:

B9F057764EDD709665C95E90EE104D4131145677

SHA256:

CF5D83EF8F30332284BF5A6B7B11B3EA119BEAD357CD3508FB5D72CEAFEA1B5F

SSDEEP:

3072:GzvOp90TY6SA20EvIVBJmyxCqsKKiWbMT1kINI:A5ljEwPWiWb81kIW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • REDLINE has been found (auto)

      • cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe (PID: 6036)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe (PID: 6036)
    • Executable content was dropped or overwritten

      • cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe (PID: 6036)
    • Starts CMD.EXE for commands execution

      • cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe (PID: 6036)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 6516)
    • Executing commands from a ".bat" file

      • cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe (PID: 6036)
    • Creates file in the systems drive root

      • cmd.exe (PID: 6516)
  • INFO

    • Create files in a temporary directory

      • cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe (PID: 6036)
    • Checks supported languages

      • cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe (PID: 6036)
      • windows.exe (PID: 456)
    • Reads the computer name

      • windows.exe (PID: 456)
      • cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe (PID: 6036)
    • Process checks computer location settings

      • cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe (PID: 6036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (41)
.exe | Win64 Executable (generic) (36.3)
.dll | Win32 Dynamic Link Library (generic) (8.6)
.exe | Win32 Executable (generic) (5.9)
.exe | Win16/32 Executable Delphi generic (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:07:30 08:52:50+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 2.5
CodeSize: 68608
InitializedDataSize: 30208
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #REDLINE cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe cmd.exe no specs conhost.exe no specs windows.exe no specs timeout.exe no specs conhost.exe no specs sppextcomobj.exe no specs slui.exe no specs cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
456windows.exe C:\Users\admin\AppData\Local\Temp\windows.execmd.exe
User:
admin
Integrity Level:
HIGH
Description:
SimpleMbrOverride
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\windows.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1628\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3156timeout /t 30 /nobreak C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4300"C:\Users\admin\AppData\Local\Temp\cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe" C:\Users\admin\AppData\Local\Temp\cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5064\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exewindows.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6036"C:\Users\admin\AppData\Local\Temp\cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe" C:\Users\admin\AppData\Local\Temp\cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6184C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6516"C:\WINDOWS\sysnative\cmd.exe" /c "C:\Users\admin\AppData\Local\Temp\B6DE.tmp\B6DF.tmp\B6E0.bat C:\Users\admin\AppData\Local\Temp\cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe"C:\Windows\System32\cmd.execf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
6872"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
430
Read events
430
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
456windows.exe\Device\Harddisk0\DR0
MD5:
SHA256:
6036cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exeC:\Users\admin\AppData\Local\Temp\visualpayloads.exeexecutable
MD5:16BE61B70227E6618916BD1039D77421
SHA256:EE4433694C5BFC9B1B1147B4D1A42D0EEBDDF74893DE1BFA814310648DA32EBA
6516cmd.exeC:\vbs.vbstext
MD5:530252EA9A425008A3BB9F9E642AB595
SHA256:02180BA45AD8FE9A406A8ECE82426128444C5E89B715D2E236D24D59709520E6
6036cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exeC:\Users\admin\AppData\Local\Temp\B6DE.tmp\B6DF.tmp\B6E0.battext
MD5:29ACBE606BFAAB9315F59B16A2598090
SHA256:07E9E1A1140EEF8B447CFCE2321533A150E6E0A9F6B066BF6EA4B8C866D0EC26
6036cf5d83ef8f30332284bf5a6b7b11b3ea119bead357cd3508fb5d72ceafea1b5f.exeC:\Users\admin\AppData\Local\Temp\windows.exeexecutable
MD5:E74B01104277AE90E12B8F9428039356
SHA256:C18981AAD433A362EEFC7EE537A475F418714E515D4039D51EFE0D161EB64651
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
15
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 216.58.206.46
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
  • 23.216.77.42
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
login.live.com
  • 20.190.160.130
  • 40.126.32.136
  • 20.190.160.2
  • 40.126.32.138
  • 20.190.160.20
  • 20.190.160.64
  • 20.190.160.128
  • 40.126.32.68
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted

Threats

No threats detected
No debug info