File name:

pornhub premuim for pc.exe

Full analysis: https://app.any.run/tasks/51b08720-f0b0-496d-9703-30034b03aaed
Verdict: Malicious activity
Threats:

RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.

Analysis date: February 18, 2024, 21:01:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
stealer
redline
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

675456672D1B814D793D195FC47A3DC8

SHA1:

180FCAE12B42EDC6A36AB1F8D3DC66F5F5627915

SHA256:

D8751EED96DF9C9777B56438250140686AE2982034D91635703937462BCC4FC3

SSDEEP:

12288:iHXeUazxSTRTXaNCQ4BT2/loqSIltIp34pjbLt6IX0F4Wm72z+X0g4AxQaRO4CjE:it+STRTXaNCQ4BT29oqSIltIp34pjbLg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • pornhub premuim for pc.exe (PID: 4052)
    • Connects to the CnC server

      • pornhub premuim for pc.exe (PID: 4052)
    • REDLINE has been detected (SURICATA)

      • pornhub premuim for pc.exe (PID: 4052)
    • Steals credentials from Web Browsers

      • pornhub premuim for pc.exe (PID: 4052)
    • REDLINE has been detected (YARA)

      • pornhub premuim for pc.exe (PID: 4052)
    • Actions looks like stealing of personal data

      • pornhub premuim for pc.exe (PID: 4052)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • pornhub premuim for pc.exe (PID: 4052)
    • Reads the Internet Settings

      • pornhub premuim for pc.exe (PID: 4052)
    • Reads browser cookies

      • pornhub premuim for pc.exe (PID: 4052)
    • Searches for installed software

      • pornhub premuim for pc.exe (PID: 4052)
  • INFO

    • Reads the computer name

      • pornhub premuim for pc.exe (PID: 4052)
    • Checks supported languages

      • pornhub premuim for pc.exe (PID: 4052)
    • Reads the machine GUID from the registry

      • pornhub premuim for pc.exe (PID: 4052)
    • Reads Environment values

      • pornhub premuim for pc.exe (PID: 4052)
    • Reads product name

      • pornhub premuim for pc.exe (PID: 4052)
    • Reads the software policy settings

      • pornhub premuim for pc.exe (PID: 4052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

RedLine

(PID) Process(4052) pornhub premuim for pc.exe
C2 (1)45.15.156.167:80
Botnet@Ebursteamss
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorHammock
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: -
CodeSize: -
InitializedDataSize: -
UninitializedDataSize: -
EntryPoint: 0x5f22
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows command line
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #REDLINE pornhub premuim for pc.exe

Process information

PID
CMD
Path
Indicators
Parent process
4052"C:\Users\admin\AppData\Local\Temp\pornhub premuim for pc.exe" C:\Users\admin\AppData\Local\Temp\pornhub premuim for pc.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\pornhub premuim for pc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
RedLine
(PID) Process(4052) pornhub premuim for pc.exe
C2 (1)45.15.156.167:80
Botnet@Ebursteamss
Options
ErrorMessageClick Close to exit the program. Error code: 1142
Keys
XorHammock
Total events
5 695
Read events
5 640
Write events
37
Delete events
18

Modification events

(PID) Process:(4052) pornhub premuim for pc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pornhub premuim for pc_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4052) pornhub premuim for pc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pornhub premuim for pc_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(4052) pornhub premuim for pc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pornhub premuim for pc_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(4052) pornhub premuim for pc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pornhub premuim for pc_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(4052) pornhub premuim for pc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pornhub premuim for pc_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(4052) pornhub premuim for pc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pornhub premuim for pc_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(4052) pornhub premuim for pc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pornhub premuim for pc_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4052) pornhub premuim for pc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pornhub premuim for pc_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(4052) pornhub premuim for pc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pornhub premuim for pc_RASMANCS
Operation:writeName:FileTracingMask
Value:
(PID) Process:(4052) pornhub premuim for pc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\pornhub premuim for pc_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
10

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4052
pornhub premuim for pc.exe
45.15.156.167:80
Galaxy LLC
RU
malicious
4052
pornhub premuim for pc.exe
104.26.12.31:443
api.ip.sb
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
api.ip.sb
  • 104.26.12.31
  • 104.26.13.31
  • 172.67.75.172
whitelisted

Threats

PID
Process
Class
Message
4052
pornhub premuim for pc.exe
Potentially Bad Traffic
ET INFO Microsoft net.tcp Connection Initialization Activity
4052
pornhub premuim for pc.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC Activity
4052
pornhub premuim for pc.exe
A Network Trojan was detected
ET MALWARE [ANY.RUN] RedLine Stealer/MetaStealer Family Related (MC-NMF Authorization)
4052
pornhub premuim for pc.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC - Id1Response
4052
pornhub premuim for pc.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC Activity
4052
pornhub premuim for pc.exe
Successful Credential Theft Detected
STEALER [ANY.RUN] Clear Text Password Exfiltration Atempt
4052
pornhub premuim for pc.exe
Successful Credential Theft Detected
STEALER [ANY.RUN] Clear Text Password Exfiltration Atempt
4052
pornhub premuim for pc.exe
A Network Trojan was detected
ET MALWARE Redline Stealer TCP CnC Activity
2 ETPRO signatures available at the full report
No debug info