| File name: | EXloader.exe |
| Full analysis: | https://app.any.run/tasks/4e51100c-9ec1-4490-8f12-76419aaf56e3 |
| Verdict: | Malicious activity |
| Threats: | RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware. |
| Analysis date: | December 04, 2023, 14:06:06 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (console) Intel 80386, for MS Windows |
| MD5: | 51E3263209ED14CF22023D1EEF0106E6 |
| SHA1: | 92F4AF01B69A116EF2859A641A5C0F00874211C4 |
| SHA256: | E069E3136F52F56534F1FD933715AB405092A3B04816B7827D80DF6B1D610A7E |
| SSDEEP: | 6144:JVOYqFcSe/F9Gg3udfMUoh4+5OORW1puuwSluyPa/aSwPc9Ue1z105UYkMWGzhqH:JVOYrDF8SwMFke |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:11:29 14:45:06+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 49664 |
| InitializedDataSize: | 240128 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x3e12 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 564 | "C:\Users\admin\AppData\Local\Temp\EXloader.exe" | C:\Users\admin\AppData\Local\Temp\EXloader.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
RedLine(PID) Process(564) EXloader.exe C2 (1)45.15.156.142:33597 Botnet@Oleheskevich Options ErrorMessage Keys XorOnsetting | |||||||||||||||
| 1584 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (564) EXloader.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: 4DEA41326EDF70A35FBB0647C0F9AFC708143819D1A9237ABCE41C1766A1B1FA | |||
| (PID) Process: | (564) EXloader.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Users\admin\AppData\Local\Google\Chrome\User Data\lockfile | |||
| (PID) Process: | (564) EXloader.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (564) EXloader.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: E9AED17232AF15579B72090E22A8CD968A0B6A9C20B3B2940E3D32535BD7EE86 | |||
| (PID) Process: | (564) EXloader.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Owner |
Value: 3402000050B40B0ABB26DA01 | |||
| (PID) Process: | (564) EXloader.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (564) EXloader.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: 66BA55135471C8F4D1F4FCA4CC89C0D8DB16926D319BA321955FE87EA11AA749 | |||
| (PID) Process: | (564) EXloader.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\lockfile | |||
| (PID) Process: | (564) EXloader.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: 91965F1D1DD705FDD0EAAB12AF1EF4405F147304A60581BAAB2CB00E43E85142 | |||
| (PID) Process: | (564) EXloader.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: 6E82FE4A8CD531F1C74E16C47B5E022D3E260B31A62D21F5111812EBFA781D71 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
564 | EXloader.exe | 45.15.156.142:33597 | — | Galaxy LLC | RU | malicious |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
564 | EXloader.exe | Potentially Bad Traffic | ET INFO Microsoft net.tcp Connection Initialization Activity |
564 | EXloader.exe | A Network Trojan was detected | ET MALWARE Redline Stealer TCP CnC Activity |
564 | EXloader.exe | A Network Trojan was detected | ET MALWARE [ANY.RUN] RedLine Stealer Family Related (MC-NMF Authorization) |
564 | EXloader.exe | A Network Trojan was detected | ET MALWARE Redline Stealer TCP CnC - Id1Response |
564 | EXloader.exe | A Network Trojan was detected | ET MALWARE Redline Stealer TCP CnC Activity |
564 | EXloader.exe | A Network Trojan was detected | ET MALWARE Redline Stealer Family Activity (Response) |
564 | EXloader.exe | Successful Credential Theft Detected | SUSPICIOUS [ANY.RUN] Clear Text Password Exfiltration Atempt |
564 | EXloader.exe | Successful Credential Theft Detected | SUSPICIOUS [ANY.RUN] Clear Text Password Exfiltration Atempt |
564 | EXloader.exe | A Network Trojan was detected | ET MALWARE Redline Stealer TCP CnC Activity |