Hash / BilgiDeger
SHA256fd9ac1e2f891b86ca0a5949521259ca4a89c0b8e23555bc4938eab185230cc6a
MD5571526093d8239f3f7ecf11992beaa1d
SHA1ece9c8f061220dc2390f1f1e83a3ae825e551a4e
ImpHash445554923421947cbff896012e27345a
Dosya AdiGalaxySkinChanger.exe
Dosya Türüexe
Boyut4,164,760 bytes
Ilk Görülme2022-02-19

Tehdit Degerlendirmesi

Bu ornek, etkilenen sistemlerdeki hassas kimlik bilgilerini ve kisisel verileri toplayan bir bilgi hırsızı (infostealer) olarak siniflandirilmistir. Tarayici kayitli parolalar, cerezler, kripto para cüzdani verileri ve oturum tokenlari birincil hedefleridir.

Tespit Edilen Yetenekler

  • Tarayici Kimlik Bilgileri
  • Cerez Hirsizligi
  • Kripto Cüzdan
  • 2FA Kodu
  • Sistem Bilgisi

MalwareBazaar Etiketleri

exeRedlineRedLineStealer

Analiz Notu

Bu ornek RedLine ailesine ait ve MalwareBazaar platformundan alınmıstır. KEYDAL Guvenlik Arastirmaları tarafından metadata analizi gerceklestirilmis ve IOC veritabanına eklenmistir.

RedLine — Malware Profile

RedLine Stealer. QUOTATION lure. PCRE regex library. Form-grabbing. Credential theft.

Malware Type
Infostealer
Programming Language
.NET C#
C2 Protocol
HTTPS
Target Systems
Windows
Also Known As (AKA)
RedLine Stealer

Technical Details

.NET, gRPC C2 protokolu, browser credential theft (tum Chromium/Firefox tabanlılar), cryptocurrency wallet stealer, VPN credential stealer, Discord/Steam token stealer

Attribution / Threat Actor

Rusca konusulan gelistirici/operatorler; MaaS modeli ile cok sayida musteriye hizmet. 2024 Operasyon Magnus'ta birden fazla sunucu operatoru gozaltina alinmistir.

Capabilities & Behavior

Tarayıcı Kimlik Bilgileri
Çerez Hırsızlığı
Kripto Cüzdan Çalma
Sistem Bilgisi
Ekran Görüntüsü
FTP/SSH İstemci Şifreleri
E-posta İstemcisi Çalma
Veri Sızıntısı

IOC List (21 indicators)

IOC — RedLine
# SHA256 fd9ac1e2f891b86ca0a5949521259ca4a89c0b8e23555bc4938eab185230cc6a # MD5 571526093d8239f3f7ecf11992beaa1d # IP 45.142.212.100 # IP 193.56.255.42 # IP 5.188.87.39 # IP 103.224.241.163 # IP 185.220.101.47 # IP 185.246.188.111 # IP 91.92.255.73 # IP 45.87.153.97 # DOMAIN panel-redline.ru # DOMAIN redlinestealer.gg # DOMAIN browser-data.xyz # DOMAIN redline-stealer-panel.com # MUTEX RedLineMutex_4aZ2xW # MUTEX RedLine_Mutex_v21 # REGISTRY HKCUSoftwareLocal App WizardPackages{e1b2c} # REGISTRY HKCUSoftwareMicrosoftWindowsCurrentVersionRunRedLine # FILEPATH %APPDATA%RedLineRedLine.exe # FILEPATH %LOCALAPPDATA%TempRedLineRunner.exe # URL https://redline-builds.ru/client.exe
TypeValueNote
sha256 fd9ac1e2f891b86ca0a5949521259ca4a89c0b8e23555bc4938eab185230cc6a
md5 571526093d8239f3f7ecf11992beaa1d
ip 45.142.212.100 C2:11821
ip 193.56.255.42 C2:15000
ip 5.188.87.39 C2:30000
ip 103.224.241.163 C2:443
ip 185.220.101.47 C2:80
ip 185.246.188.111 RedLine Stealer C2 panel
ip 91.92.255.73 RedLine C2 Rusya IP
ip 45.87.153.97 RedLine payload server
domain panel-redline.ru RedLine Stealer C2 panel domain
domain redlinestealer.gg RedLine distribution domain
domain browser-data.xyz RedLine exfiltration endpoint
domain redline-stealer-panel.com RedLine panel domain
mutex RedLineMutex_4aZ2xW RedLine Stealer mutex - sifrelenmemis
mutex RedLine_Mutex_v21 RedLine Stealer mutex
registry HKCUSoftwareLocal App WizardPackages{e1b2c} RedLine Stealer data storage key
registry HKCUSoftwareMicrosoftWindowsCurrentVersionRunRedLine RedLine Stealer autorun
filepath %APPDATA%RedLineRedLine.exe RedLine Stealer persistence
filepath %LOCALAPPDATA%TempRedLineRunner.exe RedLine Stealer runner dosyasi
url https://redline-builds.ru/client.exe RedLine Stealer builder URL

C2 Servers (8 recorded servers for this family)

Address Type Port Protocol Status Country
github.com domain — HTTP active —
185.220.101.47 ip 80 HTTP active DE
103.224.241.163 ip 443 HTTPS inactive SG
45.142.212.100 ip 11821 TCP inactive —
193.56.255.42 ip 15000 TCP inactive —
5.188.87.39 ip 30000 TCP inactive —
46.205.202.219 ip 1912 TCP inactive —
217.65.2.14 ip 1912 TCP inactive —

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
exeRedlineRedLineStealer