Managed XDR

41f92844c0f4071bc76a98e8ad6562c7.virus (RedLine Stealer) — malware analysis report

File info

Filename
41f92844c0f4071bc76a98e8ad6562c7.virus
File type
PE32 executable (GUI) Intel 80386, for MS Windows
File size
385 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
d60eba5e6fb0193f8b24f5e3a4e629201ff29d1b
SHA256
d5f2be31318db9b2d45635fea78ec59cd2f4c5e88ff5f9ecf07662763f07b756
MD5
41f92844c0f4071bc76a98e8ad6562c7

Malwares

  • RedLine Stealer

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_entropy: Probably contains compressed or encrypted data
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
message_box: Displays a message
get_policy_info: Retrieves information about a Policy object

Related reports