0.3.VBY5zBdZox.exe.27d0000.0.raw.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.3.VBY5zBdZox.exe.27d0000.0.raw.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x1d0b0:$s1: 23 00 2B 00 33 00 3B 00 43 00 53 00 63 00 73 00
- 0x80:$s2: 68 10 84 2D 2C 71 EA 7E 2C 71 EA 7E 2C 71 EA 7E 32 23 7F 7E 3F 71 EA 7E 0B B7 91 7E 2B 71 EA 7E 2C 71 EB 7E 5C 71 EA 7E 32 23 6E 7E 1C 71 EA 7E 32 23 69 7E A2 71 EA 7E 32 23 7B 7E 2D 71 EA 7E
- 0x700:$s3: 83 EC 38 53 B0 87 88 44 24 2B 88 44 24 2F B0 AB 88 44 24 30 88 44 24 31 88 44 24 33 55 56 8B F1 B8 0C 00 FE FF 2B C6 89 44 24 14 B8 0D 00 FE FF 2B C6 89 44 24 1C B8 02 00 FE FF 2B C6 89 44 24 ...
- 0x1ed8a:$s4: B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
- 0x1e9d0:$s5: delete[]
- 0x1de88:$s6: constructor or from DllMain.
|
0.2.VBY5zBdZox.exe.2950ee8.2.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.2.VBY5zBdZox.exe.2950ee8.2.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x25a56:$pat14: , CommandLine:
- 0x1a21a:$v2_1: ListOfProcesses
- 0x199bd:$v4_3: base64str
- 0x1998a:$v4_4: stringKey
- 0x199c7:$v4_5: BytesToStringConverted
- 0x199b2:$v4_6: FromBase64
- 0x19ed5:$v4_8: procName
- 0x17b1d:$v5_7: RecordHeaderField
- 0x17a59:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
|
0.2.VBY5zBdZox.exe.2a63a26.5.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.2.VBY5zBdZox.exe.2a63a26.5.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x2693e:$pat14: , CommandLine:
- 0x1b102:$v2_1: ListOfProcesses
- 0x1a8a5:$v4_3: base64str
- 0x1a872:$v4_4: stringKey
- 0x1a8af:$v4_5: BytesToStringConverted
- 0x1a89a:$v4_6: FromBase64
- 0x1adbd:$v4_8: procName
- 0x18a05:$v5_7: RecordHeaderField
- 0x18941:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
|
0.2.VBY5zBdZox.exe.5150000.6.raw.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.2.VBY5zBdZox.exe.5150000.6.raw.unpack | JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | |
0.2.VBY5zBdZox.exe.5150000.6.raw.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x27856:$pat14: , CommandLine:
- 0x1c01a:$v2_1: ListOfProcesses
- 0x1b7bd:$v4_3: base64str
- 0x1b78a:$v4_4: stringKey
- 0x1b7c7:$v4_5: BytesToStringConverted
- 0x1b7b2:$v4_6: FromBase64
- 0x1bcd5:$v4_8: procName
- 0x1991d:$v5_7: RecordHeaderField
- 0x19859:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
|
0.3.VBY5zBdZox.exe.c15928.1.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.3.VBY5zBdZox.exe.c15928.1.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x25a56:$pat14: , CommandLine:
- 0x1a21a:$v2_1: ListOfProcesses
- 0x199bd:$v4_3: base64str
- 0x1998a:$v4_4: stringKey
- 0x199c7:$v4_5: BytesToStringConverted
- 0x199b2:$v4_6: FromBase64
- 0x19ed5:$v4_8: procName
- 0x17b1d:$v5_7: RecordHeaderField
- 0x17a59:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
|
0.2.VBY5zBdZox.exe.2950000.3.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.2.VBY5zBdZox.exe.2950000.3.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x2693e:$pat14: , CommandLine:
- 0x1b102:$v2_1: ListOfProcesses
- 0x1a8a5:$v4_3: base64str
- 0x1a872:$v4_4: stringKey
- 0x1a8af:$v4_5: BytesToStringConverted
- 0x1a89a:$v4_6: FromBase64
- 0x1adbd:$v4_8: procName
- 0x18a05:$v5_7: RecordHeaderField
- 0x18941:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
|
0.2.VBY5zBdZox.exe.2a6490e.4.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.2.VBY5zBdZox.exe.2a6490e.4.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x25a56:$pat14: , CommandLine:
- 0x1a21a:$v2_1: ListOfProcesses
- 0x199bd:$v4_3: base64str
- 0x1998a:$v4_4: stringKey
- 0x199c7:$v4_5: BytesToStringConverted
- 0x199b2:$v4_6: FromBase64
- 0x19ed5:$v4_8: procName
- 0x17b1d:$v5_7: RecordHeaderField
- 0x17a59:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
|
0.2.VBY5zBdZox.exe.2950000.3.raw.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.2.VBY5zBdZox.exe.2950000.3.raw.unpack | JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | |
0.2.VBY5zBdZox.exe.2950000.3.raw.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x2873e:$pat14: , CommandLine:
- 0x1cf02:$v2_1: ListOfProcesses
- 0x1c6a5:$v4_3: base64str
- 0x1c672:$v4_4: stringKey
- 0x1c6af:$v4_5: BytesToStringConverted
- 0x1c69a:$v4_6: FromBase64
- 0x1cbbd:$v4_8: procName
- 0x1a805:$v5_7: RecordHeaderField
- 0x1a741:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
|
0.2.VBY5zBdZox.exe.400000.0.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.2.VBY5zBdZox.exe.400000.0.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x1d0b0:$s1: 23 00 2B 00 33 00 3B 00 43 00 53 00 63 00 73 00
- 0x80:$s2: 68 10 84 2D 2C 71 EA 7E 2C 71 EA 7E 2C 71 EA 7E 32 23 7F 7E 3F 71 EA 7E 0B B7 91 7E 2B 71 EA 7E 2C 71 EB 7E 5C 71 EA 7E 32 23 6E 7E 1C 71 EA 7E 32 23 69 7E A2 71 EA 7E 32 23 7B 7E 2D 71 EA 7E
- 0x700:$s3: 83 EC 38 53 B0 87 88 44 24 2B 88 44 24 2F B0 AB 88 44 24 30 88 44 24 31 88 44 24 33 55 56 8B F1 B8 0C 00 FE FF 2B C6 89 44 24 14 B8 0D 00 FE FF 2B C6 89 44 24 1C B8 02 00 FE FF 2B C6 89 44 24 ...
- 0x1ed8a:$s4: B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
- 0x1e9d0:$s5: delete[]
- 0x1de88:$s6: constructor or from DllMain.
|
0.2.VBY5zBdZox.exe.2a6490e.4.raw.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.2.VBY5zBdZox.exe.2a6490e.4.raw.unpack | JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | |
0.2.VBY5zBdZox.exe.2a6490e.4.raw.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x27856:$pat14: , CommandLine:
- 0x1c01a:$v2_1: ListOfProcesses
- 0x1b7bd:$v4_3: base64str
- 0x1b78a:$v4_4: stringKey
- 0x1b7c7:$v4_5: BytesToStringConverted
- 0x1b7b2:$v4_6: FromBase64
- 0x1bcd5:$v4_8: procName
- 0x1991d:$v5_7: RecordHeaderField
- 0x19859:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
|
0.2.VBY5zBdZox.exe.5150000.6.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.2.VBY5zBdZox.exe.5150000.6.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x25a56:$pat14: , CommandLine:
- 0x1a21a:$v2_1: ListOfProcesses
- 0x199bd:$v4_3: base64str
- 0x1998a:$v4_4: stringKey
- 0x199c7:$v4_5: BytesToStringConverted
- 0x199b2:$v4_6: FromBase64
- 0x19ed5:$v4_8: procName
- 0x17b1d:$v5_7: RecordHeaderField
- 0x17a59:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
|
0.2.VBY5zBdZox.exe.400000.0.raw.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.2.VBY5zBdZox.exe.400000.0.raw.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x1e4b0:$s1: 23 00 2B 00 33 00 3B 00 43 00 53 00 63 00 73 00
- 0x80:$s2: 68 10 84 2D 2C 71 EA 7E 2C 71 EA 7E 2C 71 EA 7E 32 23 7F 7E 3F 71 EA 7E 0B B7 91 7E 2B 71 EA 7E 2C 71 EB 7E 5C 71 EA 7E 32 23 6E 7E 1C 71 EA 7E 32 23 69 7E A2 71 EA 7E 32 23 7B 7E 2D 71 EA 7E
- 0x1300:$s3: 83 EC 38 53 B0 87 88 44 24 2B 88 44 24 2F B0 AB 88 44 24 30 88 44 24 31 88 44 24 33 55 56 8B F1 B8 0C 00 FE FF 2B C6 89 44 24 14 B8 0D 00 FE FF 2B C6 89 44 24 1C B8 02 00 FE FF 2B C6 89 44 24 ...
- 0x2018a:$s4: B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
- 0x1fdd0:$s5: delete[]
- 0x1f288:$s6: constructor or from DllMain.
|
0.2.VBY5zBdZox.exe.2a63a26.5.raw.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.2.VBY5zBdZox.exe.2a63a26.5.raw.unpack | JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | |
0.2.VBY5zBdZox.exe.2a63a26.5.raw.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x2873e:$pat14: , CommandLine:
- 0x1cf02:$v2_1: ListOfProcesses
- 0x1c6a5:$v4_3: base64str
- 0x1c672:$v4_4: stringKey
- 0x1c6af:$v4_5: BytesToStringConverted
- 0x1c69a:$v4_6: FromBase64
- 0x1cbbd:$v4_8: procName
- 0x1a805:$v5_7: RecordHeaderField
- 0x1a741:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
|
0.2.VBY5zBdZox.exe.2790e67.1.raw.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.2.VBY5zBdZox.exe.2790e67.1.raw.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x1d0b0:$s1: 23 00 2B 00 33 00 3B 00 43 00 53 00 63 00 73 00
- 0x80:$s2: 68 10 84 2D 2C 71 EA 7E 2C 71 EA 7E 2C 71 EA 7E 32 23 7F 7E 3F 71 EA 7E 0B B7 91 7E 2B 71 EA 7E 2C 71 EB 7E 5C 71 EA 7E 32 23 6E 7E 1C 71 EA 7E 32 23 69 7E A2 71 EA 7E 32 23 7B 7E 2D 71 EA 7E
- 0x700:$s3: 83 EC 38 53 B0 87 88 44 24 2B 88 44 24 2F B0 AB 88 44 24 30 88 44 24 31 88 44 24 33 55 56 8B F1 B8 0C 00 FE FF 2B C6 89 44 24 14 B8 0D 00 FE FF 2B C6 89 44 24 1C B8 02 00 FE FF 2B C6 89 44 24 ...
- 0x1ed8a:$s4: B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
- 0x1e9d0:$s5: delete[]
- 0x1de88:$s6: constructor or from DllMain.
|
0.2.VBY5zBdZox.exe.2950ee8.2.raw.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.2.VBY5zBdZox.exe.2950ee8.2.raw.unpack | JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | |
0.2.VBY5zBdZox.exe.2950ee8.2.raw.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x27856:$pat14: , CommandLine:
- 0x1c01a:$v2_1: ListOfProcesses
- 0x1b7bd:$v4_3: base64str
- 0x1b78a:$v4_4: stringKey
- 0x1b7c7:$v4_5: BytesToStringConverted
- 0x1b7b2:$v4_6: FromBase64
- 0x1bcd5:$v4_8: procName
- 0x1991d:$v5_7: RecordHeaderField
- 0x19859:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
|
0.3.VBY5zBdZox.exe.c15928.1.raw.unpack | JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | |
0.3.VBY5zBdZox.exe.c15928.1.raw.unpack | JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | |
0.3.VBY5zBdZox.exe.c15928.1.raw.unpack | MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen | - 0x27856:$pat14: , CommandLine:
- 0x1c01a:$v2_1: ListOfProcesses
- 0x1b7bd:$v4_3: base64str
- 0x1b78a:$v4_4: stringKey
- 0x1b7c7:$v4_5: BytesToStringConverted
- 0x1b7b2:$v4_6: FromBase64
- 0x1bcd5:$v4_8: procName
- 0x1991d:$v5_7: RecordHeaderField
- 0x19859:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
|
Click to see the 33 entries |