General
-
Target
JaffaCakes118_1271919ae14d9d651f39b99954913efc
-
Size
1.2MB
-
Sample
250614-xxakwstks5
-
MD5
1271919ae14d9d651f39b99954913efc
-
SHA1
71aba078ab4b5d0cc069240c9a8f9ece632b0c82
-
SHA256
b99cba07cd51b158075a1fcc8371d06b8d2bb20850ace051d0b96d823bc06d9a
-
SHA512
0da2acbfed54b51641d888bc5c44f0d89f89f615c49c4bddce7407e05e15216f0597351a8efe22dc795af602fd2c693acb3a67636670dbca83f3569aec63d2e9
-
SSDEEP
24576:FCp0jfOFqaNyFF98tHhVQoah8UlvyzRuYxJrSUYIDx4hZ9BaMFBA:FOkWFDKMhVxU4FuYxJGU5DxWZ3a5
Static task
static1
Behavioral task
behavioral1
Sample
JaffaCakes118_1271919ae14d9d651f39b99954913efc.exe
Resource
win10v2004-20250610-en
Malware Config
Extracted
redline
800bot
193.0.61.155:10790
Targets
-
-
Target
JaffaCakes118_1271919ae14d9d651f39b99954913efc
-
Size
1.2MB
-
MD5
1271919ae14d9d651f39b99954913efc
-
SHA1
71aba078ab4b5d0cc069240c9a8f9ece632b0c82
-
SHA256
b99cba07cd51b158075a1fcc8371d06b8d2bb20850ace051d0b96d823bc06d9a
-
SHA512
0da2acbfed54b51641d888bc5c44f0d89f89f615c49c4bddce7407e05e15216f0597351a8efe22dc795af602fd2c693acb3a67636670dbca83f3569aec63d2e9
-
SSDEEP
24576:FCp0jfOFqaNyFF98tHhVQoah8UlvyzRuYxJrSUYIDx4hZ9BaMFBA:FOkWFDKMhVxU4FuYxJGU5DxWZ3a5
-
RedLine
RedLine Stealer is a malware family written in C#, first appearing in early 2020.
-
RedLine payload
-
Redline family
-
SectopRAT payload
-
Sectoprat family
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Drops startup file
-
Executes dropped EXE
-
Suspicious use of SetThreadContext
-