top of page

My Kids NFT Group

Public·60 members

Redline-Stealer-main.exe


The PowerShell script will connect to hxxp://45.93.201[.]114/docs/fzLJerifqJwFtnjbrlnJPNrfnupnYg[.]txt to get another MSIL file named Ferriteswarmed.exe, which will then be AES-decrypted, GZIP-decompressed, and loaded in PowerShell via .NET reflective loading. It has a debugger check that will exit once a debugger is found.




Redline-Stealer-main.exe



Once registry key is modified , it takes task scheduler to run the specific malicious file under temp folder for every 5 minutes C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN mnolyk.exe /TR "C:\Users\admin\AppData\Local\Temp\4b9a106e76\mnolyk.exe" /F


The stealer can pinch usernames, passwords, cookies, bank card details and autofill data from Chromium- and Gecko-based browsers, data from cryptowallets, instant messengers and FTP/SSH/VPN clients, as well as files with particular extensions from devices. In addition, RedLine can download and run third-party programs, execute commands in cmd.exe and open links in the default browser. The stealer spreads in various ways, including through malicious spam e-mails and third-party loaders.


The last malicious file in the bundle is upload.exe, which uploads the video previously downloaded using download.exe, to YouTube. This file is also written in NodeJS. It uses the Puppeteer Node library, which provides a high-level API for managing Chrome and Microsoft Edge using the DevTools protocol. When the video is successfully uploaded to YouTube, upload.exe sends a message to Discord with a link to the uploaded video.


Cyber criminals usually attach Microsoft Office, PDF documents, archive files (RAR, ZIP), executable files (.exe and others) and JavaScript files. If opened, the attached files install malicious software. Trojans often proliferate and install other malware and cause chain infections, however, they must first be installed.


Update 3 November 2020 - It is known that cyber criminals now use fake Inno Setup installers for TeamViewer to distribute RedLine stealer. Those installers are designed to execute the "wmiprvse.exe" file, which loads the malicious "msi.dll" that contacts the malicious URL that hosts the RedLine password stealer malware.


The script looks for PSUAService.exe on the infected system, which is a part of Panda Cloud Antivirus Software. If the mentioned antivirus is not present on the system, the malware will execute the main payload with the renamed AutoIt tool.


On 09-03-2022 I started getting repeat Norton 360 alerts about my personal laptop being attacked and it was referencing the Redline Stealer Activity 2 and it kept saying it was blocking it but not popping up with anything to quarantine. I read the details about what was going on and it points to a file called "AppLaunch.exe" located in:


Please read the 20-May-2022 Netskope article RedLine Stealer Campaign Using Binance Mystery Box Videos to Spread GitHub-Hosted Payload, which notes that "RedLine Stealer is developed in .NET" and that one of the loaders may attempt to load the payload using C:\Windows\Microsoft.NET\Framework\v4.0.30319\Applaunch.exe. The 30-Dec-2021 BleepingComputer article Have I Been Pwned Adds 441K Accounts Stolen by RedLine Malware also notes that "RedLine is currently the most widely used information-stealing malware, distributed through phishing campaigns with malicious attachments, YouTube scams, and warez/crack sites". As suggested in that BleepingComputer article, you can enter your email address(es) in the Have I Been Pwned site at just to see if any of your usernames, passwords, etc., might have been stolen during a recent RedLine Stealer campaign.My best guess is that the IP address of the attacker (16.202.186.xxx) is irrelevant because this is the domain of the web service hosting the attacking site. Antivirus programs can't block the entire domain because all the other legitimate sites being hosted on that web server would also be blocked. Your Norton log shows that it is blocking an attempted intrusion from a specific URL (tobe24.xyz - I personally would be suspicious of any website that uses a top-level domain of .xyz) that is know to launch RedLine Stealer attacks.


Attackers were also found hosting a RedLine Stealer sample at the URL covid-19-gov[.]com within a ZIP file. When the contents of the ZIP file are extracted, the RedLine Stealer binary was revealed to have the filename Covid-Locator.exe.


The trojan zip file, with a size of 4MB, when decompressed contains an executable named Rufus.exe with a file size of 734MB. This is an immediate warning sign, since most executable files are not this large. Once analysed with a hex editor, we can see that the attackers have used consecutive bytes of 0x30 as padding in between the executable and the signature to increase the size of the file. The main reasoning behind this is to evade AV detection as well as prevent analysis by sandboxes and malware analysis tools, since many would not be able to process such a large file. Removing this padding trims our file into a valid PE with a size of 63MB.


The Rufus.exe file from above uses Smartassembly for obfuscation combined with possibly another unknown obfuscator. Smartassembly is a sophisticated obfuscator and is used by many organisations as a means to protect IP of a .NET executable.


After the 20 seconds have passed, the powershell.exe process is killed. The Rufus.exe process will then create two new child processes: Kgcxsxcxhacdareyrufus-3.19.exe (Rufus application) and Applaunch.exe (used for injection and connecting with c2) before the initial process is also killed.


After some manual reviewing of the decompiled C# code, we can see (Figure 16) that there is an embedded resource payload (named Fjtiuzuykcjfgbijyop and stored with the resource named Zostmhmmqw.Properties.Resources.resources) with an offset of 0x00158533. This payload is used by the DLL to inject into the newly created process Applaunch.exe.


All the scripts starting with PERFORMSCRIPT are very similar. They receive as parameters a set of file paths and variables and create a scheduled task XML descriptor by invoking one of the create_xml files and then register the scheduled task using the schtasks.exe command with the generated XML.


The third and last scheduled script is checkFscr.vbs. The checkFscr.vbs script has two main responsibilities: installing plink.exe (an SSH command line tool for Windows) and requesting a command from the C2 server, as shown in the following image.


If the server responds with an HTTP status code of 201, the response body will be appended to the "plink.exe" command. This allows the attacker to send a plink command that creates an ssh tunnel to a remote server, forwarding the local RDP port to be used for remote access.


The dropper, in turn, installed several executables. The first was a legitimate Microsoft Visual Studio component (msbuild.exe). MSBuild is normally used to compile and execute coding projects; it can be passed project files or XML files containing scripts on the command line and launch them Since the file is a trusted Microsoft binary, it can be packed into a dropper to mask the malicious nature of the malware.


Next, the attackers dropped a copy of a legitimate Perl script interpreter on the targeted system, along with a Perl script file (named c) and a batch file (execute.exe) seen in previous Impacket-based intrusions. They then used Meterpreter to pass the following command string:


After the malicious file was executed, the breached personal PC had traces of suspicious files being run such as cio.exe.com, orrore.exe.com, and certe.exe.com. But they could not be secured as they were deleted after being run. Considering that the traces discovered in the system are similar to those of the system infected with Redline Stealer type, it seems that the malicious files all fall into the same category.


The password is added in order to deceive AV detection systems. Once the victim launches the setup.exe file inside the archive, a whole set of malware launched. Malware samples detected in these fake crack sites typically contain STOP/DJVU ransomware variants, Vidar, Azorult and RedLine Stealers.


  • Malwarebytes can detect and remove many Spyware.Password infections without further user interaction.Please download Malwarebytesto your desktop.

  • Double-click MBSetup.exeand follow the prompts to install the program.

  • When your Malwarebytes for Windowsinstallation completes, the program opens to the Welcome to Malwarebytes screen.

  • Click on the Get started button.

  • Click Scan to start a Threat Scan.

  • Click Quarantineto remove the found threats.

  • Reboot the system if prompted to complete the removal process.

Business remediation How to remove Spyware.Password with the Malwarebytes Nebula consoleYou can use the Malwarebytes Anti-Malware Nebula console to scan endpoints.Nebula endpoint tasks menu


Once the file had been shrunk, the researchers were able to analyze it dynamically in a sandbox or with static malware analysis tools. Once the malware is executed, it starts a PowerShell process with an encoded argument, which causes a cmd.exe process to be launched with a timeout of 21 seconds. Once this timeout expires, the initial process downloads a file named win11.jpg from a remote web server.


The stealer creates a random file name with a .exe extension and sets the stream Zone.Identifier of the file to [ZoneTransfer] ZoneId=2, which indicates that the file has been downloaded from a trusted site.


Oski removes its traces from the machine and deletes all the files, logs, DLLs, etc. from the disk.In addition, it creates a new process of cmd.exe while the parameters for cmd.exe are /c /taskkill /pid & erase & RD /S /Q \* & exit to kill the malware process and delete other files.


We can detect the deletion command as we have seen some consistency in the command utilized. This may not be as effective since we would alert after the malware has fully executed but helps to identify this malware in your environment. We see cmd.exe get launched and a command run with similar parameters: 041b061a72


bottom of page