862ff11452de99418139941018e044e7802fad311d21ddd396a5476adbe56352
Classification: Malicious
862ff11452de99418139941018e044e7802fad311d21ddd396a5476adbe56352 is a malicious file sample. Linked to Redline Stealer malware.
Detection summary
- 54 antivirus detections (75% detection ratio)
- 11 IDS alerts
- 28 processes observed
- 4 contacted hosts
- 4 DNS requests
MITRE ATT&CK associations
Malware families: REDLINE STEALER (S1240)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2023-11-13 20:15:06 | 2026-09-03 00:45:10 | malicious-activity | |
| RedLineStealer | MalwareBazaar Abuse.ch | 2023-11-13 19:50:19 | 2023-11-13 19:50:19 | malicious-activity | S1240 RedLine Stealer |
Sample information
- Filenames
- 862ff11452de99418139941018e044e7802fad311d21ddd396a5476adbe56352, 11203f21fe90e8794b321cda96397a8b.exe
- File type
- PE32 executable (console) Intel 80386, for MS Windows
- Size
- 289656 bytes
- MD5
11203f21fe90e8794b321cda96397a8b- SHA-1
13805bcf723280184af39a045679c494a4b07082- SHA-256
862ff11452de99418139941018e044e7802fad311d21ddd396a5476adbe56352- First indexed
- 2023-11-13 19:50:44
- Last updated
- 2026-09-03 00:45:10
Antivirus detections
| Engine | Detection |
|---|---|
| Bkav | W32.AIDetectMalware |
| Lionic | Trojan.Win32.RedLine.l!c |
| Elastic | malicious (high confidence) |
| MicroWorld-eScan | Gen:Variant.Ser.Zusy.4722 |
| FireEye | Generic.mg.11203f21fe90e879 |
| Skyhigh | BehavesLike.Win32.Generic.dh |
| McAfee | Artemis!11203F21FE90 |
| Cylance | unsafe |
| VIPRE | Gen:Variant.Ser.Zusy.4722 |
| Sangfor | Trojan.Win32.Save.a |
| K7AntiVirus | Trojan ( 005ad6a81 ) |
| BitDefender | Gen:Variant.Ser.Zusy.4722 |
| K7GW | Trojan ( 005ad6a81 ) |
| Cybereason | malicious.f72328 |
| Arcabit | Trojan.Ser.Zusy.D1272 |
| Symantec | ML.Attribute.HighConfidence |
| ESET-NOD32 | a variant of Win32/Kryptik.HVCX |
| APEX | Malicious |
| Kaspersky | HEUR:Trojan-Spy.Win32.Stealer.gen |
| Alibaba | TrojanSpy:Win32/Redline.d01ba309 |
| ViRobot | Trojan.Win.Z.Stealer.289656 |
| Rising | Backdoor.Agent!8.C5D (TFE:1:czAUEI8AoaV) |
| Sophos | Mal/Generic-S |
| F-Secure | Trojan.TR/Crypt.Agent.sqdze |
| DrWeb | Trojan.PWS.RedLineNET.9 |
| TrendMicro | TrojanSpy.Win32.REDLINE.YXDKLZ |
| Trapmine | malicious.high.ml.score |
| Emsisoft | Gen:Variant.Ser.Zusy.4722 (B) |
| SentinelOne | Static AI - Suspicious PE |
| MAX | malware (ai score=83) |
| Jiangmin | TrojanSpy.Stealer.ajeh |
| Detected | |
| Avira | TR/Crypt.Agent.sqdze |
| Varist | W32/Kryptik.KVJ.gen!Eldorado |
| Antiy-AVL | Trojan/Win32.Kryptik |
| Kingsoft | malware.kb.a.1000 |
| Gridinsoft | Trojan.Win32.Kryptik.sa |
| Microsoft | Trojan:Win32/Redline.DH!MTB |
| ZoneAlarm | HEUR:Trojan-Spy.Win32.Stealer.gen |
| GData | Gen:Variant.Ser.Zusy.4722 |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Trojan/Win.RedLine.R621244 |
| BitDefenderTheta | Gen:NN.ZexaF.36792.ruW@aaAkr0h |
| ALYac | Gen:Variant.Ser.Zusy.4722 |
| DeepInstinct | MALICIOUS |
| VBA32 | BScope.TrojanPSW.RedLine |
| Malwarebytes | Trojan.Crypt |
| Panda | Trj/GdSda.A |
| TrendMicro-HouseCall | TrojanSpy.Win32.REDLINE.YXDKLZ |
| Ikarus | Trojan.Agent |
| Fortinet | W32/Kryptik.HVCX!tr |
| AVG | Win32:PWSX-gen [Trj] |
| Avast | Win32:PWSX-gen [Trj] |
| CrowdStrike | win/malicious_confidence_100% (W) |
Network contacts
DNS requests
js.monitor.azure.com microsoftmscompoc.tt.omtrdc.net mscom.demdex.net ocsp.digicert.com
Process list
| Name | Command line |
|---|---|
| 11203f21fe90e8794b321cda96397a8b.exe | |
| msedge.exe | --single-argument http://go.microsoft.com/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch2&plcid=0x409&o1=SHIM_NOVERSION_FOUND&version=(null)&processName=11203f21fe90e8794b321cda96397a8b.exe&platform=0009&osver=6&isServer=0&shimver=4.0.30319.0 |
| msedge.exe | --type=crashpad-handler "--user-data-dir=%LOCALAPPDATA%\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=%LOCALAPPDATA%\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=107.0.5304.110 "--annotation=exe=%PROGRAMFILES%\(x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=107.0.1418.56 --initial-client-data=0xc8,0xcc,0xd0,0xa4,0x12c,0x7ffd874cb208,0x7ffd874cb218,0x7ffd874cb228 |
| msedge.exe | --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1824 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:2 |
| msedge.exe | --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:3 |
| msedge.exe | --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2244 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8 |
| msedge.exe | --type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=6 --time-ticks-at-unix-epoch=-1699904144957444 --launch-time-ticks=1080254807 --mojo-platform-channel-handle=3056 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:1 |
| msedge.exe | --type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=5 --time-ticks-at-unix-epoch=-1699904144957444 --launch-time-ticks=1080723396 --mojo-platform-channel-handle=3076 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:1 |
| msedge.exe | --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3532 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=4952 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4980 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-handle=5000 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8 |
| msedge.exe | --type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=11 --time-ticks-at-unix-epoch=-1699904144957444 --launch-time-ticks=1085631106 --mojo-platform-channel-handle=5196 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:1 |
| msedge.exe | --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5164 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5276 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=5964 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2572 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8 |
| msedge.exe | --type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=16 --time-ticks-at-unix-epoch=-1699904144957444 --launch-time-ticks=1175612839 --mojo-platform-channel-handle=4436 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:1 |
| msedge.exe | --type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=17 --time-ticks-at-unix-epoch=-1699904144957444 --launch-time-ticks=1177394280 --mojo-platform-channel-handle=5988 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:1 |
| msedge.exe | --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=5976 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=4308 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8 |
| msedge.exe | --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.16299.192 --gpu-preferences=UAAAAAAAAADoAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAACQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=6116 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:2 |
| msedge.exe | --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=1068 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8 |
| msedge.exe | --single-argument http://go.microsoft.com/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch2&plcid=0x409&o1=SHIM_NOVERSION_FOUND&version=(null)&processName=11203f21fe90e8794b321cda96397a8b.exe&platform=0009&osver=6&isServer=0&shimver=4.0.30319.0 |
| msedge.exe | --type=crashpad-handler "--user-data-dir=%LOCALAPPDATA%\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=%LOCALAPPDATA%\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=107.0.5304.110 "--annotation=exe=%PROGRAMFILES%\(x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=107.0.1418.56 --initial-client-data=0xc8,0xcc,0xd0,0xa4,0x160,0x7ffd874cb208,0x7ffd874cb218,0x7ffd874cb228 |
| 11203f21fe90e8794b321cda96397a8b.exe | |
| iexplore.exe | http://go.microsoft.com/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch2&plcid=0x409&o1=SHIM_NOVERSION_FOUND&version=(null)&processName=11203f21fe90e8794b321cda96397a8b.exe&platform=0000&osver=5&isServer=0&shimver=4.0.30319.0 |
| iexplore.exe | SCODEF:3900 CREDAT:275457 /prefetch:2 |