862ff11452de99418139941018e044e7802fad311d21ddd396a5476adbe56352

Classification: Malicious

862ff11452de99418139941018e044e7802fad311d21ddd396a5476adbe56352 is a malicious file sample. Linked to Redline Stealer malware.

Detection summary

  • 54 antivirus detections (75% detection ratio)
  • 11 IDS alerts
  • 28 processes observed
  • 4 contacted hosts
  • 4 DNS requests

MITRE ATT&CK associations

Malware families: REDLINE STEALER (S1240)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-11-13 20:15:06 2026-09-03 00:45:10 malicious-activity
RedLineStealer MalwareBazaar Abuse.ch 2023-11-13 19:50:19 2023-11-13 19:50:19 malicious-activity S1240 RedLine Stealer

Sample information

Filenames
862ff11452de99418139941018e044e7802fad311d21ddd396a5476adbe56352, 11203f21fe90e8794b321cda96397a8b.exe
File type
PE32 executable (console) Intel 80386, for MS Windows
Size
289656 bytes
MD5
11203f21fe90e8794b321cda96397a8b
SHA-1
13805bcf723280184af39a045679c494a4b07082
SHA-256
862ff11452de99418139941018e044e7802fad311d21ddd396a5476adbe56352
First indexed
2023-11-13 19:50:44
Last updated
2026-09-03 00:45:10

Antivirus detections

EngineDetection
BkavW32.AIDetectMalware
LionicTrojan.Win32.RedLine.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Zusy.4722
FireEyeGeneric.mg.11203f21fe90e879
SkyhighBehavesLike.Win32.Generic.dh
McAfeeArtemis!11203F21FE90
Cylanceunsafe
VIPREGen:Variant.Ser.Zusy.4722
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ad6a81 )
BitDefenderGen:Variant.Ser.Zusy.4722
K7GWTrojan ( 005ad6a81 )
Cybereasonmalicious.f72328
ArcabitTrojan.Ser.Zusy.D1272
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HVCX
APEXMalicious
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
AlibabaTrojanSpy:Win32/Redline.d01ba309
ViRobotTrojan.Win.Z.Stealer.289656
RisingBackdoor.Agent!8.C5D (TFE:1:czAUEI8AoaV)
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.sqdze
DrWebTrojan.PWS.RedLineNET.9
TrendMicroTrojanSpy.Win32.REDLINE.YXDKLZ
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ser.Zusy.4722 (B)
SentinelOneStatic AI - Suspicious PE
MAXmalware (ai score=83)
JiangminTrojanSpy.Stealer.ajeh
GoogleDetected
AviraTR/Crypt.Agent.sqdze
VaristW32/Kryptik.KVJ.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.1000
GridinsoftTrojan.Win32.Kryptik.sa
MicrosoftTrojan:Win32/Redline.DH!MTB
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
GDataGen:Variant.Ser.Zusy.4722
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.RedLine.R621244
BitDefenderThetaGen:NN.ZexaF.36792.ruW@aaAkr0h
ALYacGen:Variant.Ser.Zusy.4722
DeepInstinctMALICIOUS
VBA32BScope.TrojanPSW.RedLine
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXDKLZ
IkarusTrojan.Agent
FortinetW32/Kryptik.HVCX!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

Network contacts

150.171.109.71 52.89.194.32 174.129.215.118 192.229.211.108

DNS requests

js.monitor.azure.com microsoftmscompoc.tt.omtrdc.net mscom.demdex.net ocsp.digicert.com

Process list

NameCommand line
11203f21fe90e8794b321cda96397a8b.exe
msedge.exe--single-argument http://go.microsoft.com/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch2&plcid=0x409&o1=SHIM_NOVERSION_FOUND&version=(null)&processName=11203f21fe90e8794b321cda96397a8b.exe&platform=0009&osver=6&isServer=0&shimver=4.0.30319.0
msedge.exe--type=crashpad-handler "--user-data-dir=%LOCALAPPDATA%\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=%LOCALAPPDATA%\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=107.0.5304.110 "--annotation=exe=%PROGRAMFILES%\(x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=107.0.1418.56 --initial-client-data=0xc8,0xcc,0xd0,0xa4,0x12c,0x7ffd874cb208,0x7ffd874cb218,0x7ffd874cb228
msedge.exe--type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1824 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:2
msedge.exe--type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:3
msedge.exe--type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2244 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=6 --time-ticks-at-unix-epoch=-1699904144957444 --launch-time-ticks=1080254807 --mojo-platform-channel-handle=3056 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:1
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=5 --time-ticks-at-unix-epoch=-1699904144957444 --launch-time-ticks=1080723396 --mojo-platform-channel-handle=3076 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:1
msedge.exe--type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3532 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=4952 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4980 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-handle=5000 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=11 --time-ticks-at-unix-epoch=-1699904144957444 --launch-time-ticks=1085631106 --mojo-platform-channel-handle=5196 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:1
msedge.exe--type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5164 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5276 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=5964 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2572 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=16 --time-ticks-at-unix-epoch=-1699904144957444 --launch-time-ticks=1175612839 --mojo-platform-channel-handle=4436 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:1
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=17 --time-ticks-at-unix-epoch=-1699904144957444 --launch-time-ticks=1177394280 --mojo-platform-channel-handle=5988 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:1
msedge.exe--type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=5976 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=4308 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8
msedge.exe--type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.16299.192 --gpu-preferences=UAAAAAAAAADoAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAACQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=6116 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:2
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=1068 --field-trial-handle=1976,i,4499296398355823837,2064915680133790010,131072 /prefetch:8
msedge.exe--single-argument http://go.microsoft.com/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch2&plcid=0x409&o1=SHIM_NOVERSION_FOUND&version=(null)&processName=11203f21fe90e8794b321cda96397a8b.exe&platform=0009&osver=6&isServer=0&shimver=4.0.30319.0
msedge.exe--type=crashpad-handler "--user-data-dir=%LOCALAPPDATA%\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=%LOCALAPPDATA%\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=107.0.5304.110 "--annotation=exe=%PROGRAMFILES%\(x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=107.0.1418.56 --initial-client-data=0xc8,0xcc,0xd0,0xa4,0x160,0x7ffd874cb208,0x7ffd874cb218,0x7ffd874cb228
11203f21fe90e8794b321cda96397a8b.exe
iexplore.exehttp://go.microsoft.com/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch2&plcid=0x409&o1=SHIM_NOVERSION_FOUND&version=(null)&processName=11203f21fe90e8794b321cda96397a8b.exe&platform=0000&osver=5&isServer=0&shimver=4.0.30319.0
iexplore.exeSCODEF:3900 CREDAT:275457 /prefetch:2