877ced13ebaf2b0fbe6b9ec4e332251d6e9d65d7ace653da77003ef4ef0003fe

Classification: Malicious

877ced13ebaf2b0fbe6b9ec4e332251d6e9d65d7ace653da77003ef4ef0003fe is a malicious file sample. Linked to Redline Stealer malware.

Detection summary

  • 75 antivirus detections
  • 2 IDS alerts
  • 2 processes observed
  • 2 contacted hosts
  • 1 DNS requests

MITRE ATT&CK associations

Malware families: REDLINE STEALER (S1240)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-02-06 01:00:04 2026-09-03 01:45:04 malicious-activity
RedLineStealer MalwareBazaar Abuse.ch 2024-02-06 00:40:11 2024-02-06 00:40:11 malicious-activity S1240 RedLine Stealer

Tags

evasive

Sample information

Filenames
877ced13ebaf2b0fbe6b9ec4e332251d6e9d65d7ace653da77003ef4ef0003fe, ad60e52eaf62591bd71bb3bbe419ca3b.exe
File type
PE32 executable (console) Intel 80386 Mono/.Net as ...
Size
97792 bytes
MD5
ad60e52eaf62591bd71bb3bbe419ca3b
SHA-1
974bc6c10a10d172a950eaf9bba06a94d4fbfca8
SHA-256
877ced13ebaf2b0fbe6b9ec4e332251d6e9d65d7ace653da77003ef4ef0003fe
First indexed
2024-02-06 00:40:19
Last updated
2026-09-03 01:45:04

Antivirus detections

EngineDetection
ALYacGen:Variant.Jalapeno.273
APEXMalicious
AVGWin32:MalwareX-gen [Trj]
AhnLab-V3Infostealer/Win.RedLine.C4566112
Antiy-AVLTrojan[PSW]/MSIL.RedLine
ArcabitTrojan.Jalapeno.273
AvastWin32:MalwareX-gen [Trj]
AviraHEUR/AGEN.1305503
BitDefenderGen:Variant.Jalapeno.273
BitDefenderThetaGen:NN.ZemsilF.36744.fm0@aqV69nk
BkavW32.AIDetectMalware.CS
CAT-QuickHealTrojan.MsilFC.S24736542
CrowdStrikewin/malicious_confidence_100% (D)
Cylanceunsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
DrWebTrojan.PWS.Stealer.32288
ESET-NOD32a variant of MSIL/Spy.RedLine.A
ElasticWindows.Trojan.Generic
EmsisoftTrojan-Spy.Agent (A)
F-SecureHeuristic.HEUR/AGEN.1305503
FireEyeGeneric.mg.ad60e52eaf62591b
FortinetMSIL/Agent.DFY!tr.spy
GDataMSIL.Trojan-Stealer.Redline.B
GoogleDetected
IkarusTrojan-Spy.MSIL.Redline
JiangminTrojan.PSW.MSIL.cihh
K7AntiVirusSpyware ( 0057a2d41 )
K7GWSpyware ( 0057a2d41 )
KasperskyHEUR:Trojan-PSW.MSIL.Reline.gen
MAXmalware (ai score=83)
MalwarebytesGeneric.Spyware.Stealer.DDS
McAfeeGenericRXPZ-SW!AD60E52EAF62
MicroWorld-eScanGen:Variant.Jalapeno.273
MicrosoftPWS:MSIL/RedLine!atmn
RisingBackdoor.SectopRAT!1.DA27 (CLASSIC)
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
SangforSuspicious.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Generic.nm
SophosMal/Reline-B
SymantecTrojan Horse
TencentTrojan-PSW.MSIL.Reline.ha
Trapminemalicious.high.ml.score
TrendMicroTrojanSpy.MSIL.REDLINE.SMYXDILZ
VBA32Trojan.MSIL.RedLine.Heur
VIPREGen:Variant.Jalapeno.273
VaristW32/MSIL_Agent.BJO.gen!Eldorado
ZoneAlarmHEUR:Trojan-PSW.MSIL.Reline.gen
ZonerTrojan.Win32.139086
tehtrisGeneric.Malware
AVGWin32:MalwareX-gen [Misc]
AlibabaTrojanPSW:MSIL/RedLine.ebab85e0
AvastWin32:MalwareX-gen [Misc]
CTXexe.trojan.msil
ClamAVWin.Malware.Bulz-9880537-0
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
GridinsoftTrojan.Win32.AsyncRAT.dd!n
KingsoftMSIL.Trojan-PSW.Reline.gen
LionicTrojan.Win32.RedLine.i!c
MaxSecureTrojan.Malware.300983.susgen
McAfeeDReal Protect-LS!AD60E52EAF62
NANO-AntivirusTrojan.Win32.Reline.kingqn
Paloaltogeneric.ml
PandaTrj/CI.A
SkyhighBehavesLike.Win32.Trojan.nm
TrellixENSGenericRXPZ-SW!AD60E52EAF62
TrendMicro-HouseCallTrojanSpy.MSIL.REDLINE.SMYXDILZ
VirITTrojan.Win32.MSIL_Heur.A
XcitiumMalware@#mvazywo7h18r
ZillyaTrojan.RedLine.Win32.9816
ZoneAlarmMal/Reline-B
alibabacloudSpy:MSIL/Redline.GG!MTB
huorongTrojanSpy/RedLine.q

Network contacts

94.156.66.178 104.26.12.31

DNS requests

api.ip.sb

Process list

NameCommand line
ad60e52eaf62591bd71bb3bbe419ca3b.exe
ad60e52eaf62591bd71bb3bbe419ca3b.exe