MB-ff7a337d019cbe7812d281e8af9856aa764ff8d4321bb05d162954d1581e512a
high
📛 Threat Title
RedLineStealer: CA9FE6E7DCC98C0A0A4C98564037DCAF.exe
Description
File type: exe. Size: 93696 bytes. Tags: exe, RedLineStealer. Reporter: abuse_ch. First seen: 2026-09-25 06:05:14.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
f34d5f2d4577ed6d9ceec516c1f5a744
IOC database
- Type
- hash_imphash
- Value
f34d5f2d4577ed6d9ceec516c1f5a744- First seen
- Last seen
- Attached to this threat
- Appears in
- 944 threats
- Description
- imphash of URLhaus payload 61d424c2e3c5d8db…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
ff7a337d019cbe7812d281e8af9856aa764ff8d4321bb05d162954d1581e512a
IOC database
- Type
- hash_sha256
- Value
ff7a337d019cbe7812d281e8af9856aa764ff8d4321bb05d162954d1581e512a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- RedLineStealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
716d103addea74d8492e269a372759df216df7b9
IOC database
- Type
- hash_sha1
- Value
716d103addea74d8492e269a372759df216df7b9- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
ca9fe6e7dcc98c0a0a4c98564037dcaf
IOC database
- Type
- hash_md5
- Value
ca9fe6e7dcc98c0a0a4c98564037dcaf- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 93696 bytes. Tags: exe, RedLineStealer. Reporter: abuse_ch. First seen: 2026-09-25 06:05:14.
Remediations (10)
-
web:attack.mitre.org
RedLine Stealer is an information-stealer malware variant first identified in 2020. [1] [2] [3] RedLine Stealer is a Malware as a Service (MaaS) and was reportedly sold as either a one-time purchase or a monthly subscription service.
-
web:bazaar.abuse.ch
Information on RedLineStealer malware sample (SHA256 ff7a337d019cbe7812d281e8af9856aa764ff8d4321bb05d162954d1581e512a) MalwareBazaar uses YARA rules from several ...
-
web:flare.io
RedLine stealer malware files as seen in Flare RedLine Stealer is a Malware-as-a-Service (MaaS), so threat actors can purchase it then sell the stolen data on dark web forums.
-
web:fortiguard.fortinet.com
Updates to RedLine Stealer also include RAT functions, allowing it to upload and download files, execute commands, and take screenshots. While this family typically uses its own C2 servers, some campaigns have used public repositories such as GitHub to distribute malicious archives disguised as game cheats, and RedLine control panels have used ...
-
web:forums.malwarebytes.com
Hello, Today after a scan I noticed 4 detections and after quarantining them a couple time and restarting the scan keeps giving the same result. I google it a bit and came by another support topic on this forum and hope you can help me too! Thanks in advance.
-
web:malpedia.caad.fkie.fraunhofer.de
RedLine Stealer is a malware available on underground forums for sale apparently as a standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as ...
-
web:malwaretips.com
Spyware. RedlineStealer is a Trojan that is designed to steal sensitive information from the infected computer, such as login credentials, financial information, and other personal data. If you believe that your login credentials or other sensitive information may have been stolen, change the passwords for any accounts that may have been compromised.
-
web:www.microsoft.com
Deploy endpoint detection and response agents that generate alerts for process hollowing behavior. Configure alerts for Regsvcs.exe, vbc.exe, or other system binaries creating child processes or making outbound network connections. Instruct users to discontinue the use of password managers built into web browsers.
-
web:www.pcrisk.com
RedLine Stealer (also known as RedLine) is a malicious program which can be purchased on hacker forums for $150/$200 depending on the version. It can be used to steal information and infect operating systems with other malware.
-
web:www.youtube.com
I am NOT to be mistaken with the malware RedLineStealer . Been cheating in minecraft for 7y now. DISCLAIMER: I do not partake/develop malware, ransomware, RATs or any malicious code. I do not hack ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.