Redline Stealer:
Curated IOCs

Redline Stealer's IOCs & Sandbox Analysis

Sample Hash File Type VMRay Platform Report STIX 2.1 Report (JSON) IOCs
9280d7dadb8e9268d8d8692a391d3bb77f24a8480c66f07b3aace6beca2d9ebb EXE View the Report STIX 2.1 hxxps://pastebin[.]com/raw/KE5Mft0T
b860e12c6881da7071cdce615aa6fbaef8b6794078f4524eb636b5df19adf9ed EXE View the Report STIX 2.1 185[.]216[.]70[.]15
18c790568c6e0e30d600135a33a9e41ff55e076600fec006772d95849abc4def EXE View the Report STIX 2.1 147[.]185[.]221[.]16 hxxp://ii-restored[.]gl[.]at[.]ply[.]gg:43416
6fea47929205ee6ccaf014456c2ce24b6fcd330722cf3bffba2b3085cd2d1594 EXE View the Report STIX 2.1 217[.]196[.]96[.]101
927e8668d7e5b22d0d278cb66ecbb15a51420f2fc5299aaa324d43a7d04719a2 DOC View the Report STIX 2.1 hxxps://universalmovies[.]top/notorious[.]doc hxxp://185[.]38[.]142[.]10:7474 hxxps://universalmovies[.]top/ExtExport2[.]exe hxxps://universalmovies[.]top 185[.]38[.]142[.]10 172[.]67[.]75[.]172
b95c8d80ccb988d87562f0a3ea91d31e0ee579320a758517e8ae77c268c9a628 EXE View the Report STIX 2.1 94[.]142[.]138[.]4
f9547f1d7dea3927c4ddeaced997544c7bfc28b458fc188a717b10682f681040 EXE View the Report STIX 2.1 hxxps://t[.]me/+7Lir0e4Gw381MDhi*
hxxps://steamcommunity[.]com/id/993846634744/
spahere[.]top
301fed97c01d2236d1cbabe06160562605da6f445fa3a4c28417560d06d21430 RTF View the Report STIX 2.1 hxxp://91[.]92[.]243[.]245:47477
hxxps://ampol[.]top/wabmig[.]exe
91[.]92[.]243[.]245
104[.]26[.]13[.]31
bd776414632dd90a5d459f240e2094566e70554d86ecb4bbb2a2914015426f09 DOC View the Report STIX 2.1 hxxps://covid19help[.]top/notori[.]doc
hxxp://185[.]38[.]142[.]10:7474
hxxps://covid19help[.]top/wordpad[.]exe
hxxps://covid19help[.]top
185[.]38[.]142[.]10
104[.]26[.]13[.]31
bf89362748b9e66c11aaa49ddf83b1665fe038d04225b36de4f26cffc11a0f3d RTF View the Report STIX 2.1 hxxp://185[.]38[.]142[.]10:7474
hxxps://universalmovies[.]top/ExtExport2[.]exe
185[.]38[.]142[.]10
172[.]67[.]75[.]172
be735fb6d9811ebc95011003c79b1df34a438e765f9a2065c1ef98930e72c698 EXE View the Report STIX 2.1 hxxps://t[.]me/+J_Z1QGHfHko0MGZi*
hxxps://steamcommunity[.]com/id/elcadillac
698cdfaf8a202dbac69809be1861e390a013bac64522e29b6b3fd7d9b7e0c450 EXE View the Report STIX 2.1 212[.]113[.]116[.]143

Subscribe to our IOC Newsletter for the latest intelligence on Redline Stealer

Tech Insights Deep Dive of April:
Detection Strategies & Operational Excellence

join VMRay for two powerhouse webinars designed to sharpen your threat detection and response capabilities — featuring a special joint session with Red Canary:

Days
Hours
Minutes
Seconds

Live session's over. Watch the on-demand video to learn how VMRay and Red Canary combine forces to deliver faster, smarter threat detection!

Days
Hours
Minutes
Seconds

Learn how to cut phishing triage time with automated detonation and deep analysis — quickly uncover threats while improving response accuracy!