Published 03/10/2023
RedLine Stealer is a malware family written in C# that harvests autocomplete data, such as saved credentials and financial information, from web browsers. It can also steal system information such as location, hardware configuration, and security software data.
Redline Stealer (RLS) is a popular malware strain that operates on a malware-as-a-service (MaaS) model and is sold on underground forums for approximately $100 (Unnikrishnan). Cybercriminals can use this software to collect a wide range of sensitive data from Gecko- and Chromium-based web browsers. This data includes saved credentials, financial information, and cookies, which allow attackers to access various accounts ranging from social media to cryptocurrency wallets (Meskauskas).
Telemetry data collected by CloudSEK has detected the deployment of RLS via Regsvcs.exe on Windows systems. The contents of the Regsvcs.exe process, in a suspended state, are replaced by the loader using a process hollowing technique. This allows for the portable executable of RLS to be mapped into the Regsvcs.exe process, where thread contexts can be manipulated to point to RLS’s entry location. Once complete, RLS can masquerade as a legitimate process on the system (Unnikrishnan).
Fake software posing as legitimate software is often used to spread malware like RLS, and eSentire’s Threat Response Unit (eTRU) has observed such a case where RLS is being distributed via a fake version of AnyDesk (eSentire). The legitimate AnyDesk website was cloned into a malicious site, where a victim would download an installer as an ISO image file padded with junk data. This padding is used to bypass file size limitations imposed by sandboxes and antivirus software (eSentire). Once the victim runs the installer, several commands are executed to run obfuscated files that check for antivirus software, communicate with the attacker’s command-and-control servers, and read the victim’s data (eSentire).
RLS comes with several additional features beyond data theft, such as saved passwords. Its primary targets are the user’s desktop and documents directories, where it searches for cryptocurrency data, such as crypto wallets, via more than 40 browser extensions. It captures a desktop screenshot and collects Discord tokens and user data from Steam. Beyond financial data, RLS can retrieve system information such as username, processor and memory information, installed browsers and antivirus programs, and currently running processes (Unnikrishnan).
After initial malware execution, Cyber Florida has observed multiple executables dropped by a self-extracting RAR file. These executables, 123.exe and 321.exe, work together to create two vbc.exe child processes that execute the malicious code. The process vbc.exe appears to attempt communication with targeted IP addresses and ports, and with one of those communications, Cyber Florida observed what appeared to be the creation of “bebra.exe,” but upon a hex content review of the file, only the ASCII string “Hello” was present. It is suspected that this process may be attempting to establish some form of communication and then, by design, leads to a program crash. A hypothesis is that the “bebra.exe” file may simply be a placeholder until the malware needs or wants actual binary content. A review of vbc.exe appears to be a legitimate binary that may have been abused and injected into. Vbc.exe is the Visual Basic Compiler and is used with the .NET Framework. Injecting into a known-good process may be a way for an attacker’s malware to evade detection. The vbc.exe processes did have portions of memory that had RWX (Read, Write, and Execute) permissions. These sections of memory contained binary data, and they were extracted and analyzed. Cyber Florida uploaded both files to VirusTotal, and the following binary file was already detected:
However, the following was not seen on VirusTotal until Cyber Florida uploaded the file for review:
https://www.virustotal.com/gui/file/f179a2d8bc7ab6cd32a8c1f95988d77fb1381072ac92f099047f7395cae84115
Network Traffic
This communication was the first observed network connection from the victim system to a system potentially controlled by an attacker. The communication was to 65.21.213.208:3000. The TCP stream below shows a POST action to the system with no real content. The server replies with a “Hello” response. Of interest, the “bebra.exe” file identified in the victim’s AppData/Roaming folder was not a binary of any sort, and when viewed in a hex editor, it only had an ASCII string of “Hello”. Also, of interest about “bebra.exe” is that the Content-Type was application/x-msdownload, which is associated with a binary file.
The following communication was the second observed network connection from the victim system to a system potentially controlled by a potential attacker. The traffic was to 51.89.207.166:47909. The observed traffic appeared to have no successful connections made. However, this IP and the specified port have been identified as potentially malicious through other threat intelligence sources.
Similar Observations Seen From ArechClient2
In November 2022, the Cyber Florida SOC released a threat advisory on Arechclient2 and provided presentations on their analysis. During analysis of Arechclient2 a Base64 string containing, once de-obfuscated, various Chrome extensions associated to Crypto wallets. Arechclient2 and RedLine appear to have similar functionality, including stealing browser data like usernames, passwords, and other sensitive information, such as crypto wallet details. When analyzing the current version of RedLine, a similar Base64 string was found. The following string is base64-encoded data and its decoded result via CyberChef. This further shows similarity between the two malware variants.
Inject VBC 1 Process
The following shows metadata associated with the injected binary for the first VBC process. Of note is essentially the future timestamp value of the binary. Also, reviewing some of the content statically did not reveal as much data as reviewing it dynamically did. For example, attacker IP addresses and other key findings were not identified in a static manner. The binary appears to have been compiled in .NET, and the source code of the injected binary would be the next step for analysis.
The following string was extracted from ProcessHacker as the malware was running. This string shows the IP address and specified port of interest, along with the POST action observed in Wireshark. This activity also aligns with the ProcMon (ProcessMonitor) logs generated by this activity.
Inject VBC 2 Process
The following shows metadata associated with the injected binary for the second VBC process. Of note is essentially the no timestamp value of the binary. Also, reviewing some of the content statically did not reveal as much data as reviewing it dynamically did. For example, attacker IP addresses and other key findings were not identified in a static manner.
The following screenshots were taken from ProcessHacker as the malware was running. We can observe the IP address and the specified port of interest as strings, and they can also be represented in Base64.
Overall Order of VBC Activity
The following is a brief, high-level (non-exhaustive) order of events related to the execution of malicious activity by vbc.exe. Taken from ProcMon logs.
4efdf3a4c19a94b2e58f5212124cb161.exe
Note: the initial executable may have a different file name.
123.exe
https://www.virustotal.com/gui/file/d3b64baa18214715f544c836b59e2ca839e86 95f93706476033a1e8c56dd7287
321.exe
https://www.virustotal.com/gui/file/aadbf6b7fd77075e6355a209c4cbd8b1049f21eb69f503203bd6fd7a7a085dc6
Vbc.exe.bin (injected 1 process)
https://www.virustotal.com/gui/file/a82732b71779c41df6b105ffe98f385b53d6bd64d783d6cb3caac9be3270d783
Vbc.exe2.bin (injected 2 processes)
https://www.virustotal.com/gui/file/f179a2d8bc7ab6cd32a8c1f95988d77fb1381072ac92f099047f7395cae84115?nocache=1
eSentire. Entire Threat Intelligence Malware Analysis: Redline Stealer. eSentire. (n.d.). Retrieved February 10, 2023, from https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-redline-stealer
Meskauskas, T. (2023, February 1). Redline Stealer malware. RedLine Stealer Malware – Malware removal instructions (updated). Retrieved February 10, 2023, from https://www.pcrisk.com/removal-guides/17280-redlinestealer-malware
Unnikrishnan, A., & CloudSEk. (2023, January 26). Technical analysis of the redline stealer: CloudSEK. RSS. Retrieved February 10, 2023, from https://cloudsek.com/blog/technical-analysis-of-the-redline-stealer
Contributing Security Analysts: Sreten Dedic, EJ Bulut