0xblack.dev Malware research · ARGUS
← all findings

31b81ea20ff83ca54ec0d7091722edf40cb2066170e1e7208b0cdb30a4a11d3c.exe

Published 2026-08-03 06:28 UTC · ARGUS
Share on X VirusTotal MalwareBazaar

Summary

Verdict
SUSPICIOUS   confidence 80% (moderate)
Family
RedLineStealer
SHA-256
31b81ea20ff83ca54ec0d7091722edf40cb2066170e1e7208b0cdb30a4a11d3c
Signals
network, child-processes

Methodology

The sample was executed in an isolated, instrumented Windows VM (host-only networking with emulated C2 responses) while process, file-system, registry and network activity were recorded. The verdict is derived by correlating observed runtime behaviour with static indicators. No sample binary was uploaded or redistributed.

Child processes (1)

Network endpoints (14)

MITRE ATT&CK

T1071 Application Layer Protocol (C2)T1059 Command and Scripting Interpreter

Indicators of Compromise (defanged)

IOCs (JSON)

{
  "sha256": "31b81ea20ff83ca54ec0d7091722edf40cb2066170e1e7208b0cdb30a4a11d3c",
  "family": "RedLineStealer",
  "verdict": "suspicious",
  "confidence": 80,
  "signals": [
    "network",
    "child-processes"
  ],
  "attack": [
    "T1071",
    "T1059"
  ],
  "network": [
    "lab:49673 -> lab:http",
    "lab:49674 -> lab:http",
    "lab:49675 -> lab:http",
    "lab:49676 -> lab:http",
    "lab:49677 -> lab:http",
    "lab:49678 -> lab:http",
    "lab:49679 -> lab:http",
    "lab:49680 -> lab:http",
    "lab:49681 -> lab:http",
    "lab:49682 -> lab:http",
    "lab:49683 -> lab:http",
    "lab:49684 -> lab:http"
  ],
  "children": [
    "C:\\argus-vr-agent\\quarantine\\31b81ea20ff83ca54ec0d7091722edf40cb2066170e1e7208b0cdb30a4a11d3c_extracted\\31b81ea20ff83ca54ec0d7091722edf40cb2066170e1e7208b0cdb30a4a11d3c.exe"
  ]
}
ARGUS · 0xblack.dev