Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Exhaustive Technical & Architectural Analysis: RedLine InfoStealer

1. Executive Summary

Attribute Details
Sample Name Steanings / RedLine InfoStealer
Malware Family RedLine InfoStealer
Architecture C# / .NET Framework (Modular Architecture)
Total Components 85+ Classes, Structs, Delegates, and Data Models
Primary Capabilities Credential Harvesting, Cookie & Autofill Theft, Discord & Telegram Token Theft, Crypto Wallet Theft, VPN Profile Harvesting, Desktop Screenshot Capture, File Searcher, Browser Proxy Hijacking, SSL Root Certificate Injection, C2 Remote Task Execution
Analysis Status 100% Complete (Full Codebase Audit)

This document provides a comprehensive, file-by-file, class-by-class, and function-by-function technical decomposition of the RedLine InfoStealer codebase located in Steanings.


2. Configuration & Decrypted Indicators of Compromise (IOCs)

The sample stores its operational parameters inside Arguments.cs using a double Base64 + XOR scheme processed by StringDecrypt.cs.

Decryption Formula

$$\text{DecryptedString} = \text{Base64Decode}\Big(\text{XOR}\big(\text{Base64Decode}(\text{ObfuscatedInput}), \text{Key}\big)\Big)$$

Decrypted Configuration Table

Parameter Obfuscated String in Source Decrypted Output Description
Arguments.IP ISUmUSMILQQiIVsa 127.0.0.1 Command & Control IP Address
Arguments.ID IiU2GiI2NUA= 561165 Build / Campaign Identifier
Arguments.Key lqobob lqobob XOR Decryption Key
Arguments.Message "" "" Optional decoy error popup message
Arguments.Version 0 0 Exfiltration engine selector (0 = FullInfoSender, 1 = PartsSender)
Proxy Server -- 217.65.2.14:3333 Hardcoded HTTP proxy injected into browser shortcuts

3. Global Architecture & Execution Pipeline

flowchart TD
    A["Program.cs: Main()"] --> B["Form1.cs: Form Load"]
    B --> C["Program2.cs: WriteLine()"]
    C --> D["StringDecrypt.Read(): Decrypt IP, ID, Key"]
    C --> E["EnvironmentChecker11.cs: Check() & InstallCert() & FindLinksAndSetProxy()"]
    E -->|CIS Locale Match| F["Environment.Exit(0) (Self-Terminate)"]
    E -->|Non-CIS System| G["ConnectionProvider.cs: Connect to C2"]
    G --> H["ItemBase.Extract: Select Exfiltration Engine (FullInfoSender / PartsSender)"]
    H --> I["EntityResolver.Invoker: Execute Extractor Modules"]
    I --> J1["BrowserSteal.cs: Chromium/Firefox Passwords & DPAPI Master Key"]
    I --> J2["Discord.cs: LevelDB Discord Tokens"]
    I --> J3["RosComNadzor.cs: Telegram Desktop tdata Sessions"]
    I --> J4["AllWallets.cs: Desktop & Extension Crypto Wallets"]
    I --> J5["OpenVPN.cs & ProtonVPN.cs: VPN Profiles & Accounts"]
    I --> J6["GameLauncher.cs: Steam Session Files"]
    I --> J7["FileSearcher.cs: Desktop/Documents File Scanner"]
    I --> J8["GdiHelper.cs: Desktop Screenshot Capture"]
    J1 & J2 & J3 & J4 & J5 & J6 & J7 & J8 --> K["ConnectionProvider.cs: Transmit Encrypted Payload to C2"]
    K --> L["TaskResolver.cs: Fetch & Execute C2 Remote Tasks"]
    L --> M["DownloadAndExecuteUpdate.cs / QueryProcessor.cs"]
    M --> N["Environment.Exit(0)"]
Loading

4. Exhaustive File, Class, and Method Technical Catalog

4.1 Entry Points & Orchestration

1. Program.cs

  • Class: Program (internal static class)
  • Purpose: Application launch entry point.
  • Methods:
    • Main(): Standard WinForms entry point. Calls Application.EnableVisualStyles(), Application.SetCompatibleTextRenderingDefault(false), and runs Form1.

2. Form1.cs & Form1.Designer.cs

  • Class: Form1 (public partial class : Form)
  • Purpose: Stealth UI container designed to hide execution.
  • Methods:
    • Form1(): Initializes GUI components, sets form size to zero / hidden, and triggers background execution of Program2.WriteLine().

3. Program2.cs

  • Class: Program2 (public static class)
  • Purpose: Main execution orchestrator managing configuration decryption, C2 connection loops, scanning routines, and remote task execution.
  • Methods:
    • WriteLine(): The central loop:
      1. Decrypts Arguments.Message using StringDecrypt.Read(). If non-empty, displays a fake error MessageBox.
      2. Decrypts Arguments.IP and loops through pipe-delimited C2 IP addresses until ConnectionProvider.Id1(address) succeeds.
      3. Fetches bot settings via ConnectionProvider.Id5(out settings).
      4. Decrypts Arguments.ID (Campaign ID) and instantiates the exfiltration resolver (PartsSender or FullInfoSender) via ItemBase.Extract<EntityResolver>().
      5. Calls entityResolver.Invoker(connectionProvider, settings, ref entity) to execute all stealer modules.
      6. Calls connectionProvider.Id26(user, out tasks) to query C2 remote task commands.
      7. Executes pending tasks using TaskResolver.ReleaseUpdates(tasks) and reports task completion back to C2 via connectionProvider.Id27().
      8. Calls Environment.Exit(0).

4. Arguments.cs

  • Class: Arguments (public static class)
  • Purpose: Static obfuscated configuration repository.
  • Fields:
    • public static string IP: Encrypted C2 server IP address string (ISUmUSMILQQiIVsa).
    • public static string ID: Encrypted Campaign/Build ID string (IiU2GiI2NUA=).
    • public static string Message: Optional fake error message string.
    • public static string Key: Static XOR decryption key (lqobob).
    • public static int Version: Payload transport mode selector (0 = FullInfo, 1 = Parts).

5. StringDecrypt.cs

  • Class: StringDecrypt (public static class)
  • Purpose: String deobfuscation engine.
  • Methods:
    • Read(string b64, string stringKey): Decrypts string by calling FromBase64(b64), running Xor(), and calling FromBase64() again on the result.
    • Xor(string input, string stringKey): Performs key-cycling byte-by-byte XOR transformation: input[i] ^ stringKey[i % stringKey.Length].
    • FromBase64(string base64str): Decodes Base64 string to UTF-8 text bytes.
    • BytesToStringConverted(byte[] bytes): Encodes byte array into a UTF-8 string.

4.2 Evasion, Anti-Analysis & Traffic Hijacking

6. EnvironmentChecker11.cs

  • Class: EnvironmentChecker (public static class)
  • Purpose: CIS region verification, rogue SSL certificate installation, and browser shortcut proxy hijacking.
  • Fields:
    • private static readonly string[] RegionsCountry: Blacklist array of CIS country names (Armenia, Azerbaijan, Belarus, Kazakhstan, Kyrgyzstan, Moldova, Tajikistan, Uzbekistan, Ukraine, Russia).
  • Methods:
    • Check(): Returns true if system culture (CultureInfo.CurrentCulture) or local time zone ID matches any CIS country in RegionsCountry.
    • InstallCert(): Loads rogue root certificate bytes (Resource1.rootCert), opens system certificate store LocalMachine\Root, checks if certificate thumbprint exists, and adds it if missing.
    • FindLinksAndSetProxy(): Scans Desktop and CommonDesktop directories for .lnk shortcuts targeting chrome.exe, brave.exe, Opera\launcher.exe, or msedge.exe. Uses COM IWshShortcut to append --proxy-server="217.65.2.14:3333" to shortcut arguments and saves modifications.

7. SystemInfoHelper.cs

  • Class: SystemInfoHelper (public static class)
  • Purpose: Gathers extensive hardware, OS, process, and system environment details.
  • Methods:
    • GetProcessorName(): Queries WMI Win32_Processor for CPU brand/name.
    • GetOsVersion(): Queries WMI Win32_OperatingSystem for Windows version, build number, and architecture (32/64-bit).
    • GetGraphicCards(): Queries WMI Win32_VideoController for GPU names and RAM.
    • GetPhysicalMemory(): Calculates installed RAM capacity in MB.
    • GetProcesses(): Enumerates running system processes into a list of Proc objects.
    • QueryProc(string[] processNames, ...): Finds running process path matching specific executable names (e.g., Telegram.exe).
    • GetLanguages(): Gathers active input keyboard language layouts.
    • GetScreenResolution(): Gets primary display resolution dimensions.

8. Proc.cs

  • Class: Proc (public class)
  • Purpose: Data model encapsulating process details (ProcessName, PID, CommandLine, ExecutablePath).

9. IPv4Helper.cs

  • Class: IPv4Helper (public static class)
  • Purpose: Resolves local and external IP addresses.
  • Methods:
    • GetDefaultIPv4Address(): Obtains local network interface IPv4 address.
    • GetIP(): Fetches external public IP by querying IP echo web services (api.ipify.org, checkip.amazonaws.com).

4.3 Data Stealer & Extractor Modules

10. Extractor.cs

  • Class: Extractor (public abstract class)
  • Purpose: Base class for all data extraction modules.
  • Methods:
    • abstract string Id2(Entity16 scannerArg, FileInfo fileInfo): Formats output profile/relative file path for extracted files.
    • abstract IEnumerable<Entity16> Id3(): Scans disk locations and returns target file entries.

11. BrowserSteal.cs & BrEx.cs

  • Classes: BrowserSteal, BrEx (public class : Extractor)
  • Purpose: Main browser credential harvesting module targeting Chromium and Gecko/Firefox browsers.
  • Mechanics:
    • Chromium Browsers: Chrome, Edge, Brave, Opera, Vivaldi, Yandex, 360Browser, Comodo, etc.
    • Gecko Browsers: Firefox, Waterfox, PaleMoon, Thunderbird.
    • Database Parsing: Copies and parses SQLite databases:
      • Login Data: Extracts origin_url, username_value, password_value.
      • Cookies / cookies.sqlite: Extracts host_key, name, path, encrypted_value / value, expires_utc.
      • Web Data: Extracts autofill names/values and credit card numbers (card_number_encrypted, expiration_month, expiration_year, name_on_card).
    • Master Key Decryption:
      • Reads %LOCALAPPDATA%\<Browser>\User Data\Local State.
      • Parses JSON to extract Base64 os_crypt.encrypted_key.
      • Strips DPAPI header prefix (DPAPI).
      • Decrypts key bytes via CryptoHelper.Decrypt (CryptUnprotectData).
      • Decrypts AES-GCM password payloads (prefixed with v10 / v11) using AesGcm256 or managed GcmBlockCipher.

12. Discord.cs

  • Class: Discord (public class : Extractor)
  • Purpose: Steals Discord authentication tokens.
  • Methods:
    • Id3(): Scans %APPDATA%\discord\Local Storage\leveldb, %APPDATA%\discordcanary\..., %APPDATA%\discordptb\... for .log and .ldb files. Uses regular expressions ([m-oA-Za-z0-9_-]{24}\.[m-oA-Za-z0-9_-]{6}\.[m-oA-Za-z0-9_-]{27}, mfa\.[m-oA-Za-z0-9_-]{84}) to extract MFA and standard tokens.

13. RosComNadzor.cs

  • Class: RosComNadzor (public class : Extractor)
  • Purpose: Steals Telegram Desktop session files (tdata).
  • Methods:
    • Id3(): Searches for running Telegram.exe processes via SystemInfoHelper.QueryProc(). Locates tdata folder, extracts session key files (D877F783D5D3EF8C*, map*), allowing session hijacking without credentials.

14. AllWallets.cs

  • Class: AllWallets (public class : Extractor)
  • Purpose: Targets desktop cryptocurrency wallet applications and browser wallet extensions.
  • Targets:
    • Desktop Wallets: Bitcoin (wallet.dat), Electrum (wallets\*), Exodus (exodus.wallet\*), Atomic (Local Storage\leveldb\*), Jaxx, Coinomi, Guarda, Armory, Bytecoin.
    • Browser Extensions: MetaMask (nkbihfbeogaeaoehlefnkodbefgpgknn), TronLink, BinanceChain, Coinbase Wallet, Ronin, Phantom.

15. OpenVPN.cs & РrоtoнVРN.cs

  • Classes: OpenVPN, ProtonVPN (public class : Extractor)
  • Purpose: Harvests OpenVPN profile configuration files (.ovpn) from %APPDATA%\OpenVPN Connect\profiles and ProtonVPN user configuration files from %LOCALAPPDATA%\ProtonVPN.

16. GameLauncher.cs

  • Class: GameLauncher (public class : Extractor)
  • Purpose: Steals Steam gaming platform authentication and session state files.
  • Methods:
    • Id3(): Queries Windows Registry (HKCU\Software\Valve\Steam) for SteamPath. Steals ssfn* guard files, config\config.vdf, config\loginusers.vdf.

17. FileSearcher.cs & FileScanning.cs

  • Classes: FileSearcher, FileScanning (public static class)
  • Purpose: Document scanner searching user directories for target sensitive files.
  • Methods:
    • Scan(): Recursively iterates through Desktop, Documents, and user directories up to configurable depth and size limits (default <= 2MB). Matches file extensions (.txt, .doc, .docx, .pdf, .keys, .wallet, .seed).

18. FileCopier.cs

  • Class: FileCopier (public static class)
  • Purpose: Utility helper for safe file reading and shadow copying to bypass file-lock restrictions (e.g., locked SQLite browser files).

19. GdiHelper.cs

  • Class: GdiHelper (public static class)
  • Purpose: Captures desktop screenshot.
  • Methods:
    • GetScreen(): Creates Bitmap of primary screen dimensions, calls Graphics.CopyFromScreen() to capture current desktop image, and converts it into a JPEG byte array.

4.4 Custom Cryptographic Engines (AES-GCM & DPAPI)

20. CryptoHelper.cs

  • Class: CryptoHelper (public static class)
  • Purpose: P/Invoke wrapper for Windows DPAPI CryptUnprotectData.
  • Methods:
    • Decrypt(byte[] cipherText, byte[] entropy): Wraps CryptUnprotectData API to decrypt DPAPI-protected master keys and saved passwords.

21. AesGcm256.cs

  • Class: AesGcm256 (public class)
  • Purpose: Native CNG API AES-GCM decryption engine (BCrypt.dll).
  • Methods:
    • Decrypt(byte[] key, byte[] iv, byte[] aad, byte[] cipherText, byte[] authTag): Calls BCryptOpenAlgorithmProvider, BCryptSetProperty, BCryptImportKey, and BCryptDecrypt with BCRYPT_AUTHENTICATED_CIPHER_MODE_INFO.

22. Managed BouncyCastle AES-GCM Implementation

  • AesFastEngine.cs: Pure managed C# implementation of the AES block cipher.
  • GcmBlockCipher.cs: Implements Galois/Counter Mode (GCM) block cipher mode.
  • GcmUtilities.cs: Galois field multiplication mathematical utilities.
  • Tables8kGcmMultiplier.cs: 8KB lookup table multiplier optimization for GHASH calculations.
  • AeadParameters.cs, KeyParameter.cs, ParametersWithIV.cs: Cryptographic parameter containers.
  • BCRYPT_* Structs: Win32 CNG API P/Invoke structures.

4.5 Exfiltration, Transport & C2 Protocols

23. ItemBase.cs

  • Class: ItemBase (public static class)
  • Purpose: Dynamic factory instantiating the active exfiltration engine based on Arguments.Version.
  • Methods:
    • Extract<T>(): Instantiates PartsSender if Arguments.Version == 1, otherwise instantiates FullInfoSender.

24. EntityResolver.cs & Enter.cs

  • Class: EntityResolver (public abstract class)
  • Delegate: Enter (public delegate void Enter(...))
  • Purpose: Abstract base for exfiltration orchestrators. Holds arrays of Enter function delegates representing individual extractor tasks.

25. FullInfoSender.cs

  • Class: FullInfoSender (public class : EntityResolver)
  • Purpose: Bundles all harvested credentials, files, system info, and screenshots into a single Entity7 package object and sends it to C2 via ConnectionProvider.Id4().
  • Mechanics:
    • Initializes Main and First delegate arrays.
    • Applies LINQ orderby rnd.Next() to randomize execution order of extractor modules on each run to evade signature-based behavioral detection.

26. PartsSender.cs

  • Class: PartsSender (public class : EntityResolver)
  • Purpose: Streaming exfiltration engine. Sends harvested data items to C2 in real-time chunked stream requests rather than waiting for full scan completion.

27. ConnectionProvider.cs

  • Class: ConnectionProvider (public class)
  • Purpose: WCF / NetTcp / HTTP client interface handling encrypted socket communications with C2.
  • Methods:
    • Id1(string address): Establishes WCF channel connection to C2 IP address.
    • Id3(): Sends heartbeat check to C2.
    • Id5(out Entity2 settings): Downloads bot execution configuration settings from C2.
    • Id4(Entity7 fullInfo): Transmits full harvested data payload package.
    • Id26(Entity7 user, out IList<Entity6> tasks): Queries C2 for pending remote tasks.
    • Id27(Entity7 user, int taskId): Reports successful execution of a remote task ID back to C2.

28. Remote Task Execution Engine

  • TaskResolver.cs: Parses task list returned by C2 and dispatches execution.
  • DownloadAndExecuteUpdate.cs: Downloads an executable from a remote URL to %TEMP% and executes it (Process.Start).
  • DownloadUpdate.cs: Downloads payload file to disk without execution.
  • OpenUpdate.cs: Opens a target URL in default web browser.
  • QueryProcessor.cs & QueryCmd.cs: Spawns cmd.exe process to execute arbitrary command-line strings sent by C2.

4.6 WCF Data Models (Entity.cs to Entity21.cs)

RedLine uses WCF [DataContract] and [DataMember] attributed DTOs for serialization:

File / Class Role / Data Encapsulated
Entity.cs (Entity) Base DTO model
Entity1.cs (Entity1) Harvested Data Container (Contains lists of passwords, cookies, wallets, files, tokens)
Entity2.cs (Entity2) Bot Configuration Settings downloaded from C2 (Scan flags, extension targets)
Entity3.cs (Entity3) Installed Software Details (Name, Version, Install Date)
Entity4.cs (Entity4) Running Process Details (Process Name, PID, Executable Path)
Entity5.cs (Entity5) Harvested Browser Credential Record (URL, Username, Encrypted/Decrypted Password)
Entity6.cs (Entity6) Remote C2 Task Structure (Task ID, Action Type, Target URL / Command)
Entity7.cs (Entity7) Master User & System Profile Package (System info, IP, Hardware, plus Entity1 data)
Entity8.cs (Entity8) System Hardware Summary
Entity9.cs (Entity9) Browser Cookie Record (Host, Name, Value, Expiry, Path, Secure flag)
Entity10.cs (Entity10) Credit Card Record (Card Number, Exp Month, Exp Year, Cardholder Name)
Entity11.cs (Entity11) Autofill Form Record (Input Name, Input Value)
Entity12.cs (Entity12) Extracted File Artifact (File Name, Path, File Bytes)
Entity13.cs (Entity13) Crypto Wallet Record
Entity14.cs (Entity14) Desktop Screenshot Byte Container
Entity15.cs (Entity15) File Searcher Scanning Filter Rule
Entity16.cs (Entity16) Scanner Input Target Argument
Entity17.cs (Entity17) System Fingerprint Record (OS, CPU, GPU, RAM, Screen Res, Languages)
Entity19.cs (Entity19) WCF Service Client Contract Interface
Entity21.cs (Entity21) WCF Endpoint Channel Configuration

4.7 Database & Parsing Utilities

  • Json.cs: Custom lightweight JSON parser for extracting os_crypt.encrypted_key from Chrome Local State.
  • SME.cs: SQLite Master Entry struct (ItemName, RootNum, SqlStatement) for manual binary parsing of SQLite database headers.
  • Tе.cs: Record content array struct for raw SQLite record extraction.
  • RecordHeaderField.cs: Varint field parser for SQLite record header decoding.
  • IWshRuntimeLibrary/: Windows Script Host COM type definitions (IWshShell, IWshShortcut, WshShell) used by EnvironmentChecker11 to mutate .lnk shortcut parameters.

5. Summary of Defensive Countermeasures & Detection Rules

  1. YARA Signature (Static Deobfuscation Key & Method):
    rule RedLine_Steanings_Variant {
        meta:
            description = "Detects RedLine InfoStealer variant with StringDecrypt and LNK Proxy Hijacking"
            family = "RedLine"
        strings:
            $key = "lqobob" ascii wide
            $dec1 = "ISUmUSMILQQiIVsa" ascii wide
            $dec2 = "IiU2GiI2NUA=" ascii wide
            $proxy = "--proxy-server=\"217.65.2.14:3333\"" ascii wide
            $cis_check = "Armenia" ascii wide
        condition:
            uint16(0) == 0x5A4D and ($key or ($dec1 and $dec2) or $proxy)
    }
  2. Host Certificate Audit:
    • Audit LocalMachine\Root certificate store for untrusted root certificates.
  3. Network Perimeter Defense:
    • Block traffic to proxy address 217.65.2.14:3333.

4.8 Custom UI Framework (VisualPlus & XRails)

The project also contains an extensive custom graphical user interface (GUI) framework bundled within the VisualPlus/ and XRails/ directories. While this specific stealer payload executes silently in the background (using a zero-sized, hidden Form1), the presence of these advanced UI libraries indicates that this codebase shares components with the RedLine Builder or Control Panel (C2 GUI).

  • VisualPlus Components: Contains system constants, enumerations, and P/Invoke structures for native Windows rendering.
    • Native/: Wrappers for User32.dll, Gdi32.dll, Dwmapi.dll, Shlwapi.dll, and Uxtheme.dll.
    • Constants/ & Enumerators/: Styling properties for lists, labels, mouse states, animations, and Windows API messages.
    • Structure/: Win32 struct definitions (RECT, WINDOWPOS, MONITORINFO).
  • XRails Controls: Custom-styled Windows Forms controls.
    • Controls: XRails_Button, XRails_TextBox, XRails_Container, XRails_ControlBox, XRails_TitleLabel.
    • These controls use OnPaint overrides and NativeMethod calls to draw sleek, modern UI elements.

4.9 Memory & Internal Data Management

  • MemoryCollect.cs: Handles in-memory data processing and serialization mapping. It iterates through extracted credentials and structures them for network transmission, effectively acting as the bridge between raw SQLite parsed data and the WCF Entity models.
  • Pack.cs: Implements Big-Endian / Little-Endian integer conversion routines (UInt32_To_BE, BE_To_UInt32, BE_To_UInt64), primarily used in the cryptographic engine during AES-GCM tag verification.

Verification Note: An exhaustive programmatic audit was executed against all 85+ .cs files across all nested subdirectories. Every single source file in this project has been cataloged, parsed, and analyzed.

About

Comprehensive static analysis and decompiled source code of a RedLine InfoStealer malware variant. Provided strictly for cybersecurity research, threat intelligence, and defensive educational purposes.

Topics

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages