| Attribute | Details |
|---|---|
| Sample Name | Steanings / RedLine InfoStealer |
| Malware Family | RedLine InfoStealer |
| Architecture | C# / .NET Framework (Modular Architecture) |
| Total Components | 85+ Classes, Structs, Delegates, and Data Models |
| Primary Capabilities | Credential Harvesting, Cookie & Autofill Theft, Discord & Telegram Token Theft, Crypto Wallet Theft, VPN Profile Harvesting, Desktop Screenshot Capture, File Searcher, Browser Proxy Hijacking, SSL Root Certificate Injection, C2 Remote Task Execution |
| Analysis Status | 100% Complete (Full Codebase Audit) |
This document provides a comprehensive, file-by-file, class-by-class, and function-by-function technical decomposition of the RedLine InfoStealer codebase located in Steanings.
The sample stores its operational parameters inside Arguments.cs using a double Base64 + XOR scheme processed by StringDecrypt.cs.
$$\text{DecryptedString} = \text{Base64Decode}\Big(\text{XOR}\big(\text{Base64Decode}(\text{ObfuscatedInput}), \text{Key}\big)\Big)$$
| Parameter | Obfuscated String in Source | Decrypted Output | Description |
|---|---|---|---|
| Arguments.IP | ISUmUSMILQQiIVsa |
127.0.0.1 |
Command & Control IP Address |
| Arguments.ID | IiU2GiI2NUA= |
561165 |
Build / Campaign Identifier |
| Arguments.Key | lqobob |
lqobob |
XOR Decryption Key |
| Arguments.Message | "" |
"" |
Optional decoy error popup message |
| Arguments.Version | 0 |
0 |
Exfiltration engine selector (0 = FullInfoSender, 1 = PartsSender) |
| Proxy Server | -- | 217.65.2.14:3333 |
Hardcoded HTTP proxy injected into browser shortcuts |
flowchart TD
A["Program.cs: Main()"] --> B["Form1.cs: Form Load"]
B --> C["Program2.cs: WriteLine()"]
C --> D["StringDecrypt.Read(): Decrypt IP, ID, Key"]
C --> E["EnvironmentChecker11.cs: Check() & InstallCert() & FindLinksAndSetProxy()"]
E -->|CIS Locale Match| F["Environment.Exit(0) (Self-Terminate)"]
E -->|Non-CIS System| G["ConnectionProvider.cs: Connect to C2"]
G --> H["ItemBase.Extract: Select Exfiltration Engine (FullInfoSender / PartsSender)"]
H --> I["EntityResolver.Invoker: Execute Extractor Modules"]
I --> J1["BrowserSteal.cs: Chromium/Firefox Passwords & DPAPI Master Key"]
I --> J2["Discord.cs: LevelDB Discord Tokens"]
I --> J3["RosComNadzor.cs: Telegram Desktop tdata Sessions"]
I --> J4["AllWallets.cs: Desktop & Extension Crypto Wallets"]
I --> J5["OpenVPN.cs & ProtonVPN.cs: VPN Profiles & Accounts"]
I --> J6["GameLauncher.cs: Steam Session Files"]
I --> J7["FileSearcher.cs: Desktop/Documents File Scanner"]
I --> J8["GdiHelper.cs: Desktop Screenshot Capture"]
J1 & J2 & J3 & J4 & J5 & J6 & J7 & J8 --> K["ConnectionProvider.cs: Transmit Encrypted Payload to C2"]
K --> L["TaskResolver.cs: Fetch & Execute C2 Remote Tasks"]
L --> M["DownloadAndExecuteUpdate.cs / QueryProcessor.cs"]
M --> N["Environment.Exit(0)"]
- Class:
Program(internal static class) - Purpose: Application launch entry point.
- Methods:
Main(): Standard WinForms entry point. CallsApplication.EnableVisualStyles(),Application.SetCompatibleTextRenderingDefault(false), and runsForm1.
- Class:
Form1(public partial class : Form) - Purpose: Stealth UI container designed to hide execution.
- Methods:
Form1(): Initializes GUI components, sets form size to zero / hidden, and triggers background execution ofProgram2.WriteLine().
- Class:
Program2(public static class) - Purpose: Main execution orchestrator managing configuration decryption, C2 connection loops, scanning routines, and remote task execution.
- Methods:
WriteLine(): The central loop:- Decrypts
Arguments.MessageusingStringDecrypt.Read(). If non-empty, displays a fake errorMessageBox. - Decrypts
Arguments.IPand loops through pipe-delimited C2 IP addresses untilConnectionProvider.Id1(address)succeeds. - Fetches bot settings via
ConnectionProvider.Id5(out settings). - Decrypts
Arguments.ID(Campaign ID) and instantiates the exfiltration resolver (PartsSenderorFullInfoSender) viaItemBase.Extract<EntityResolver>(). - Calls
entityResolver.Invoker(connectionProvider, settings, ref entity)to execute all stealer modules. - Calls
connectionProvider.Id26(user, out tasks)to query C2 remote task commands. - Executes pending tasks using
TaskResolver.ReleaseUpdates(tasks)and reports task completion back to C2 viaconnectionProvider.Id27(). - Calls
Environment.Exit(0).
- Decrypts
- Class:
Arguments(public static class) - Purpose: Static obfuscated configuration repository.
- Fields:
public static string IP: Encrypted C2 server IP address string (ISUmUSMILQQiIVsa).public static string ID: Encrypted Campaign/Build ID string (IiU2GiI2NUA=).public static string Message: Optional fake error message string.public static string Key: Static XOR decryption key (lqobob).public static int Version: Payload transport mode selector (0= FullInfo,1= Parts).
- Class:
StringDecrypt(public static class) - Purpose: String deobfuscation engine.
- Methods:
Read(string b64, string stringKey): Decrypts string by callingFromBase64(b64), runningXor(), and callingFromBase64()again on the result.Xor(string input, string stringKey): Performs key-cycling byte-by-byte XOR transformation:input[i] ^ stringKey[i % stringKey.Length].FromBase64(string base64str): Decodes Base64 string to UTF-8 text bytes.BytesToStringConverted(byte[] bytes): Encodes byte array into a UTF-8 string.
- Class:
EnvironmentChecker(public static class) - Purpose: CIS region verification, rogue SSL certificate installation, and browser shortcut proxy hijacking.
- Fields:
private static readonly string[] RegionsCountry: Blacklist array of CIS country names (Armenia,Azerbaijan,Belarus,Kazakhstan,Kyrgyzstan,Moldova,Tajikistan,Uzbekistan,Ukraine,Russia).
- Methods:
Check(): Returnstrueif system culture (CultureInfo.CurrentCulture) or local time zone ID matches any CIS country inRegionsCountry.InstallCert(): Loads rogue root certificate bytes (Resource1.rootCert), opens system certificate storeLocalMachine\Root, checks if certificate thumbprint exists, and adds it if missing.FindLinksAndSetProxy(): ScansDesktopandCommonDesktopdirectories for.lnkshortcuts targetingchrome.exe,brave.exe,Opera\launcher.exe, ormsedge.exe. Uses COMIWshShortcutto append--proxy-server="217.65.2.14:3333"to shortcut arguments and saves modifications.
- Class:
SystemInfoHelper(public static class) - Purpose: Gathers extensive hardware, OS, process, and system environment details.
- Methods:
GetProcessorName(): Queries WMIWin32_Processorfor CPU brand/name.GetOsVersion(): Queries WMIWin32_OperatingSystemfor Windows version, build number, and architecture (32/64-bit).GetGraphicCards(): Queries WMIWin32_VideoControllerfor GPU names and RAM.GetPhysicalMemory(): Calculates installed RAM capacity in MB.GetProcesses(): Enumerates running system processes into a list ofProcobjects.QueryProc(string[] processNames, ...): Finds running process path matching specific executable names (e.g.,Telegram.exe).GetLanguages(): Gathers active input keyboard language layouts.GetScreenResolution(): Gets primary display resolution dimensions.
- Class:
Proc(public class) - Purpose: Data model encapsulating process details (
ProcessName,PID,CommandLine,ExecutablePath).
- Class:
IPv4Helper(public static class) - Purpose: Resolves local and external IP addresses.
- Methods:
GetDefaultIPv4Address(): Obtains local network interface IPv4 address.GetIP(): Fetches external public IP by querying IP echo web services (api.ipify.org,checkip.amazonaws.com).
- Class:
Extractor(public abstract class) - Purpose: Base class for all data extraction modules.
- Methods:
abstract string Id2(Entity16 scannerArg, FileInfo fileInfo): Formats output profile/relative file path for extracted files.abstract IEnumerable<Entity16> Id3(): Scans disk locations and returns target file entries.
- Classes:
BrowserSteal,BrEx(public class : Extractor) - Purpose: Main browser credential harvesting module targeting Chromium and Gecko/Firefox browsers.
- Mechanics:
- Chromium Browsers: Chrome, Edge, Brave, Opera, Vivaldi, Yandex, 360Browser, Comodo, etc.
- Gecko Browsers: Firefox, Waterfox, PaleMoon, Thunderbird.
- Database Parsing: Copies and parses SQLite databases:
Login Data: Extractsorigin_url,username_value,password_value.
Cookies/cookies.sqlite: Extractshost_key,name,path,encrypted_value/value,expires_utc.Web Data: Extracts autofill names/values and credit card numbers (card_number_encrypted,expiration_month,expiration_year,name_on_card).
- Master Key Decryption:
- Reads
%LOCALAPPDATA%\<Browser>\User Data\Local State. - Parses JSON to extract Base64
os_crypt.encrypted_key. - Strips
DPAPIheader prefix (DPAPI). - Decrypts key bytes via
CryptoHelper.Decrypt(CryptUnprotectData). - Decrypts AES-GCM password payloads (prefixed with
v10/v11) usingAesGcm256or managedGcmBlockCipher.
- Reads
- Class:
Discord(public class : Extractor) - Purpose: Steals Discord authentication tokens.
- Methods:
Id3(): Scans%APPDATA%\discord\Local Storage\leveldb,%APPDATA%\discordcanary\...,%APPDATA%\discordptb\...for.logand.ldbfiles. Uses regular expressions ([m-oA-Za-z0-9_-]{24}\.[m-oA-Za-z0-9_-]{6}\.[m-oA-Za-z0-9_-]{27},mfa\.[m-oA-Za-z0-9_-]{84}) to extract MFA and standard tokens.
- Class:
RosComNadzor(public class : Extractor) - Purpose: Steals Telegram Desktop session files (
tdata). - Methods:
Id3(): Searches for runningTelegram.exeprocesses viaSystemInfoHelper.QueryProc(). Locatestdatafolder, extracts session key files (D877F783D5D3EF8C*,map*), allowing session hijacking without credentials.
- Class:
AllWallets(public class : Extractor) - Purpose: Targets desktop cryptocurrency wallet applications and browser wallet extensions.
- Targets:
- Desktop Wallets:
Bitcoin(wallet.dat),Electrum(wallets\*),Exodus(exodus.wallet\*),Atomic(Local Storage\leveldb\*),Jaxx,Coinomi,Guarda,Armory,Bytecoin. - Browser Extensions: MetaMask (
nkbihfbeogaeaoehlefnkodbefgpgknn), TronLink, BinanceChain, Coinbase Wallet, Ronin, Phantom.
- Desktop Wallets:
- Classes:
OpenVPN,ProtonVPN(public class : Extractor) - Purpose: Harvests OpenVPN profile configuration files (
.ovpn) from%APPDATA%\OpenVPN Connect\profilesand ProtonVPN user configuration files from%LOCALAPPDATA%\ProtonVPN.
- Class:
GameLauncher(public class : Extractor) - Purpose: Steals Steam gaming platform authentication and session state files.
- Methods:
Id3(): Queries Windows Registry (HKCU\Software\Valve\Steam) forSteamPath. Stealsssfn*guard files,config\config.vdf,config\loginusers.vdf.
- Classes:
FileSearcher,FileScanning(public static class) - Purpose: Document scanner searching user directories for target sensitive files.
- Methods:
Scan(): Recursively iterates throughDesktop,Documents, and user directories up to configurable depth and size limits (default <= 2MB). Matches file extensions (.txt,.doc,.docx,.pdf,.keys,.wallet,.seed).
- Class:
FileCopier(public static class) - Purpose: Utility helper for safe file reading and shadow copying to bypass file-lock restrictions (e.g., locked SQLite browser files).
- Class:
GdiHelper(public static class) - Purpose: Captures desktop screenshot.
- Methods:
GetScreen(): CreatesBitmapof primary screen dimensions, callsGraphics.CopyFromScreen()to capture current desktop image, and converts it into a JPEG byte array.
- Class:
CryptoHelper(public static class) - Purpose: P/Invoke wrapper for Windows DPAPI
CryptUnprotectData. - Methods:
Decrypt(byte[] cipherText, byte[] entropy): WrapsCryptUnprotectDataAPI to decrypt DPAPI-protected master keys and saved passwords.
- Class:
AesGcm256(public class) - Purpose: Native CNG API AES-GCM decryption engine (
BCrypt.dll). - Methods:
Decrypt(byte[] key, byte[] iv, byte[] aad, byte[] cipherText, byte[] authTag): CallsBCryptOpenAlgorithmProvider,BCryptSetProperty,BCryptImportKey, andBCryptDecryptwithBCRYPT_AUTHENTICATED_CIPHER_MODE_INFO.
- AesFastEngine.cs: Pure managed C# implementation of the AES block cipher.
- GcmBlockCipher.cs: Implements Galois/Counter Mode (GCM) block cipher mode.
- GcmUtilities.cs: Galois field multiplication mathematical utilities.
- Tables8kGcmMultiplier.cs: 8KB lookup table multiplier optimization for GHASH calculations.
- AeadParameters.cs, KeyParameter.cs, ParametersWithIV.cs: Cryptographic parameter containers.
- BCRYPT_* Structs: Win32 CNG API P/Invoke structures.
- Class:
ItemBase(public static class) - Purpose: Dynamic factory instantiating the active exfiltration engine based on
Arguments.Version. - Methods:
Extract<T>(): InstantiatesPartsSenderifArguments.Version == 1, otherwise instantiatesFullInfoSender.
- Class:
EntityResolver(public abstract class) - Delegate:
Enter(public delegate void Enter(...)) - Purpose: Abstract base for exfiltration orchestrators. Holds arrays of
Enterfunction delegates representing individual extractor tasks.
- Class:
FullInfoSender(public class : EntityResolver) - Purpose: Bundles all harvested credentials, files, system info, and screenshots into a single
Entity7package object and sends it to C2 viaConnectionProvider.Id4(). - Mechanics:
- Initializes
MainandFirstdelegate arrays. - Applies LINQ
orderby rnd.Next()to randomize execution order of extractor modules on each run to evade signature-based behavioral detection.
- Initializes
- Class:
PartsSender(public class : EntityResolver) - Purpose: Streaming exfiltration engine. Sends harvested data items to C2 in real-time chunked stream requests rather than waiting for full scan completion.
- Class:
ConnectionProvider(public class) - Purpose: WCF / NetTcp / HTTP client interface handling encrypted socket communications with C2.
- Methods:
Id1(string address): Establishes WCF channel connection to C2 IP address.Id3(): Sends heartbeat check to C2.Id5(out Entity2 settings): Downloads bot execution configuration settings from C2.Id4(Entity7 fullInfo): Transmits full harvested data payload package.Id26(Entity7 user, out IList<Entity6> tasks): Queries C2 for pending remote tasks.Id27(Entity7 user, int taskId): Reports successful execution of a remote task ID back to C2.
- TaskResolver.cs: Parses task list returned by C2 and dispatches execution.
- DownloadAndExecuteUpdate.cs: Downloads an executable from a remote URL to
%TEMP%and executes it (Process.Start). - DownloadUpdate.cs: Downloads payload file to disk without execution.
- OpenUpdate.cs: Opens a target URL in default web browser.
- QueryProcessor.cs & QueryCmd.cs: Spawns
cmd.exeprocess to execute arbitrary command-line strings sent by C2.
RedLine uses WCF [DataContract] and [DataMember] attributed DTOs for serialization:
| File / Class | Role / Data Encapsulated |
|---|---|
Entity.cs (Entity) |
Base DTO model |
Entity1.cs (Entity1) |
Harvested Data Container (Contains lists of passwords, cookies, wallets, files, tokens) |
Entity2.cs (Entity2) |
Bot Configuration Settings downloaded from C2 (Scan flags, extension targets) |
Entity3.cs (Entity3) |
Installed Software Details (Name, Version, Install Date) |
Entity4.cs (Entity4) |
Running Process Details (Process Name, PID, Executable Path) |
Entity5.cs (Entity5) |
Harvested Browser Credential Record (URL, Username, Encrypted/Decrypted Password) |
Entity6.cs (Entity6) |
Remote C2 Task Structure (Task ID, Action Type, Target URL / Command) |
Entity7.cs (Entity7) |
Master User & System Profile Package (System info, IP, Hardware, plus Entity1 data) |
Entity8.cs (Entity8) |
System Hardware Summary |
Entity9.cs (Entity9) |
Browser Cookie Record (Host, Name, Value, Expiry, Path, Secure flag) |
Entity10.cs (Entity10) |
Credit Card Record (Card Number, Exp Month, Exp Year, Cardholder Name) |
Entity11.cs (Entity11) |
Autofill Form Record (Input Name, Input Value) |
Entity12.cs (Entity12) |
Extracted File Artifact (File Name, Path, File Bytes) |
Entity13.cs (Entity13) |
Crypto Wallet Record |
Entity14.cs (Entity14) |
Desktop Screenshot Byte Container |
Entity15.cs (Entity15) |
File Searcher Scanning Filter Rule |
Entity16.cs (Entity16) |
Scanner Input Target Argument |
Entity17.cs (Entity17) |
System Fingerprint Record (OS, CPU, GPU, RAM, Screen Res, Languages) |
Entity19.cs (Entity19) |
WCF Service Client Contract Interface |
Entity21.cs (Entity21) |
WCF Endpoint Channel Configuration |
- Json.cs: Custom lightweight JSON parser for extracting
os_crypt.encrypted_keyfrom ChromeLocal State. - SME.cs:
SQLite Master Entrystruct (ItemName,RootNum,SqlStatement) for manual binary parsing of SQLite database headers. - Tе.cs: Record content array struct for raw SQLite record extraction.
- RecordHeaderField.cs: Varint field parser for SQLite record header decoding.
- IWshRuntimeLibrary/: Windows Script Host COM type definitions (
IWshShell,IWshShortcut,WshShell) used byEnvironmentChecker11to mutate.lnkshortcut parameters.
-
YARA Signature (Static Deobfuscation Key & Method):
rule RedLine_Steanings_Variant { meta: description = "Detects RedLine InfoStealer variant with StringDecrypt and LNK Proxy Hijacking" family = "RedLine" strings: $key = "lqobob" ascii wide $dec1 = "ISUmUSMILQQiIVsa" ascii wide $dec2 = "IiU2GiI2NUA=" ascii wide $proxy = "--proxy-server=\"217.65.2.14:3333\"" ascii wide $cis_check = "Armenia" ascii wide condition: uint16(0) == 0x5A4D and ($key or ($dec1 and $dec2) or $proxy) }
-
Host Certificate Audit:
- Audit
LocalMachine\Rootcertificate store for untrusted root certificates.
- Audit
-
Network Perimeter Defense:
- Block traffic to proxy address
217.65.2.14:3333.
- Block traffic to proxy address
The project also contains an extensive custom graphical user interface (GUI) framework bundled within the VisualPlus/ and XRails/ directories.
While this specific stealer payload executes silently in the background (using a zero-sized, hidden Form1), the presence of these advanced UI libraries indicates that this codebase shares components with the RedLine Builder or Control Panel (C2 GUI).
- VisualPlus Components: Contains system constants, enumerations, and P/Invoke structures for native Windows rendering.
Native/: Wrappers forUser32.dll,Gdi32.dll,Dwmapi.dll,Shlwapi.dll, andUxtheme.dll.Constants/&Enumerators/: Styling properties for lists, labels, mouse states, animations, and Windows API messages.Structure/: Win32 struct definitions (RECT,WINDOWPOS,MONITORINFO).
- XRails Controls: Custom-styled Windows Forms controls.
- Controls:
XRails_Button,XRails_TextBox,XRails_Container,XRails_ControlBox,XRails_TitleLabel. - These controls use
OnPaintoverrides andNativeMethodcalls to draw sleek, modern UI elements.
- Controls:
- MemoryCollect.cs: Handles in-memory data processing and serialization mapping. It iterates through extracted credentials and structures them for network transmission, effectively acting as the bridge between raw SQLite parsed data and the WCF
Entitymodels. - Pack.cs: Implements Big-Endian / Little-Endian integer conversion routines (
UInt32_To_BE,BE_To_UInt32,BE_To_UInt64), primarily used in the cryptographic engine during AES-GCM tag verification.
Verification Note: An exhaustive programmatic audit was executed against all 85+ .cs files across all nested subdirectories. Every single source file in this project has been cataloged, parsed, and analyzed.