Redline Stealer Malware Analysis with Surface, Runtime, and Static Code Methods
Fahmi Ramadan, Ira Rosianal Hikmah · 2023
Data is becoming a new resource with high value, so many parties are interested in owning it. There are many ways to take it, one of which is planting and spreading malware known as stealer malware. Over time, malware has become more sophisticated, targeted, complex, commercialized, and scalable for a wider range of attacks. This makes malware analysis an important job requiring a lot of time, expertise, and extensive knowledge, both by individuals and teams of analysts. This study will analyze stealer malware using three analytical methods: surface, runtime, and static code. In malware analysis using the surface method, malware is tested by scanning by antivirus, hashing malware, and package/obfuscated detection, followed by Portable Executable analysis and malware sandbox analysis. In the runtime method, the malware is run for further observations of registry changes, DNS activity observations, and network data communication activities. In research using the static code analysis method, tests were carried out to find the relationship between the use of linked libraries and functions, string search as a guide for working steps of malware, and debugging malware to explore deeper into malware behaviour. The results obtained are information about the characteristics of the malware stealer and its impact on the test environment.