Skip to main content
Malware Investigation: RedLine Stealer Infostealer Campaign operation cover
IntermediateSIEMXDRFirewall

Malware Investigation: RedLine Stealer Infostealer Campaign

Investigate a RedLine Stealer infection originating from a malicious 'Netflix Checker' application. Analysts will trace the execution from the initial dropper to the final payload, identify the specific sensitive data targeted (browsers, crypto wallets, VPNs), and analyze the SOAP-based C2 communication used for exfiltration.

1h
9 tasks
150 points
Free

Start this operation

Create your free account and begin immediately.

Get Early Access — Free

Free forever — no credit card required

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Identifying the Initial Entry Point

10
SOC{domain_name}Hint available
2

Dropper Execution and Decryption

15
SOC{sha256_hash}Hint available
3

Analyzing Payload Masquerading

15
SOC{filename}Hint available
4

Brute Force Source Identification

20

Identify the external IP address that successfully gained access to the FIN-WS-01 workstation via a RemoteInteractive logon after multiple failed attempts.

SOC{...}Hint available
5

Profiling the Victim's Location

15
SOC{domain_or_url}Hint available
6

Crypto Wallet Discovery

20
SOC{wallet_name}Hint available
7

Persistence Mechanism

15
SOC{filename}Hint available
8

C2 Infrastructure Identification

20
SOC{domain:port}Hint available
9

Analyzing Exfiltration Volume

20
SOC{bytes_sent} - Just the numberHint available

9 tasks · 150 points total

Start investigation

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
XDR log analysis
Firewall log analysis
MITRE ATT&CK technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Intermediate

Requires foundational alert triage skills. Multiple data sources to correlate.

Prerequisites

  • Basic understanding of security alerts
  • Familiarity with SIEM concepts
  • Familiarity with XDR concepts
  • Familiarity with Firewall concepts

Ready to investigate?

Create your free account and begin immediately.

Get Early Access — Free

Free forever — no credit card required

More Operations

View all

We use cookies to improve your experience and measure usage. Learn more