Reeling in RedLine Stealer
Context
Reeling in RedLine Stealer
Context
I have been recently trying to come up with ways to generate threat traffic so I can keep up with the latest attacks. A while back, I decided to purchase a domain to create a catch-all email (and abuse email sign ups for coupon codes). Upon doing so, I started getting a lot more phishing emails that I would just filter into spam and/or report and ignore them since they were fairly obvious.
Then I realized I was missing a crucial opportunity here. If we look at how cyber attacks are initiated, in the majority of cases, it begins with a phishing email that someone clicked on. When clicked, a payload is dropped and the situation escalates. I decided it was time to utilize this domain I purchased to harvest phishing emails and investigate current attacks.
The Phish in the Sea
While we will be exploring phishing using a custom domain, this article will not discuss how to setup a custom domain so you can conduct the same activity. There are plenty of tutorials out there on how to set this up. In my case, I decided to purchase my domain off Namecheap and use Protonmail as my email provider with a paid subscription.

Also note that the Copyright is 2024 when this email was received Jan 22, 2025
So, here is our email above!
This phish landed in my catch all net with an email I don’t use. The email seems to be a verify link for CIBC (a Canadian bank).
Upon opening it in Notepad++, we see some interesting details below.

First off, I do not use the email nhemings@datamail.ca. Therefore, this landed in my catch-all email. We also managed to grab an IP address from the sender of 154[.]127[.]53[.]77.
Upon running this through VirusTotal, we can see an important relationship with this IP.

A common file associated with this IP is the SHA256 of the following:
fcc7eb446093f092eec4f1ba25b2608e77326b3e12df5680963504b96afc01f6
which is associated with RedLine Stealer. Further information on this file can be found here:
https://www.virustotal.com/gui/file/fcc7eb446093f092eec4f1ba25b2608e77326b3e12df5680963504b96afc01f6
After decrypting the body from base64 using Cyberchef, there is a truncated link embedded in the email which is connected to the verify button as seen below.

Without clicking on this dangerous link, I decided to run it through Cloudflare’s URL scanner.
Under the Network tab, you can see the following DNS record.

Running this IP through VirusTotal, we can see it is associated with many suspicious domains such as BMO, RBC, and Costco.

Conclusion
It is important to have proper email filters setup to prevent being phished. While I do have a CIBC account, it is not my primary bank. This specific phishing email landed in my catch-all domain which was suspicious in itself because my CIBC account uses my primary email address which made it easy to identify as a phishing email. While this article focuses on analyzing a phishing email associated with common malware, it is important to have proper organization skills to prevent phishing attempts that would’ve loaded a trojan onto my computer.
메타데이터
- post_id
- b54ddf3ecb15
- slug
- reeling-in-redline-stealer-b54ddf3ecb15
- url
- https://medium.com/@ksinclair6/reeling-in-redline-stealer-b54ddf3ecb15
- canonical_url
- https://medium.com/@ksinclair6/reeling-in-redline-stealer-b54ddf3ecb15
- author_url
- https://medium.com/@ksinclair6
- status
- ok
- fetched_at
- 2026-09-02 08:50:55