Gridinsoft Logo
File Icon

The modest-menu.exe File Analysis

Technical Analysis

File Name modest-menu.exe
File Type
Win32 EXE
Magic Bytes PE32+ executable (GUI) x86-64, for MS Windows
SSDEEP Hash
49152:J2yKgLM86qzl0HvjWAmRjGUhm807gM2VtG7T:JrvIH807gM2VtG7T
Scanner Version 1.0.228.174
Database Version 2025-10-27 13:00:16 UTC

Suspicious File Detected

Detected by 15 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
21%
Detection Rate
4,257,192
File Size (bytes)
15/72
Engines Detected
2025-10-27
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
211725418eb97792cac3d5faa8fbf2e0
SHA1
1dc84b1cfa0f43bcda0f163bc304b6bc59cc8ec9
SHA256
559d9d81346fafac713dd9c613f4b52a6dcd4db7740e4fff1ada17520bf2189e
SHA512
1f94d9b319ff981e78d7e191674cf75ecde6696ea229addce96bcce52f17c3b0b272dd8bffcc91c75fa572cf9464321a067e650dc5cab00a1c55d9759ed60deb
ImpHash
d42595b695fc008ef2c56aabd8efd68e

Security Engines with Detections (15 of 72)

Bkav
W64.AIDetectMalware Malicious
Elastic
malicious (high confidence) Malicious
ESET-NOD32
a variant of WinGo/Kryptik.KU Malicious
Cynet
Malicious (score: 99) Malicious
Kaspersky
HEUR:Trojan.Win64.Generic Malicious
F-Secure
Trojan.TR/Redcap.zitqt Malicious
McAfeeD
ti!559D9D81346F Malicious
Ikarus
Trojan.WinGo.Crypt Malicious
Google
Detected Malicious
Avira
TR/Redcap.zitqt Malicious
Microsoft
Trojan:Win32/Wacatac.B!ml Malicious
huorong
TrojanSpy/Stealer.rn Malicious
Fortinet
W64/GoKryptik.JY!tr Malicious
AVG
MalwareX-gen [Trj] Malicious
Avast
MalwareX-gen [Trj] Malicious
57 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 70586d63b8fd34bdea478c8d8177faae
Fuzzy: c96798e6456f45180baf07be088f85f7
dHash: 0030b030f0ccd4d4
Image Base 0x00400000
Entry Point 0x0046fc20
Compilation Time 1970-01-01 00:00:00
Checksum 0x0041e4dc (Actual: 0x0041e4dc)
OS Version 6.1
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 1 libraries
kernel32
Exports 0 functions
Resources 61 Resources
Sections 9 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 997,425 bytes 997,888 bytes 6.34 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 7D08172727214CDE8C1E3B1FF97D9020
.rdata 0x000f5000 1,829,416 bytes 1,829,888 bytes 6.19 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ FA6025BF4103CC29C8A6E715D4949BF2
.data 0x002b4000 354,304 bytes 55,808 bytes 3.91 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 475ED68CEFE9C88F9A35D151752D3126
.pdata 0x0030b000 22,284 bytes 22,528 bytes 5.27 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 8A5F200FBBEB1B7F71D873690B8DF857
.xdata 0x00311000 180 bytes 512 bytes 1.77 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 11B04742FBD4619395D4903D3DD0A2EC
.idata 0x00312000 1,342 bytes 1,536 bytes 4.01 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1AD08A5733867CD3EDD7EFD056557F17
.reloc 0x00313000 35,344 bytes 35,840 bytes 5.42 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 6625E3034D0214AB918FCB8AAB1A2D12
.symtab 0x0031c000 148,693 bytes 148,992 bytes 5.15 (Normal) IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 2767AF810D2C797F62DC1004022F523C
.rsrc 0x00341000 1,154,660 bytes 1,155,072 bytes 4.19 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 849499551490C21014D3057121D64A5A

Resource Analysis

Total Resources: 61 (1,151,605 bytes)
Resource Type Count Total Size Percentage
RT_ICON 31 1,142,413 bytes
99.2%
RT_DIALOG 28 8,746 bytes
0.8%
RT_GROUP_ICON 2 446 bytes
0%

Certificate Chain Analysis

Certificate Information
Certificate Chain Summary
XSOLLA (USA), INC. #1 Primary
Validity Period: 2020-12-16 00:00:00 → 2021-12-20 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 08 7D 64 76 45 07 CF BE 52 69 80 7B 82 34 77 8C
DigiCert EV Code Signing CA (SHA2) #2 Chain
Validity Period: 2012-04-18 12:00:00 → 2027-04-18 12:00:00
Signature Algorithm: sha256RSA
Serial Number: 03 F1 B4 E1 5F 3A 82 F1 14 96 78 B3 D7 D8 47 5C
Symantec SHA256 TimeStamping CA #3 Chain
Validity Period: 2016-01-12 00:00:00 → 2031-01-11 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 7B 05 B1 D4 49 68 51 44 F7 C9 89 D2 9C 19 9D 12
Symantec SHA256 TimeStamping Signer - G3 #4 Chain
Validity Period: 2017-12-23 00:00:00 → 2029-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 7B D4 E5 AF BA CC 07 3F A1 01 23 04 22 41 4D 12

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
15 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware