Malware RedLine Malware Analysis

Online Virus Checkerv.1.0.139.174
DB Version:2023-09-15 12:03:27
Available languages:ENESBRFRDEUACN

Scan Your File

Analyze suspicious files to detect malware and automatically share them with our team. You can compress your file into a zip archive (if needed, we use the password "infected" to extract before checking).

Malware.Win32.RedLine.bot

RedLine Stealer is a malicious program designed to exfiltrate users’ confidential data from browsers, systems, and installed software. It is often delivered through email attachments or compromised websites. RedLine not only steals sensitive information but also poses a significant threat by introducing other malware into the victim's operating system. This two-pronged attack approach makes RedLine a potent and dangerous cyber threat.

Checked:2023-09-15 09:19:06
MD5:3b1efcafca28654e7ee16923ce5a56d2
SHA1:89f33e99cbdc8cc8594ec7f5388c584fd5837e3b
SHA256:6b3ac18fa5d0a3a4ecfe6800c8d6449c166516d60f3661bf72a4ecd24fcfbd3b
SHA512:ccbbd55807b8ecbc34e81697a3de7c293cc847e6b8bfac47916f22d0df88bcf63e3c2fcb7a7a14d9acd883f1129f970f0c04d9d602532fe7c9b8a0e2a7528e43
Imphash:29c8b785823d6c11cf3aae5ebbb5f0e6
File Size:825856 bytes

Malware.Win32.RedLine.bot Removal

Gridinsoft has the capability to identify and eliminate Malware.Win32.RedLine.bot without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

Portable Executable Info

Image Base:0x00400000
Entry Point:0x0040d5dc
Compilation:2023-09-12 22:37:07
Checksum:0x00000000 (Actual: 0x000d0e7e)
OS Version:6.0
PEiD:PE32 executable (console) Intel 80386, for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:6
Imports: USER32, ole32, KERNEL32,
Exports: 1
Resources:1

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00001000 0x0002967c 0x00029800 f352a3630895f04450834e08d91b39d0 6.60
.rdata 0x0002b000 0x0000efa4 0x0000f000 bca45e663bb2b385ee6fbd9e481fe4f3 5.44
.data 0x0003a000 0x00002b10 0x00001c00 ed3356dfdf856ccbae026cf6e70449f8 4.16
.bsp 0x0003d000 0x0008ca90 0x0008cc00 3f7536edffa511d6c2c9a227f6ee7bb3 7.85
.rsrc 0x000ca000 0x000001e0 0x00000200 d4b97648991d0055be3ff0f7c7ce98b9 4.72
.reloc 0x000cb000 0x000022f0 0x00002400 34cbd75acb1584da6de7a22fd5c0c35b 6.49

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware