Gridinsoft Logo

CGHotman_Redshift_Server.exe Malware Generic Analysis

Technical Analysis

File Name CGHotman_Redshift_Server.exe
File Type
PE32+ executable (console) x86-64, for MS Windows
Scanner Version 1.0.227.174
Database Version 2025-10-10 15:00:15 UTC

Malware.Win64.Generic.cld

Malware family: Generic

This detection name identifies suspicious files displaying Trojan-like behavior patterns. It represents malware that masquerades as benign programs while executing unauthorized activities on the infected system.
N/A
Detection Rate
8,071,680
File Size (bytes)
2025-10-10
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
b0d6ae3bae0ecf922835e88f0d2651f2
SHA1
ca62d67d5eeec91bd5d7b683198af9b5c3afe396
SHA256
802ff85804d2980c56a008faaf630d43fbabd1cf3926d154189fb482d9e64948
SHA512
26fc0a5e5fa3e1849afc4090cb74edb712f72a12495026d3d90d4d75190ce153d340c63d3ee57c32fa5810637d8598442de240c9e27a3f149c8d7fcfcac0c87a
ImpHash
f0826202236df596bec1f1c47fc3f726

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x140e59058
Compilation Time 2021-06-15 23:53:33
Checksum 0x007bea2e (Actual: 0x007bf9ac)
OS Version 5.2
PEiD Signatures PE32+ executable (console) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 10 libraries
kernel32, IPHLPAPI, WS2_32, ADVAPI32, USER32, SHELL32, WINHTTP, ole32, OLEAUT32, PatchCode
Exports 0 functions
Resources 24 Resources
Sections 11 Sections

Version Information

Comments
CompanyName Reprise Software Inc.
FileVersion 14, 2, 4, 0
LegalCopyright Copyright © 2006-2021
PrivateBuild
ProductName RLM
ProductVersion 14, 2, 4, 0
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 1,796,330 bytes 737,280 bytes 7.98 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ C535641D84809A1509E276DF54125967
0x001b8000 175,166 bytes 74,240 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ EE9D43B1D2A74E80E2025BC27FD599FC
0x001e3000 1,485,444 bytes 104,960 bytes 7.97 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1AEF08A7F094014789A29B8ECC01C243
0x0034e000 60,660 bytes 36,864 bytes 7.59 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ A48553A10687059E3186EB8C1176AA4F
0x0035d000 116 bytes 512 bytes 3.49 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 867386D25FE60475C287116E5845B2E9
0x0035e000 688 bytes 512 bytes 5.85 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 357C1E72638CB26134045E37A36DE313
0x0035f000 21,106 bytes 3,584 bytes 7.80 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ DCE165D13B551588288AFB6C7C71B5FD
.idata 0x00365000 4,096 bytes 1,024 bytes 2.56 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3195CF84D3EF51383ED94B5D3473AADE
.rsrc 0x00366000 8,704 bytes 8,704 bytes 4.71 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6EA012849AD0C130F25F4A90C3245117
.winlice 0x00369000 11,468,800 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.boot 0x00e59000 7,102,746 bytes 7,102,976 bytes 7.96 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 4D8C35ECA70543D513ECCE51D8B15493
Entropy Analysis Alert

6 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 24 (7,011 bytes)
Resource Type Count Total Size Percentage
RT_DIALOG 6 1,456 bytes
20.8%
RT_STRING 9 85 bytes
1.2%
RT_RCDATA 8 4,882 bytes
69.6%
RT_VERSION 1 588 bytes
8.4%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Malware.Win64.Generic.cld Removal

Gridinsoft has the capability to identify and eliminate Malware.Win64.Generic.cld without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware