Gridinsoft Logo
File Icon

Modest-menu.exe Trojan RedLine Analysis

Technical Analysis

File Name modest-menu.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.190.174
Database Version 2024-09-22 20:00:26 UTC
⚠

Trojan.Win32.RedLine.mz!n

Malware family: RedLine

RedLine Stealer is a data exfiltration tool that targets browser data, system information, and installed software credentials. It spreads through email attachments and compromised websites. Beyond data theft, it serves as a delivery mechanism for additional malware payloads, creating multiple attack vectors on infected systems.
N/A
Detection Rate
4,956,972
File Size (bytes)
2024-09-22
Analysis Date

Scan Another File

The uploaded file itself is not retained or shared with third parties. File names, hashes, and analysis results may appear in public reports. For confidential material, contact Support before uploading. How we use your data.

File Identification

Hash Type Value Action
MD5
95b19538dfa7a5a409124b7a415e4764
SHA1
cbabc2829faf533b99191bde1e12612a1d23509b
SHA256
cd07f55fee9c352d07424a5a45e657f139d908bdfa73896f6dc92402dd42a6ca
SHA512
0465df7bdf21cac1be4fb916d44099ed4f4a6aa20108595fee2333b5431eeeb623a99654315db6f53922098bbfac7793fa6455d7c17167e389466b5b8fb5cb50
ImpHash
4328f7206db519cd4e82283211d98e83

PE Analysis

Basic Information

▼
Icon
Hash: fd0d7e7755adc0ea9ccca581d1f3389e
Fuzzy: b268c68a90cd683448e21cd46852730e
dHash: 00ccd8d4ccf030c4
Image Base 0x00400000
Entry Point 0x00f16000
Compilation Time 2077-08-19 09:06:07
Checksum 0x004bb212 (Actual: 0x004c7457)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 2 libraries
kernel32, mscoree
Exports 0 functions
Resources 5 Resources
Sections 8 Sections

Version Information

▼
Translation 0x0000 0x04b0
Comments XHP Booster
CompanyName
FileDescription XHP
FileVersion 12.9.1.22
InternalName Seignories.exe
LegalCopyright XHP Corporation Copyright © 2021
LegalTrademarks
OriginalFilename Seignories.exe
ProductName XHP booster
ProductVersion 12.9.1.22
Assembly Version 1.1.21.1

PE Sections

▼
Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00002000 196,608 bytes 191,488 bytes 6.21 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 89CE047EAC735B996FB8E73869E637C2
0x00032000 147,980 bytes 61,445 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 02193C69C72B975D3D4259730143FB82
0x00058000 12 bytes 15 bytes 3.77 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 7BAB651E9ACD8B6D5EB282045D93C64F
.imports 0x0005a000 8,192 bytes 1,024 bytes 0.64 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7F8970A849F0D15E9A35FD0A70EE89CB
.rsrc 0x0005c000 50,176 bytes 50,176 bytes 7.90 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BC59EF6101E36C544F6964E3BF9844CE
.themida 0x0006a000 6,553,600 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.boot 0x006aa000 4,629,504 bytes 4,629,504 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 794EA5FD501E21C8292AC9EE65112DA4
.taggant 0x00b16000 9,216 bytes 8,212 bytes 0.30 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ BB61BBABC38922589D1762A03B6014ED
Entropy Analysis Alert

3 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

▼
Total Resources: 5 (48,915 bytes)
Resource Type Count Total Size Percentage
RT_ICON 1 46,331 bytes
94.7%
RT_GROUP_ICON 1 20 bytes
0%
RT_VERSION 1 858 bytes
1.8%
RT_MANIFEST 2 1,706 bytes
3.5%

Certificate Chain Analysis

▼
No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win32.RedLine.mz!n Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.RedLine.mz!n without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. 1
    Get Gridinsoft Anti-Malware — it's a quick 2 MB download that won't slow down your PC.
  2. 2
    Run the installer gsam-en-install.exe. The setup takes about 2 minutes and doesn't require a restart.
  3. 3
    The app launches right after installation. You'll see the main dashboard with the scan button front and center.
  4. 4
    Hit "Standard Scan" — this checks all the spots where malware typically hides: temp folders, browser data, startup programs, and system directories.
  5. 5
    Once the scan finds this threat, click "Clean Now". The removal usually happens instantly, though some stubborn infections may need a reboot.
  6. 6
    If you see a restart prompt, go ahead and reboot. This clears any malware that was running in memory and ensures your system starts fresh.
Important: Before You Start
Quick tip: unplug from the internet before scanning. Some malware phones home for instructions or downloads extra payloads when it senses trouble. If the infection is severe, boot into Safe Mode first — it limits what can run and makes cleanup easier.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware