Gridinsoft Logo
File Icon

Modest-menu.exe Trojan RedLine Analysis

Technical Analysis

File Name modest-menu.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.190.174
Database Version 2024-09-22 20:00:26 UTC

Trojan.Win32.RedLine.mz!n

Malware family: RedLine

RedLine Stealer is a data exfiltration tool that targets browser data, system information, and installed software credentials. It spreads through email attachments and compromised websites. Beyond data theft, it serves as a delivery mechanism for additional malware payloads, creating multiple attack vectors on infected systems.
N/A
Detection Rate
4,956,972
File Size (bytes)
2024-09-22
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
95b19538dfa7a5a409124b7a415e4764
SHA1
cbabc2829faf533b99191bde1e12612a1d23509b
SHA256
cd07f55fee9c352d07424a5a45e657f139d908bdfa73896f6dc92402dd42a6ca
SHA512
0465df7bdf21cac1be4fb916d44099ed4f4a6aa20108595fee2333b5431eeeb623a99654315db6f53922098bbfac7793fa6455d7c17167e389466b5b8fb5cb50
ImpHash
4328f7206db519cd4e82283211d98e83

PE Analysis

Basic Information

Icon
Hash: fd0d7e7755adc0ea9ccca581d1f3389e
Fuzzy: b268c68a90cd683448e21cd46852730e
dHash: 00ccd8d4ccf030c4
Image Base 0x00400000
Entry Point 0x00f16000
Compilation Time 2077-08-19 09:06:07
Checksum 0x004bb212 (Actual: 0x004c7457)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 2 libraries
kernel32, mscoree
Exports 0 functions
Resources 5 Resources
Sections 8 Sections

Version Information

Translation 0x0000 0x04b0
Comments XHP Booster
CompanyName
FileDescription XHP
FileVersion 12.9.1.22
InternalName Seignories.exe
LegalCopyright XHP Corporation Copyright © 2021
LegalTrademarks
OriginalFilename Seignories.exe
ProductName XHP booster
ProductVersion 12.9.1.22
Assembly Version 1.1.21.1

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00002000 196,608 bytes 191,488 bytes 6.21 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 89CE047EAC735B996FB8E73869E637C2
0x00032000 147,980 bytes 61,445 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 02193C69C72B975D3D4259730143FB82
0x00058000 12 bytes 15 bytes 3.77 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 7BAB651E9ACD8B6D5EB282045D93C64F
.imports 0x0005a000 8,192 bytes 1,024 bytes 0.64 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7F8970A849F0D15E9A35FD0A70EE89CB
.rsrc 0x0005c000 50,176 bytes 50,176 bytes 7.90 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BC59EF6101E36C544F6964E3BF9844CE
.themida 0x0006a000 6,553,600 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.boot 0x006aa000 4,629,504 bytes 4,629,504 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 794EA5FD501E21C8292AC9EE65112DA4
.taggant 0x00b16000 9,216 bytes 8,212 bytes 0.30 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ BB61BBABC38922589D1762A03B6014ED
Entropy Analysis Alert

3 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 5 (48,915 bytes)
Resource Type Count Total Size Percentage
RT_ICON 1 46,331 bytes
94.7%
RT_GROUP_ICON 1 20 bytes
0%
RT_VERSION 1 858 bytes
1.8%
RT_MANIFEST 2 1,706 bytes
3.5%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win32.RedLine.mz!n Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.RedLine.mz!n without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware