Threat Database Trojans Trojan.Modred

Trojan.Modred

By Domesticus in Trojans

Threat Scorecard

Popularity Rank: 23,567
Threat Level: 90 % (High)
Infected Computers: 24
First Seen: May 22, 2013
Last Seen: February 18, 2026
OS(es) Affected: Windows

Trojan.Modred is a Trojan that reroutes Internet traffic on the corrupted PC. Trojan.Modred may be spread to a victimized computer together with other malware infections. Trojan.Modred may slow down the affected computer and Internet connection. Trojan.Modred may drop and install additional malware infections onto the targeted computer system. Trojan.Modred enables cybercriminals to obtain full remote access and control of the attacked PC. Trojan.Modred may monitor the victim's browsing habits and gather confidential information.

Analysis Report

General information

Family Name: Trojan.Ulise.AB
Signature status: No Signature

Known Samples

MD5: 0141df7f44ee03018997de0a73c17fb0
SHA1: eb4bc366bc4c2fb2ad4439e01a1953acb01092f4
SHA256: 50D9E49153CE7203EB246FCAB2662BB676BC5C14DDBB28C4CDF69EB3EE141DD7
File Size: 859.14 KB, 859136 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
File Version 0.0.0.1
Legal Copyright Copyright (C) 2018
Product Name TODO: <Product name>
Product Version 1.0.0.9

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 1,008
Potentially Malicious Blocks: 219
Whitelisted Blocks: 789
Unknown Blocks: 0

Visual Map

0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x x x x x 0 x 0 x x x x x x x x 0 x x x 0 0 0 0 x 0 x x 0 x x x x x x x x 0 x x x x x x x 0 0 x x 0 0 x 0 x x x x x x x x x x x 0 x x 0 x x x x x x x x x x x x 0 0 0 x 0 0 x x x x x x x 0 0 x x x x 0 x x x x 0 x x x x x 0 x x x x 0 x x x x x x x x x x x x x 0 x x x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 0 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 x x x 0 0 x 0 0 0 x 0 x x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x x 0 0 0 0 x x x x x x x x x x x 0 x x 0 x 0 0 0 x x x x x x 0 0 0 x x x x x x 0 0 x x 0 0 0 0 0 x x x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 1 1 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 1 1 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 1 0 0 0 0 0 2 2 0 0 1 1 1 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Ulise.AB

Windows API Usage

Category API
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...