Threat Database Trojans Trojan.MSIL.Redline

Trojan.MSIL.Redline

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,057
Threat Level: 80 % (High)
Infected Computers: 29,472
First Seen: January 7, 2013
Last Seen: March 4, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Redline
Signature status: No Signature

Known Samples

MD5: f932e207f1df24949dae0d5ac0ec6811
SHA1: 2bc8cccb04f912275bce694c7b455672cea91325
SHA256: 5F321809C6425BF908A2F99A2DBB569DDCEC056A9A10EBF0424E1D268B6D5A85
File Size: 467.79 KB, 467788 bytes
MD5: 71f6a9c9ba62f022e2a16f806bf8dc0f
SHA1: d81126bdb01372ddb3e60a087565c40571d70443
SHA256: A13F81F71339F7C1B1C5B805D32CEED1B9A0FCCDE4109226945452DD7766CD8F
File Size: 307.71 KB, 307712 bytes
MD5: 422a6c2d270b14e48fd2f2d916fb45d8
SHA1: dfdb8aeae9b955e07168d25f38587a1e7670dfcb
SHA256: 448023A221FB284BD6F90BACA26ABF84969E8FE35E814FDD0A3969BE2E2AF59F
File Size: 179.54 KB, 179536 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 15.9.28307.1440
  • 1.1.21.1
Comments
  • Visual Studio Installer
  • XHP Booster
File Description
  • Microsoft Visual Studio
  • XHP
File Version
  • 15.9.28307.1440
  • 12.9.1.22
  • 1.00
Internal Name
  • Squama.exe
  • Steanings.exe
  • TJprojMain
Legal Copyright
  • Microsoft Corporation Copyright © 2021
  • XHP Corporation Copyright © 2021
Original Filename
  • Squama.exe
  • Steanings.exe
  • TJprojMain.exe
Product Name
  • Project1
  • Visual Studio
  • XHP booster
Product Version
  • 15.9.28307.1440
  • 12.9.1.22
  • 1.00

File Traits

  • .NET
  • 00 section
  • 2+ executable sections
  • HighEntropy
  • Installer Version
  • x86

Block Information

Total Blocks: 212
Potentially Malicious Blocks: 148
Whitelisted Blocks: 31
Unknown Blocks: 33

Visual Map

? ? ? ? ? x ? x ? ? ? ? ? x x ? x x x x x x x x ? ? ? x ? ? ? x x x x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x ? x x 0 x ? x x x x x x x x x x x x x x x x x x x x x x 0 x ? x x x x x x x 0 0 x 0 0 x x x x x x x x x x x x x x x x x x 0 x x ? 0 0 x x ? 0 ? 0 x x x x ? ? x x 0 x x x x x x x x 0 0 x x x x 0 x x x x ? x 0 ? x x x x ? ? ? x x x ? x x 0 x x 0 0 x x x x 0 x x x x 0 0 0 0 0 0 x x 0 ? 0 x x 0 x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Stealer.RAR

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

Related Posts

Trending

Most Viewed

Loading...