Gridinsoft Logo
File Icon

SAntivirusWD.exe Trojan Heuristic Analysis

Technical Analysis

File Name SAntivirusWD.exe
File Type
PE32+ executable (console) x86-64, for MS Windows
Scanner Version 1.0.154.174
Database Version 2024-01-15 01:03:51 UTC

Trojan.Heur!.00016023

Malware family: Heuristic

Heuristic detection uses behavioral analysis and pattern recognition to identify potential threats without specific signatures. This proactive approach detects suspicious code behavior that may indicate malware presence. Detection may occasionally produce false positives when legitimate software exhibits similar behavioral patterns.
N/A
Detection Rate
74,770,848
File Size (bytes)
2024-01-15
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
f0d41c048482ae563bfaba92f4b323df
SHA1
f7db99926c1c4408921365f9dfda9e23ada2a783
SHA256
5013e953a55534b83f74be41d5a08048f57e52be78c776566d58d296a0e7b381
SHA512
ac180878080123baf5e99b0419b3a9f7ad6c7e2bbd8a82e6b45dd94d3de48e2fc17545221aec94fbe421371ae8f1cc2b331615d279cf26e1d71508d5640a014d
ImpHash
87b79871203ea245059d92a2ab553b6f

PE Analysis

Basic Information

Icon
Hash: f33c31bbe5e37d7d2d48f3b2f9dbf889
Fuzzy: 14e33edbae4e2016dd5ba8d1dc15dddc
dHash: c08362434b69a6c8
Image Base 0x140000000
Entry Point 0x1400ec474
Compilation Time 2023-04-07 18:11:07
Checksum 0x0074ef7b (Actual: 0x04752629)
OS Version 6.0
PEiD Signatures PE32+ executable (console) x86-64, for MS Windows
Digital Signature Unknown certificate revision b5e6
Imports 19 libraries
Exports 0 functions
Resources 7 Resources
Sections 16 Sections

Digital Signatures

Segurazo Security Segurazo Security (CA)

Version Information

CompanyName DlGlTAL COMMUNICATIONS INC
FileDescription IServ
FileVersion 1.0.22.33
InternalName IServ
LegalCopyright DlGlTAL COMMUNICATIONS INC
OriginalFilename IServ
ProductName IServ
ProductVersion 1.0.22.33
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,314,080 bytes 2,314,240 bytes 6.48 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 3B4ED70EABEE589BD2A0155DAE93E2CE
.fdata 0x00236000 186 bytes 512 bytes 2.77 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ ED044A3C2E2DC7EF655EE144D336FCAB
.code2 0x00237000 479 bytes 512 bytes 4.34 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ C2262431B34FEC58E005756A1BAC3D27
.code3 0x00238000 3,928 bytes 4,096 bytes 5.97 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 41B1B7CAC9BF4A0ECF098B8E536893F2
.code4 0x00239000 1,196 bytes 1,536 bytes 5.35 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 8FE73101A44FB0C26480D0DFAAD53170
.code1 0x0023a000 2,412 bytes 2,560 bytes 5.97 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 276368249272FC22F2B7B739FDDAC430
.code 0x0023b000 11,752 bytes 11,776 bytes 6.01 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ E30C336F54417A0B1936CD86FA6373BB
.code5 0x0023e000 1,190 bytes 1,536 bytes 4.91 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ E7E161C8CE6598336FF4B62A64108C1D
.code6 0x0023f000 9,544 bytes 9,728 bytes 5.85 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 2372CAE56E81CCBECF220BCD028B5844
.code7 0x00242000 9,692 bytes 9,728 bytes 6.09 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 758FE1DEF761BAB35FF309FDD7857C54
.rdata 0x00245000 4,849,178 bytes 4,849,664 bytes 7.89 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 2EA14844A082BF6087880025AF54FD5E
.data 0x006e5000 79,180 bytes 64,000 bytes 5.23 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 887F958AAA144E44F2B18E3A3C40A8B6
.pdata 0x006f9000 118,644 bytes 118,784 bytes 6.32 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E3914A36A6DA74AFE36A32153EFF98C7
.gfids 0x00716000 5,652 bytes 6,144 bytes 3.84 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7531A774DA6AEA899F517B19172BD653
.tls 0x00718000 9 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1F354D76203061BFDD5A53DAE48D5435
.rsrc 0x00719000 257,160 bytes 257,536 bytes 7.96 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 2E036F7CC01D1B7C084DF8E5EB3F657F
Entropy Analysis Alert

2 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 7 (256,667 bytes)
Resource Type Count Total Size Percentage
RT_ICON 2 13,904 bytes
5.4%
RT_RCDATA 2 241,648 bytes
94.1%
RT_GROUP_ICON 1 34 bytes
0%
RT_VERSION 1 700 bytes
0.3%
RT_MANIFEST 1 381 bytes
0.1%

Certificate Chain Analysis

Certificate #1
Subject Segurazo Security
Segurazo Security
CA
Issuer Segurazo Security
Serial Number -2777590441930211166224332569712903199
Certificate Verification Status

Unknown certificate revision b5e6

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Heur!.00016023 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.00016023 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware