Gridinsoft Logo

@WhoiseInfo_Fatality.exe Trojan Heuristic Analysis

Technical Analysis

File Name @WhoiseInfo_Fatality.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.212.174
Database Version 2025-04-05 21:00:50 UTC

Trojan.Heur!.022520A3

Malware family: Heuristic

Heuristic detection uses behavioral analysis and pattern recognition to identify potential threats without specific signatures. This proactive approach detects suspicious code behavior that may indicate malware presence. Detection may occasionally produce false positives when legitimate software exhibits similar behavioral patterns.
N/A
Detection Rate
13,551,616
File Size (bytes)
2025-04-05
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
93fa727b0b2b6e33aaf28fb26a26c5ab
SHA1
948b2f09a5a58a49888b21b33ccfcfaa2ccd041f
SHA256
9e75c195fd5d46002021ff42cd60bd0d663b564b57930016019dc78129a9432f
SHA512
1c3f9c3cdbdb21caaed6042975cef208d0f714780c7c149ffc77125329b074651aef6fe42a56815bf5b8c110e2123f82049c811ae4e5e7953f77138dba1d5d5a
ImpHash
76ed0ff71316a363345c9471f9e4d3dc

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x140a0cdb0
Compilation Time 2025-04-05 10:56:55
Checksum 0x00000000 (Actual: 0x00cf7a9a)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 6 libraries
ntdll, KERNEL32, WS2_32, USER32, SHELL32, ole32
Exports 1 functions
Resources 1 Resources
Sections 14 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 724,162 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.rdata 0x000b2000 116,236 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.data 0x000cf000 16,988 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.pdata 0x000d4000 20,832 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.gxfg 0x000da000 9,552 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.ksw 0x000dd000 180 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.license 0x000de000 4,096 bytes 4,096 bytes 0.10 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0F30D694E3DA6732D35939B260D8076E
.retplne 0x000df000 140 bytes 0 bytes 0.00 (Normal) 0x00000000 D41D8CD98F00B204E9800998ECF8427E
_RDATA 0x000e0000 500 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.xDJ 0x000e1000 8,837,075 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.l<P 0x0094f000 144 bytes 512 bytes 0.34 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7D4E7E8EF81B26FF6765584F2DADB6F5
.4|R 0x00950000 13,544,672 bytes 13,544,960 bytes 7.88 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 18747F2EFE6777CD23850268D6D4EB84
.rsrc 0x0163b000 422 bytes 512 bytes 4.26 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ BA2C9A50500E945BCE48CADDBA1E54BA
.reloc 0x0163c000 252 bytes 512 bytes 2.53 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ BB57226BD253563434EA121CA3EBFDD3
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 1 (334 bytes)
Resource Type Count Total Size Percentage
RT_MANIFEST 1 334 bytes
100%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Heur!.022520A3 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.022520A3 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware