Analysis of HEURRemoteAdmin.GoToResolve.gen
Essential information
- Published
- 22/01/2026 00:39
- Modified
- 22/01/2026 11:19
- Tags
- 2026-01-22 digital signature gotoresolve heurremoteadmin.gotoresolve.gen pua ransomware remote access security-risk unattended-access wiper
- Related entities
- 2 observables, 1 malware
Description
A comprehensive analysis of a Potentially Unwanted Application (PUA) identified as HEURRemoteAdmin.GoToResolve.gen reveals its association with the GoTo Resolve Unattended Access application. While digitally signed by GoTo Technologies USA, LLC, the sample exhibits behaviors typical of PUAs, including silent installation, background thread execution, and persistent presence on the system. The application's use of the Restart Manager library, often seen in ransomware and wiper malware, raises concerns. Although no direct malicious payload was observed, the remote access capabilities present a significant security risk, potentially allowing unauthorized system control or deployment of secondary malware. The sample's detection by UltraAV further supports its classification as a security threat, warranting removal unless explicitly authorized and managed within organizational security policies.