Malware

Troj/Urelas-AS (file analysis)

Malware Removal

The Troj/Urelas-AS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Urelas-AS virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Urelas-AS?


File Info:

name: BB7C45A41FA8D59B79DF.mlw
path: /opt/CAPEv2/storage/binaries/2513c7f2a6dace2492bd9dff8f6927023c95f29ec01ad8013a45b10b04bd9fba
crc32: 643AF9ED
md5: bb7c45a41fa8d59b79dfea4136d47c10
sha1: c9df10e65d49d37b8d2d5517de5e640a975d36a1
sha256: 2513c7f2a6dace2492bd9dff8f6927023c95f29ec01ad8013a45b10b04bd9fba
sha512: 399404d113be86543dd72dae8e8413cb515649e2650a0c4367afcde39171ef75d7a221f4e0f2d7374712992c5dd710d146f3f6f7e4c1996cece6d97312c8577f
ssdeep: 1536:C01+VO8LWbp4Zt/kvT2/AWbAoUETLKyUGDeF3eP8UVu065RG0/bpHwk5feKJM:C019Tp4biALbUGc065Q0jpHwUG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8F3D51166008471F3590B315A06FAE049A9AD3D19E8F94FF7787E3A6D322C39A7724F
sha3_384: a6eee831aeec3f41b6917862081c4a6f6a9e44cf04706dff54e82bd4e7ccf3dc25370205acbe8ce7820d2bf043c5c290
ep_bytes: e809520000e979feffff8bff558bec8b
timestamp: 2014-06-06 13:43:54

Version Info:

0: [No Data]

Troj/Urelas-AS also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
FireEyeGeneric.mg.bb7c45a41fa8d59b
SkyhighBehavesLike.Win32.Generic.cm
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Heur.Mint.SP.Urelas.1
SangforVirus.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
BitDefenderGen:Heur.Mint.SP.Urelas.1
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Urelas.a
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Urelas.U
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Urelas-6717394-0
KasperskyBackdoor.Win32.Plite.bhtr
NANO-AntivirusTrojan.Win32.Plite.fhcuxz
TencentTrojan.Win32.Urelas.16000161
SophosTroj/Urelas-AS
F-SecureBackdoor.BDS/Backdoor.Gen7
DrWebBackDoor.Golf.182
ZillyaBackdoor.Plite.Win32.31302
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
IkarusTrojan.Win32.Urelas
JiangminTrojan/GenericCryptor.bt
VaristW32/Trojan.IMS.gen!Eldorado
AviraBDS/Backdoor.Gen7
Antiy-AVLTrojan[Backdoor]/Win32.Plite
Kingsoftmalware.kb.a.992
MicrosoftTrojan:Win32/Urelas!atmnm
XcitiumTrojWare.Win32.Urelas.SH@5674sp
ArcabitTrojan.Mint.SP.Urelas.1
SUPERAntiSpywareTrojan.Agent/Gen-Urelas
ZoneAlarmBackdoor.Win32.Plite.bhtr
GDataWin32.Trojan.PSE.1B8NEZZ
GoogleDetected
AhnLab-V3Backdoor/Win.Generic.R500451
Acronissuspicious
McAfeePWS-FBQQ!BB7C45A41FA8
MAXmalware (ai score=86)
DeepInstinctMALICIOUS
VBA32SScope.Backdoor.Urelas.3114
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Urelas!1.BE13 (CLASSIC)
YandexTrojan.GenAsa!O7ZmhanjR8Q
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Urelas.U!tr
BitDefenderThetaGen:NN.ZexaF.36792.kCX@aeSXhidi
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.65d49d
AvastWin32:BackdoorX-gen [Trj]

How to remove Troj/Urelas-AS?

Troj/Urelas-AS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment