Trojan

Trojan:Win32/Ursnif.BE!MTB (file analysis)

Malware Removal

The Trojan:Win32/Ursnif.BE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ursnif.BE!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Crashed cuckoomon during analysis. Report this error to the Github repo.

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Ursnif.BE!MTB?


File Info:

crc32: 1EC34B8D
md5: 321062596bf2443ae24092fd48af3316
name: 321062596BF2443AE24092FD48AF3316.mlw
sha1: 89f977a790335584f0fd4f8fd658487366d96215
sha256: e45ac0fe3519f58cd7402a8841f3c5ae351fb3305d0444b7a8e50893eded5209
sha512: e08808e61f2af60f1906b567e6ef3f22ed3e9a36f5a9dc43156c07ced99d18b455650bb84b29bd968d1c06812e9a35db68bfee8d53acc61da2200d365e67a34b
ssdeep: 6144:QfsvEug4/COMAIOVW3Uqz/HJpadR5FztgF:QKEufaORxezE5Fz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2004-2011, Motionsoft segment Equatechord must sense
InternalName: Stretchbrown
FileVersion: 13.7.69.65
LegalTrademarks: Stretchbrown shouldface hat
ProductName: Stretchbrown
ProductVersion: 13.7.69.65
FileDescription: Stretchbrown
OriginalFilename: Donelevel.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Ursnif.BE!MTB also known as:

BkavW32.FamVT.RazyNHmA.Trojan
LionicTrojan.Win32.Ursnif.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Poison.19083
ClamAVWin.Malware.Dpbx-6853623-0
ALYacTrojan.Agent.DPBX
CylanceUnsafe
ZillyaTrojan.Ursnif.Win32.6748
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Ursnif.5d4a33e8
K7GWTrojan ( 005473e11 )
K7AntiVirusTrojan ( 005473e11 )
CyrenW32/S-adb7f341!Eldorado
SymantecTrojan.Ursnif
ESET-NOD32a variant of Win32/Kryptik.GPMV
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Ursnif.agqi
BitDefenderTrojan.Agent.DPBX
NANO-AntivirusTrojan.Win32.Poison.fmrmom
MicroWorld-eScanTrojan.Agent.DPBX
TencentMalware.Win32.Gencirc.10b1f0f5
Ad-AwareTrojan.Agent.DPBX
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanSpy.Ursnif.GP@81wf2z
BitDefenderThetaGen:NN.ZexaF.34236.xq0@aqOoovei
VIPRETrojan.Win32.Zbot.ata (v)
McAfee-GW-EditionBehavesLike.Win32.Ursnif.fm
FireEyeGeneric.mg.321062596bf2443a
EmsisoftTrojan.Agent.DPBX (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Ursnif.cbx
AviraHEUR/AGEN.1114562
eGambitUnsafe.AI_Score_81%
Antiy-AVLTrojan/Generic.ASMalwS.2A7D816
MicrosoftTrojan:Win32/Ursnif.BE!MTB
ArcabitTrojan.Agent.DPBX
GDataTrojan.Agent.DPBX
TACHYONTrojan-Spy/W32.Ursnif.380928.B
AhnLab-V3Malware/Gen.Generic.C3002208
Acronissuspicious
McAfeeUrsnif-FQIR!321062596BF2
MAXmalware (ai score=100)
VBA32TrojanSpy.Ursnif
MalwarebytesTrojan.Downloader
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.100 (RDML:VBaI4QZH9R6uDpofdoSe0A)
YandexTrojanSpy.Ursnif!ILRRXS0sEfE
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.74119004.susgen
FortinetW32/Kryptik.GPMV!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/Ursnif.BE!MTB?

Trojan:Win32/Ursnif.BE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment