Malware

Ulise.101508 malicious file

Malware Removal

The Ulise.101508 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.101508 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ulise.101508?


File Info:

crc32: C66A5CE7
md5: a36e0a2abc20661fa00f087e322cf6bf
name: soja.exe
sha1: 8a8989042e7b733a52f89782c0406fab0a6612d9
sha256: 9442b98bd1bea41607353f5cf4010bf6a9b38537131760dddbd8c2c6e6d3176b
sha512: 6cf6697cd2003f7eaffa1b484dff3e36b879a0123eabe17690cd05d3aa1b375c1a22caecacfa9424ccdc2118e4a853a85f603aec2880e4d3a31518c5c9abe626
ssdeep: 24576:HgLHilXOb6kpGoNE/DwEd6FEqe2MxIXpf+:HGGvYGj/nEFEqi0+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ulise.101508 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Ulise.101508
Qihoo-360HEUR/QVM05.1.89FB.Malware.Gen
McAfeeGenericRXJS-IA!A36E0A2ABC20
CylanceUnsafe
AegisLabTrojan.Win32.Azorult.i!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Ulise.101508
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.42e7b7
BitDefenderThetaGen:NN.ZelphiF.34090.3GW@a0TFLogi
CyrenW32/Trojan.ETQT-6658
TrendMicro-HouseCallTROJ_GEN.R002H0CBR20
Paloaltogeneric.ml
GDataGen:Variant.Ulise.101508
KasperskyHEUR:Trojan-PSW.Win32.Azorult.gen
AlibabaTrojanPSW:Win32/Injector.23aa1e5b
AvastWin32:Trojan-gen
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareGen:Variant.Ulise.101508
SophosMal/Fareit-V
F-SecureTrojan.TR/Injector.bypmx
DrWebTrojan.PWS.Siggen2.44037
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.cc
SentinelOneDFI – Suspicious PE
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a36e0a2abc20661f
EmsisoftGen:Variant.Ulise.101508 (B)
APEXMalicious
F-ProtW32/Kryptik.AST
WebrootW32.Trojan.Gen
AviraTR/Injector.bypmx
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Trojan-PSW.Win32.Azorult.gen
MicrosoftTrojan:Win32/Lokibot.F!MTB
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
MAXmalware (ai score=88)
ESET-NOD32a variant of Win32/Injector.EKTJ
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_100%
FortinetW32/Agent.AJFK!tr
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Ulise.101508?

Ulise.101508 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment