Malware

Ulise.105648 malicious file

Malware Removal

The Ulise.105648 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.105648 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ulise.105648?


File Info:

name: 3320CAF8A501C87537E4.mlw
path: /opt/CAPEv2/storage/binaries/3082c49b1617288add5e9872bfe0fb2972e1efa0fa785730b20567d243e41bfc
crc32: CB3BC987
md5: 3320caf8a501c87537e48f49bcfc1f47
sha1: 1f0d751e6f0f59ef94ba07475e535daf04feee28
sha256: 3082c49b1617288add5e9872bfe0fb2972e1efa0fa785730b20567d243e41bfc
sha512: 893ef4d93977548623d48798f40bc8cd71cee3332f640c58be75165eaeda64887a83765556ce4352f662668ce1373e8bb80c399bc63ae8860d48fff3c366355d
ssdeep: 12288:4bomTnDljOM5mmiHIffHqxzeAucP+9vGbnrbbWBGS2lcp9s4oDMUE8888888888B:HOnZh5mY3HqxqB9MeBGS2lcp9x9Umt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D1F43912A3911C3BC06F1635496B85E4AC377AD12AD678D66FF4C93C0F392B12C3E696
sha3_384: ae8f66f78500bbda92f3a35aecfc269ea0bd8b7b1e9bf1793ceaa70990343c67e0d9a53965e31e314a4bc3aa896fc61f
ep_bytes: 558bec83c4f0b8ac204a00e81c2cf6ff
timestamp: 2011-03-09 08:33:51

Version Info:

CompanyName:
FileDescription: 282112
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

Ulise.105648 also known as:

BkavW32.FamVT.Delf.Trojan
LionicTrojan.Win32.Delf.lQdB
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ulise.105648
FireEyeGeneric.mg.3320caf8a501c875
CAT-QuickHealTrojanDownloader.Delf.NK12
SkyhighGenDownloader.nz
ALYacGen:Variant.Ulise.105648
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Ulise.105648
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderGen:Variant.Ulise.105648
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.e6f0f5
BitDefenderThetaGen:NN.ZelphiF.36792.VW1@aSK7drpj
VirITTrojan.Win32.Generic.TPM
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.QEW
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.120027-1
KasperskyTrojan-Downloader.Win32.Delf.aznp
AlibabaTrojanDownloader:Win32/GenDownloader.b468cdec
NANO-AntivirusTrojan.Win32.Delf.crlibp
ViRobotTrojan.Win32.A.Downloader.282567
RisingTrojan.DL.Win32.Undef.tic (CLASSIC)
SophosMal/Generic-S
BaiduWin32.Trojan-Downloader.Agent.af
F-SecureTrojan.TR/Crypt.ASPM.Gen
DrWebTrojan.DownLoader4.5793
TrendMicroTROJ_AGENT_002427.TOMB
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Ulise.105648 (B)
IkarusTrojan-Dropper.Delf
JiangminTrojanDownloader.Delf.abkc
WebrootW32.Trojan.Downloader.Delf
VaristW32/AdLoad.L.gen!Eldorado
AviraTR/Crypt.ASPM.Gen
Antiy-AVLTrojan[Downloader]/Win32.Delf.gic
KingsoftWin32.Troj.Undef.a
MicrosoftTrojanDownloader:Win32/Adload.CI
XcitiumTrojWare.Win32.TrojanDownloader.Delf.qew@2nivix
ArcabitTrojan.Ulise.D19CB0
ZoneAlarmTrojan-Downloader.Win32.Delf.aznp
GDataGen:Variant.Ulise.105648
GoogleDetected
AhnLab-V3Downloader/Win32.Delf.R9035
McAfeeGenDownloader.nz
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
VBA32TrojanDownloader.Delf
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGENT_002427.TOMB
TencentMalware.Win32.Gencirc.10b11beb
YandexTrojan.GenAsa!mN6RV9+IomM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Delf.AZNP
FortinetW32/Delf.QEW!tr.dldr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ulise.105648?

Ulise.105648 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment