Malware

What is “Ulise.116927”?

Malware Removal

The Ulise.116927 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.116927 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Ulise.116927?


File Info:

name: 10271FEF667560F24767.mlw
path: /opt/CAPEv2/storage/binaries/e02c5bbde1802f125fda496bf8c5e9be9a2ce7032dec9fe2650d8ff79ad1fb93
crc32: CEBB8DA5
md5: 10271fef667560f247670a3eca1e8ba4
sha1: 0ceeb718f8d6640a45122e50d6e461c1d6d91391
sha256: e02c5bbde1802f125fda496bf8c5e9be9a2ce7032dec9fe2650d8ff79ad1fb93
sha512: 174a71d7d83409103a2d57fa4feba6128e1b50651f166e6d779d3a247f8a2c09a27c315f93e9e5395612ffb5192ccb650a5c1a88eabf082607fd0843396c4ae2
ssdeep: 49152:gO+Y19oo64ylo1Kdsj0qyKolOTfqwWjXCnP2pOGxoSmvNq7pa++m5niw/0iXOrUH:tF1KEasjHyHlwWjXCnP29jda++iOISO/
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1D5D5336291CC2835DA5FE977546B6EAC01B87F8EE4B22F5C38CFB61841BB2494154F13
sha3_384: e398734c3e5d1c1f182d49a9f142bfc40bc3d7bcbfd2403f5240e4c84a8200abdc662b6f60963a4c0e40eb7770311411
ep_bytes: 57565351524150488d05de0a0000488b
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: Oracle Corporation
FileDescription: Java Platform SE binary
FileVersion: 8.0.2610.12
Full Version: 1.8.0_261-b12
InternalName: Setup Launcher
LegalCopyright: Copyright © 2020
OriginalFilename: online_wrapper-cab.exe
ProductName: Java Platform SE 8 U261
ProductVersion: 8.0.2610.12
Translation: 0x0409 0x04b0

Ulise.116927 also known as:

LionicTrojan.Win32.Cerbu.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.116927
FireEyeGeneric.mg.10271fef667560f2
ALYacGen:Variant.Ulise.116927
CylanceUnsafe
K7AntiVirusTrojan ( 0055a26a1 )
AlibabaTrojan:Win64/CoinMiner.72692858
K7GWTrojan ( 0055a26a1 )
CyrenW64/S-659f3d67!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/CoinMiner.TK
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Ulise.116927
AvastWin64:Trojan-gen
TencentWin32.Trojan.Cerbu.Dtsp
Ad-AwareGen:Variant.Ulise.116927
EmsisoftGen:Variant.Ulise.116927 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win64.Generic.vc
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1207620
Antiy-AVLTrojan/Win64.CoinMiner
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Ulise.116927
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Agent.C4193120
McAfeeArtemis!10271FEF6675
MAXmalware (ai score=85)
YandexTrojan.CoinMiner!hxDk8eShBjQ
IkarusTrojan.Win64.CoinMiner
MaxSecureTrojan.Malware.106084378.susgen
FortinetW64/CoinMiner.ACR!tr
AVGWin64:Trojan-gen
Cybereasonmalicious.f66756

How to remove Ulise.116927?

Ulise.116927 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment