Malware

Ulise.235604 (file analysis)

Malware Removal

The Ulise.235604 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.235604 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

How to determine Ulise.235604?


File Info:

crc32: F4AAFFED
md5: 5b7bc8044919ae6e621a4ac7f0fedbb0
name: 5B7BC8044919AE6E621A4AC7F0FEDBB0.mlw
sha1: 1774b06f8166e56dc5848cd44e574a474c52f7ee
sha256: a371535ca5806532cdb380ec97eac49cf67d8b5cfc596970f66337801d34578b
sha512: 5b0fc29fee7107cc8d0d838ba261ff322aff5a464c9aace2d9d255e9704e21fb7f842d871bb95a13c2dc07b3abec7d368fc622b9e16768fd51671aceb7773b90
ssdeep: 1536:aLZcQenENdbJa4U4E/nJpuHZeH+B2+vlRZxDFNjxcTC0CmuJdr:0ZcznMVjUrJpuHU2H39VBbdr
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ulise.235604 also known as:

K7AntiVirusTrojan ( 0057ffc71 )
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
CynetMalicious (score: 100)
ALYacGen:Variant.Ulise.235604
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Copak.d424491f
K7GWTrojan ( 0057ffc71 )
Cybereasonmalicious.f8166e
CyrenW32/Kryptik.DCC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Copak-9853643-0
KasperskyHEUR:Trojan.Win32.Copak.vho
BitDefenderGen:Variant.Ulise.235604
NANO-AntivirusTrojan.Win32.Agent.ixszcw
MicroWorld-eScanGen:Variant.Ulise.235604
TencentMalware.Win32.Gencirc.10ce582b
Ad-AwareGen:Variant.Ulise.235604
SophosML/PE-A + Troj/Agent-BGZJ
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34236.emY@aqxLbnk
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Worm.kc
FireEyeGen:Variant.Ulise.235604
EmsisoftGen:Variant.Ulise.235604 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.cls
AviraHEUR/AGEN.1142452
Antiy-AVLTrojan/Generic.ASBOL.C686
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataGen:Variant.Ulise.235604
AhnLab-V3Malware/Gen.RL_Reputation.R368413
McAfeeGenericRXNX-YH!5B7BC8044919
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.D238 (CLASSIC)
YandexTrojan.Copak!sq6mYbquF90
IkarusTrojan.Kryptik
MaxSecureVirus.Sality.AA
FortinetW32/Kryptik.HITO!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ulise.235604?

Ulise.235604 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment