Malware

Ulise.408400 information

Malware Removal

The Ulise.408400 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ulise.408400 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Ulise.408400?


File Info:

name: 1F6DDF7FB453CFCA5AFB.mlw
path: /opt/CAPEv2/storage/binaries/cf44ad569be3c113ad3c2f5959128ebf8465e66693f7a777729ce99b027af8bb
crc32: C76ECE47
md5: 1f6ddf7fb453cfca5afb764d4fde324d
sha1: d0d45d0ae917660b31e925cc743145cfd50b6da1
sha256: cf44ad569be3c113ad3c2f5959128ebf8465e66693f7a777729ce99b027af8bb
sha512: d96d931118a0f46685be358f2060ae7ca46667bcffd1fd0abd296bb6af608d51fb96f85194925d81b273d9279f5b60aed702588938a6d5add789e737d0ba26c3
ssdeep: 1536:X+zUtBIBU+28vQBeOGtrYS3srx93UBWfwC6Ggnouy8:XahOmTsF93UYfwC6GIout
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123F39D62E12158E5E06F2AB62BB1173E68344372A8B45F5BCFD8CCF16D62531C79B41C
sha3_384: d36f0c5dd0b199c76c5a4785494f8aa4245246f82ee5970f4e6e2977c49e91ffcdadaa6a1b60f9bacc0c62d0e9598aff
ep_bytes: c20400558bec81ec10000000ff7508e8
timestamp: 2015-01-27 03:56:27

Version Info:

0: [No Data]

Ulise.408400 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.408400
ClamAVWin.Malware.Dinwod-9828955-0
FireEyeGeneric.mg.1f6ddf7fb453cfca
SkyhighBehavesLike.Win32.Generic.ct
McAfeeGenericRXVT-WP!1F6DDF7FB453
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Ulise.408400
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.ae9176
ArcabitTrojan.Ulise.D63B50
BitDefenderThetaGen:NN.ZexaF.36680.jmZ@ai7j24o
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent_AGen.ANK
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Exploit.Win32.ShellCode.vho
BitDefenderGen:Variant.Ulise.408400
NANO-AntivirusTrojan.Win32.Banker.icmelu
AvastWin32:Injector-CVE [Trj]
TACHYONTrojan/W32.Agent.159744.CJQ
SophosML/PE-A
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.Inject2.4876
EmsisoftGen:Variant.Ulise.408400 (B)
IkarusTrojan.Crypt
GoogleDetected
AviraTR/Crypt.ULPM.Gen
Antiy-AVLGrayWare/Win32.Dinwod.acqn
Kingsoftmalware.kb.b.943
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Exploit.Win32.ShellCode.vho
GDataGen:Variant.Ulise.408400
VaristW32/Kryptik.DTU.gen!Eldorado
ALYacGen:Variant.Ulise.408400
MAXmalware (ai score=81)
Cylanceunsafe
RisingTrojan.Grandoreiro!8.1174E (C64:YzY0OqfEv1HHWAHy)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.204901891.susgen
AVGWin32:Injector-CVE [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ulise.408400?

Ulise.408400 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment