Malware

Ursu.123602 (file analysis)

Malware Removal

The Ursu.123602 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.123602 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.123602?


File Info:

crc32: C6AA167A
md5: 56432042bdae5b3454405cc166dac32c
name: 56432042BDAE5B3454405CC166DAC32C.mlw
sha1: bb765d83ffd4f14489083844a16787d2d819a0b4
sha256: b782f5827c8728175d0bd243414a50b69f2707d5c7902719fd49d189ee2bf986
sha512: 2c3118b1ff4c971c5e6126eb53fdd2239f15047c4b8f7a3dd76b2949f3e0666987d4c289a962dac1b800d36b5feee4ac78e5ec2354fc603f0e55a6b2fcaf06cf
ssdeep: 12288:zv+Prp+04E2I8mWbMozvBZAsDMyRGfth7v/U2udCa4:whmmWt4EMyqL7
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: en.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
LegalTrademarks:
Comments:
ProductName: Class Reborn
ProductVersion: 1.0.0.0
FileDescription: Class Reborn
OriginalFilename: en.exe

Ursu.123602 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.123602
FireEyeGeneric.mg.56432042bdae5b34
CylanceUnsafe
BitDefenderGen:Variant.Ursu.123602
Cybereasonmalicious.2bdae5
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
Ad-AwareGen:Variant.Ursu.123602
EmsisoftGen:Variant.Ursu.123602 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosML/PE-A
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Wacatac.DB!ml
GridinsoftTrojan.Heur!.03032281
ArcabitTrojan.Ursu.D1E2D2
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Ursu.123602
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34688.Fu0@ayyOHy
ALYacGen:Variant.Ursu.123602
MalwarebytesTrojan.Crypt.MSIL
ESET-NOD32a variant of MSIL/GenKryptik.EYLM
YandexTrojan.AvsArher.bUx2VN
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.F13B.Malware.Gen

How to remove Ursu.123602?

Ursu.123602 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment