Malware

Ursu.137224 (file analysis)

Malware Removal

The Ursu.137224 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.137224 virus can do?

  • Performs some HTTP requests
  • Looks up the external IP address
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.ipify.org

How to determine Ursu.137224?


File Info:

crc32: 1CDC225C
md5: 5f90abc08e8ac8bc289e90756ad294fc
name: 5F90ABC08E8AC8BC289E90756AD294FC.mlw
sha1: ede4ef035b443fa3a92358ee7699b104ef65a957
sha256: 69fe88a6235d1852749c0d0c3b045db54719fed888ab2e465365f8e2e267c5dc
sha512: 77fb5b2dc836c69d7b6082a17c2473ae2fa9cde34e8924017eb2dc2886d3ab197f6b5822da52ed584916186b8455afdc2f74440be484dd0648ca9717c68bde1c
ssdeep: 48:C4u/reQW29P6lBHE1FPmIV2Q7N2PHNFTDpvnhCvec1noomKgzI8R8RuqS6T:5KreN29P6rGPot3v7K6I8Rcxj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.137224 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0052b1071 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Ladon
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.7281
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 0052b1071 )
Cybereasonmalicious.08e8ac
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.NPX
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Ursu.137224
NANO-AntivirusTrojan.Win32.FileCoder.ezdsuo
MicroWorld-eScanGen:Variant.Ursu.137224
TencentWin32.Trojan.Filecoder.Szvk
Ad-AwareGen:Variant.Ursu.137224
SophosMal/Generic-R + Troj/Ladon-A
ComodoMalware@#1gvecishmtwp3
BitDefenderThetaGen:NN.ZexaF.34686.auW@a8oCgJdi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_LADON.DAM
McAfee-GW-EditionBehavesLike.Win32.Generic.zt
FireEyeGeneric.mg.5f90abc08e8ac8bc
EmsisoftGen:Variant.Ursu.137224 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/FileCoder.rssfn
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Ursu.137224
AhnLab-V3Malware/Win32.Ransom_ladon.C2482614
McAfeeArtemis!5F90ABC08E8A
MAXmalware (ai score=95)
VBA32suspected of Trojan.Downloader.gen
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_LADON.DAM
RisingMalware.Undefined!8.C (CLOUD)
YandexTrojan.Filecoder!6K8AQ+p76+U
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Filecoder.NPX!dam
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.137224?

Ursu.137224 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment