Malware

About “Ursu.20240” infection

Malware Removal

The Ursu.20240 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.20240 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io

How to determine Ursu.20240?


File Info:

crc32: A341180F
md5: a3d08b7596c4740a2c132e110a31135d
name: A3D08B7596C4740A2C132E110A31135D.mlw
sha1: 47ccad6f10566a168447ff7d6131a02ee39e5ccf
sha256: 9fb31b0b820db197321f3fdedc0f5339c4197b96aabb61079af7f8044c9a845a
sha512: 62c7f6e3a48eeb638634449773f718fd9234114cb93ae9d9064280f8b1ed957761d2409eff24488b5cafe7b0524520571208ed92dd65894afd48e1d7a1bba2a8
ssdeep: 3072:512d9WaiUCRChHgaMNyLXLOovMEAvKXqsxlEZwEdb3Pk5y:51dai1RChHglCCoUxvKRGdz85
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Durries Invecked
InternalName: sulphine
FileVersion: 10.8.0.0
CompanyName: Durries Invecked
ProductName: sulphine redoublements
ProductVersion: 10.8.0.0
FileDescription: sulphine precondensed
OriginalFilename: sulphine.exe
Translation: 0x0409 0x04b0

Ursu.20240 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051c8bc1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.20240
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Zerber.d321571f
K7GWTrojan ( 0051c8bc1 )
Cybereasonmalicious.596c47
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.EYLT
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Zerber.feyv
BitDefenderGen:Variant.Ursu.20240
NANO-AntivirusTrojan.Win32.Zerber.evebcv
MicroWorld-eScanGen:Variant.Ursu.20240
TencentWin32.Trojan.Zerber.Lnns
Ad-AwareGen:Variant.Ursu.20240
SophosML/PE-A + Mal/Cerber-C
ComodoMalware@#14o2b2a98bru2
BitDefenderThetaGen:NN.ZexaF.34142.ku0@a8fg2Oni
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-Cerber.a!
FireEyeGeneric.mg.a3d08b7596c4740a
EmsisoftGen:Variant.Ursu.20240 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.emk
AviraHEUR/AGEN.1121409
eGambitUnsafe.AI_Score_59%
Antiy-AVLTrojan/Generic.ASMalwS.22B9184
MicrosoftRansom:Win32/Cerber.A
ArcabitTrojan.Ursu.D4F10
GDataGen:Variant.Ursu.20240
AhnLab-V3Trojan/Win32.Zerber.C2367058
McAfeeRansomware-Cerber.a!
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Zerber
PandaGeneric Suspicious
RisingTrojan.Generic@ML.97 (RDML:Ku8iVXgC4zORQvgeJNvleg)
YandexTrojan.Zerber!0fzSKNisKCg
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.EYKI!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ursu.20240?

Ursu.20240 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment