Malware

Ursu.387721 (file analysis)

Malware Removal

The Ursu.387721 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.387721 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.387721?


File Info:

crc32: 021F52EB
md5: 21320e6272c5c2b4e7a388cb88fcf8c6
name: 21320E6272C5C2B4E7A388CB88FCF8C6.mlw
sha1: 079ed35b963931cf2518348865969ffb1424adaf
sha256: e397b7afb75f96424c7ca785d44a5a506298dc1474ff1b275517c19ae5f2c9b0
sha512: 19718265687ed0b362a5507e091213bfdccef36a631c911fcab9d30a5f9472da16f60d6b3d5a6b6baa8e0c7b92767ab8b38d836b02c8debeebe43fe78931bfb0
ssdeep: 192:I7BEMf/GhpmaK1gMTDkxrj64VNE50rd9e:ymSv4dj64V6qd9
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: payload20.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: payload20.exe

Ursu.387721 also known as:

Elasticmalicious (high confidence)
DrWebExploit.ShellCode.46
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.387721
CylanceUnsafe
ZillyaTrojan.Shelma.Win32.2524
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/GenKryptik.29d7371e
Cybereasonmalicious.272c5c
CyrenW32/Razy.EL.gen!Eldorado
SymantecMeterpreter
ESET-NOD32a variant of MSIL/GenKryptik.DAXJ
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Shelma.gen
BitDefenderGen:Variant.Ursu.387721
MicroWorld-eScanGen:Variant.Ursu.387721
Ad-AwareGen:Variant.Ursu.387721
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34744.am0@aaYTii
TrendMicroTROJ_GEN.R005C0WFE21
McAfee-GW-EditionBehavesLike.Win32.Trojan.zt
FireEyeGeneric.mg.21320e6272c5c2b4
EmsisoftGen:Variant.Ursu.387721 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1107327
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Ursu.387721
AhnLab-V3Trojan/Win32.Kryptik.C3076693
McAfeeArtemis!21320E6272C5
MAXmalware (ai score=84)
MalwarebytesTrojan.Crypt.MSIL
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R005C0WFE21
IkarusTrojan.Shelma
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.DAXJ!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Ursu.387721?

Ursu.387721 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment