Malware

Ursu.438502 (file analysis)

Malware Removal

The Ursu.438502 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.438502 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Ursu.438502?


File Info:

name: 230AE82C63A6EBA485AF.mlw
path: /opt/CAPEv2/storage/binaries/e2660cf99707ad49f8e352efd8bb127743d8f5a8e00ad19b7bebc84bd13a9719
crc32: 8FA64E29
md5: 230ae82c63a6eba485afefaa369c254e
sha1: 3738771de227b0a5c7dc956894569eab9a5998c7
sha256: e2660cf99707ad49f8e352efd8bb127743d8f5a8e00ad19b7bebc84bd13a9719
sha512: 5ac0dce4b3cad5dd63be32e4144124a01d23cd3328700c1f37269472d07fb620667530c1d1813c1743ae61cdd0600ce5e967484521247e8104167efe9fef651a
ssdeep: 3072:kTex0tPGDCAJUytrjkDxthjNXBF4BpGUT:kTVGeWvWtDxFCp9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A4C3CE127B42DA32DC050974455286C1EBFF2E833E969C6B9F443E7E6AB03F474796A0
sha3_384: ddd33f89fb22b56a2c7b704f74d6fc1b7dfa62cfa19adcdaafae034a02e1691a19a029af4c726231e0a0fbcab98e63b6
ep_bytes: e853170000e916feffff558bec81ec28
timestamp: 2009-07-07 14:17:33

Version Info:

FileDescription: LKuds cl ssd
FileVersion: 0, 1, 2, 0
InternalName: SSD
LegalCopyright: United States
OriginalFilename: System
ProductName: Windows base
ProductVersion: 0, 0, 0, 0
Translation: 0x0409 0x04b0

Ursu.438502 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.438502
FireEyeGeneric.mg.230ae82c63a6eba4
CAT-QuickHealTrojan.Vundo.Gen
McAfeeVundo-FAYV!230AE82C63A6
CylanceUnsafe
ZillyaTrojan.SpyVoltar.Win32.88
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c63a6e
VirITTrojan.Win32.Generic.ARML
CyrenW32/Zbot.EW.gen!Eldorado
ESET-NOD32Win32/SpyVoltar.A
APEXMalicious
ClamAVWin.Virus.Blocker-751
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.438502
NANO-AntivirusTrojan.Win32.Butirat.bfqthv
SUPERAntiSpywareTrojan.Agent/Gen-Injector
AvastWin32:Injector-CRP [Trj]
TencentMalware.Win32.Gencirc.10b1f5c3
EmsisoftGen:Variant.Ursu.438502 (B)
ComodoTrojWare.Win32.Crypt.BS@7iu3rb
DrWebBackDoor.Butirat.228
VIPRETrojan.Win32.Zbot.kc (v)
TrendMicroTROJ_RANSOM_BL132BDE.TOMC
McAfee-GW-EditionBehavesLike.Win32.Emotet.cc
SophosML/PE-A + Mal/Zbot-KC
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Jorik.fzte
AviraTR/Vundo.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.12FC29
MicrosoftTrojan:Win32/Neconyd.A
ViRobotTrojan.Win32.A.Blocker.126976.AC
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ursu.438502
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Blocker.R50980
BitDefenderThetaGen:NN.ZexaF.34182.hq1@auw3sNli
ALYacGen:Variant.Ursu.438502
MAXmalware (ai score=83)
VBA32Backdoor.Buterat
MalwarebytesMalware.AI.3079724277
TrendMicro-HouseCallTROJ_RANSOM_BL132BDE.TOMC
RisingTrojan.SpyVoltar!1.6564 (RDMK:cmRtazoPHWUABwEL/5Rse+41WxY7)
YandexTrojan.GenAsa!vLNtD3Z2U80
IkarusVirus.Win32.Vundo
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Zbot.KC!tr
AVGWin32:Injector-CRP [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Ursu.438502?

Ursu.438502 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment