Malware

About “Ursu.454433 (B)” infection

Malware Removal

The Ursu.454433 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.454433 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Ursu.454433 (B)?


File Info:

name: 690F8C782C81E3CBEBBD.mlw
path: /opt/CAPEv2/storage/binaries/01f3abdbe628a8dfe6d148c46b85cd64c7251b6f7cac0bf54a9f319cc72cadf2
crc32: BA18DB8D
md5: 690f8c782c81e3cbebbd0899782cd52e
sha1: 7f59476988c95589fcf64b98ed0b342bba9976b8
sha256: 01f3abdbe628a8dfe6d148c46b85cd64c7251b6f7cac0bf54a9f319cc72cadf2
sha512: a489c14663e0294fe67e92a4af3a6dfdc8a68db541f8b12d77b110987bc1386f2ca56782dfb67ad0984413086d632e22d141249e1a6dbf0d12fb3e4e0ae1c56f
ssdeep: 3072:oVw0Qbak3QrVJ5L9pEiFZtw/xx9j1Vap/tfxHs:nakaiWi/xx9j1MVp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100E326352396051CCC6C497305DAC3E206B5E685233B9BDB2B1936784CB237EB9796CB
sha3_384: 35de6baac1daa22b13174095ffa6d6a1b12ab20d905639495f51dd1e27b616334ef51ffe5e118bf18bc10d6c9164319b
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-07-14 22:14:46

Version Info:

Translation: 0x0000 0x04b0
Comments: Windows Task Manager
CompanyName: Microsoft Corporation
FileDescription: Windows Task Manager
FileVersion: 6.1.7601.17514
InternalName: Windows Task Manager.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
LegalTrademarks:
OriginalFilename: Windows Task Manager.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7601.17514
Assembly Version: 6.1.7601.17514

Ursu.454433 (B) also known as:

BkavW32.AIDetectNet.01
DrWebBackDoor.Bladabindi.13678
MicroWorld-eScanGen:Variant.Ursu.454433
FireEyeGeneric.mg.690f8c782c81e3cb
ALYacGen:Variant.Ursu.454433
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055408e1 )
K7GWTrojan ( 0055408e1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.34786.jq0@aaFmEym
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.SJV
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Variant.Ursu.454433
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Ursu.454433
EmsisoftGen:Variant.Ursu.454433 (B)
VIPREGen:Variant.Ursu.454433
McAfee-GW-EditionGenericRXKL-MD!690F8C782C81
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
GDataGen:Variant.Ursu.454433
AviraTR/Dropper.Gen
ZoneAlarmHEUR:Backdoor.MSIL.Bladabindi.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGenericRXKL-MD!690F8C782C81
MAXmalware (ai score=84)
APEXMalicious
RisingBackdoor.Bladabindi!8.B1F (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetPossibleThreat
AVGWin32:Trojan-gen
Cybereasonmalicious.82c81e

How to remove Ursu.454433 (B)?

Ursu.454433 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment