Malware

Ursu.773421 information

Malware Removal

The Ursu.773421 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.773421 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Malayalam
  • The binary likely contains encrypted or compressed data.
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to modify desktop wallpaper
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Formbook malware family
  • Attempts to masquerade or mimic a legitimate process or file name
  • Uses suspicious command line tools or Windows utilities

How to determine Ursu.773421?


File Info:

name: 23CF51E8403001066169.mlw
path: /opt/CAPEv2/storage/binaries/c1c3399ed911782ec14180a857a48231f7e3182dd9340ed6308b9a70cacc2885
crc32: C8D12BA8
md5: 23cf51e84030010661697e3f76745934
sha1: b9add2c09dbfabcd1948483567635151cc92d321
sha256: c1c3399ed911782ec14180a857a48231f7e3182dd9340ed6308b9a70cacc2885
sha512: 7bd74e41dde490bcf8314030722aea043a514a275048b5885d7a52836c18ad53bd1fc0c2f5e516ec11cebb7a2db566f13b16624a84feed426f87c34485ce1605
ssdeep: 6144:SUCzChaE/Em7DggLs3thfOsOp4CbVbyvhCJ:vKChT/n7DgqUVODbVby5C
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14574020DBBDCE625C9BE13B259D205440923896B9A37F74B6D8C60B4DF723C689E131B
sha3_384: 76ef33b0cba56ed95fcf5ac0e71a70d88c3941767e4a1262d455de32e7870e82557a887170f5573095ce0bbbe01e3368
ep_bytes: ff250020400000000000
timestamp: 2019-06-23 08:55:34

Version Info:

Comments:
FileVersion: 1.0.0.54
ProductVersion: 1.0.0.54
CompanyName:
LegalCopyright:
ProductName: Netopsystems Size Optimizer(R)
Translation: 0x0000 0x04b0

Ursu.773421 also known as:

LionicTrojan.MSIL.Noon.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.773421
ALYacSpyware.Noon.gen
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1951583
SangforTrojan.MSIL.Noon.gen
K7AntiVirusTrojan ( 0055340c1 )
AlibabaTrojanSpy:MSIL/NanoCore.b371f64a
K7GWTrojan ( 0055340c1 )
Cybereasonmalicious.840300
CyrenW32/Trojan.SZJR-0297
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.SHS
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderGen:Variant.Ursu.773421
NANO-AntivirusTrojan.Win32.Noon.hjhbwe
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Ursu.773421
SophosMal/Generic-R + Mal/MSIL-UC
ComodoMalware@#2n2ccwvalpuj3
DrWebTrojan.Siggen9.15284
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.23cf51e840300106
EmsisoftGen:Variant.Ursu.773421 (B)
IkarusTrojan.MSIL.SmartAssembly
GDataGen:Variant.Ursu.773421
JiangminTrojanSpy.MSIL.anhb
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.3243012
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Ursu.DBCD2D
MicrosoftTrojan:MSIL/NanoCore.VN!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4084435
McAfeeGenericRXIH-IE!23CF51E84030
VBA32TScope.Trojan.MSIL
MalwarebytesMachineLearning/Anomalous.95%
TencentMsil.Trojan-spy.Noon.Hrpn
YandexTrojan.Kryptik!CfQTxKgi4TY
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/CoinMiner.SHS!tr
BitDefenderThetaGen:NN.ZemsilF.34294.um3@aStm9lcG
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.73691310.susgen

How to remove Ursu.773421?

Ursu.773421 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment