Malware

About “Ursu.774702” infection

Malware Removal

The Ursu.774702 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.774702 virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Ursu.774702?


File Info:

name: B8052C167039D00D7082.mlw
path: /opt/CAPEv2/storage/binaries/f23fdf2677a5ec522eeaa93286e33b8087392c93b1b323f05fa99e751287abeb
crc32: D0347B0F
md5: b8052c167039d00d7082e23446ec0c8f
sha1: ba2ffc652bc6d20ed24a99603d31fe8f74f533f7
sha256: f23fdf2677a5ec522eeaa93286e33b8087392c93b1b323f05fa99e751287abeb
sha512: 05d5060f091c6778a1957930ce19221d7b651e1194467557662358ea68d215e17cfc5e2f2931283d940c865eaf8c71b96293ffb6983fdb002dd7b782f79ea219
ssdeep: 96:p7+vvFduSWe9CyB4TYDaN7C1t7Kwl0f2i0gvXFjzNt:tUFdufeMfTYDaN76t2wli0gtl
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11AE1D814E3E88732EDFB4B35B8F253900774FBA198575A5F6885224A6D327060E62B73
sha3_384: c313deeb4d443fe15a5b1f0269f70e2e8cf48f65b30337d0bdfb1931e2642a4a77f2d612e0f5fbd3b84c586de0489751
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-28 17:52:08

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: DiscordTokenGrabber
FileVersion: 1.0.0.0
InternalName: DiscordTokenGrabber.exe
LegalCopyright: Copyright © 2019
LegalTrademarks:
OriginalFilename: DiscordTokenGrabber.exe
ProductName: DiscordTokenGrabber
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ursu.774702 also known as:

LionicTrojan.Win32.Ursu.4!c
DrWebTrojan.PWS.DiscordNET.5
MicroWorld-eScanGen:Variant.Ursu.774702
FireEyeGen:Variant.Ursu.774702
ALYacGen:Variant.Ursu.774702
ZillyaTrojan.Discord.Win32.6423
K7AntiVirusPassword-Stealer ( 0055d8bc1 )
AlibabaTrojanPSW:MSIL/Disco.7f995b4b
K7GWPassword-Stealer ( 0055d8bc1 )
Cybereasonmalicious.67039d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.Discord.CV
TrendMicro-HouseCallTROJ_GEN.R002C0RL221
KasperskyHEUR:Trojan-PSW.MSIL.Disco.gen
BitDefenderGen:Variant.Ursu.774702
AvastWin32:Trojan-gen
TencentWin32.Trojan.Ursu.Pdlt
Ad-AwareGen:Variant.Ursu.774702
SophosMal/Disteal-O
TrendMicroTROJ_GEN.R002C0RL221
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Ursu.774702 (B)
IkarusTrojan.MSIL.PSW
GDataGen:Variant.Ursu.774702
AviraTR/PSW.Discord.ewerw
ArcabitTrojan.Ursu.DBD22E
ViRobotTrojan.Win32.Z.Ursu.7168.ASB
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.DiscordiaMiner.R331749
McAfeeArtemis!B8052C167039
MAXmalware (ai score=81)
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.DiscordStealer.tok
YandexTrojan.PWS.Discord!uU5v0WQUI2U
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Discord.ED!tr.pws
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Ursu.774702?

Ursu.774702 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment