Malware

What is “Ursu.812560”?

Malware Removal

The Ursu.812560 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.812560 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Ursu.812560?


File Info:

name: 060260384DC618935C88.mlw
path: /opt/CAPEv2/storage/binaries/09dff3bcf97c9a3d67c1d61b5e2d64a1d946a11809c647db2fea38a6612e00e5
crc32: 4FF212B6
md5: 060260384dc618935c881b7695ad95d4
sha1: 8a22036290ef02db608ffea71d8a8aa74180bcc1
sha256: 09dff3bcf97c9a3d67c1d61b5e2d64a1d946a11809c647db2fea38a6612e00e5
sha512: 1d3c34193332315c23802e345ce329ae9437a0142380d04fb8f37984744e23d29b287ee8240a4207cd0467454643da2919510a7dacf951cc840f851a8129597b
ssdeep: 6144:AtAwA4W7aD3ZYJEHIUP8yC60uXIMbh0E6piPNM2k:zwRDpYJACBu4MmBpiDk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F24E07A6295ABE5F53D333C08325605D3FB9C15CB2ADB597F90214849F3BCC8A41AB2
sha3_384: 4f7885f34d9edb0b8209dfe3640b5cafbf1c55ba0c0069433aaa5cd9ab8f55c4d37d3320119773f158c317640c2fe9cf
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-04-02 16:04:01

Version Info:

Translation: 0x0000 0x04b0
FileDescription: WindowsApplication4
FileVersion: 1.0.0.0
InternalName: WindowsApplication4.exe
LegalCopyright: Copyright © 2020
OriginalFilename: WindowsApplication4.exe
ProductName: WindowsApplication4
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ursu.812560 also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.812560
FireEyeGeneric.mg.060260384dc61893
McAfeeGenericRXKD-KY!060260384DC6
CylanceUnsafe
ZillyaDownloader.Tiny.Win32.14620
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 004c41161 )
AlibabaBackdoor:MSIL/SpyGate.17216f8c
K7GWTrojan-Downloader ( 004c41161 )
Cybereasonmalicious.84dc61
ArcabitTrojan.Ursu.DC6610
BitDefenderThetaGen:NN.ZemsilF.34232.nq0@a4WUsvh
VirITTrojan.Win32.Dnldr25.BFPM
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Tiny.BB
TrendMicro-HouseCallTROJ_GEN.R002C0PB822
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.SpyGate.gen
BitDefenderGen:Variant.Ursu.812560
NANO-AntivirusTrojan.Win32.SpyGate.hzshwk
AvastWin32:Trojan-gen
TencentMsil.Backdoor.Spygate.Che
Ad-AwareGen:Variant.Ursu.812560
TACHYONBackdoor/W32.DN-SpyGate.218112
EmsisoftGen:Variant.Ursu.812560 (B)
DrWebTrojan.DownLoader25.21358
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PB822
McAfee-GW-EditionGenericRXKD-KY!060260384DC6
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
APEXMalicious
AviraHEUR/AGEN.1204067
Antiy-AVLTrojan/Generic.ASMalwS.3041B88
GridinsoftRansom.Win32.Bladabindi.sa
MicrosoftBackdoor:Win32/Bladabindi!ml
ViRobotTrojan.Win32.Z.Tiny.218112.A
ZoneAlarmHEUR:Backdoor.MSIL.SpyGate.gen
GDataGen:Variant.Ursu.812560
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Bladabindi.C2545855
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Ursu.812560
MAXmalware (ai score=88)
MalwarebytesTrojan.Downloader
RisingTrojan.Generic/MSIL@AI.96 (RDM.MSIL:pqXVoBNdCc7VWihMUsnz0A)
YandexTrojan.DL.Tiny!8azL3/Jofr0
IkarusTrojan-Downloader.MSIL.Tiny
MaxSecureTrojan.Malware.10118638.susgen
FortinetMSIL/Agent.WW!tr.dldr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ursu.812560?

Ursu.812560 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment