Malware

Ursu.877707 (file analysis)

Malware Removal

The Ursu.877707 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.877707 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to modify browser security settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

api.shatangmu.cn
config.shatangmu.cn
con2.shatangmu.cn
pv.sohu.com
ip.ws.126.net
info.shatangmu.cn
media.shatangmu.cn
cd002.www.duba.net
2398.35go.net
infoc0.duba.net
pm.myapp.com

How to determine Ursu.877707?


File Info:

crc32: FD16E583
md5: 27af6aaac737a67fa4eb0b58e1c95340
name: explorersetup-4830.exe
sha1: e2bd43481eef5e259ad52c0c34c4bb33cf6af44b
sha256: 94842bdc96a5bf257c222d0d4c3dedf84b6d9ebf44ca87ee3808c8cf7340dc62
sha512: e7900c09a60761b31acc006b3aaa92261d88d606b69f68adcc3f1db7b418cf2ee9cb2b66d2daeef1272c504c164570dc815eb497319e8f7c42ffc01905c4316b
ssdeep: 49152:gXKgbSUIxUCG4LNcDYH8Grkl5Dm8E0j3nRkISyF1dYqLuCZJkU4jrsgXI:4JcUQLUGrupm8EC3RkHqqEh4jhI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 1.0.0.1
CompanyName: Explorer++
Comments: Explorer++
ProductName: Setup Pack
ProductVersion: 1.0.0.1
FileDescription: x5b89x88c5x7a0bx5e8f
OriginalFilename: suf_launch.exe
Translation: 0x0409 0x0000

Ursu.877707 also known as:

MicroWorld-eScanGen:Variant.Ursu.877707
FireEyeGen:Variant.Ursu.877707
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 005624d41 )
BitDefenderGen:Variant.Ursu.877707
K7GWTrojan-Downloader ( 005624d41 )
Cybereasonmalicious.ac737a
AvastWin32:Trojan-gen
ClamAVWin.Malware.Generic-7589901-0
GDataGen:Variant.Ursu.877707
KasperskyHEUR:Trojan-Downloader.Win32.Chindo.vho
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ursu.877707 (B)
F-SecureHeuristic.HEUR/AGEN.1107653
DrWebTrojan.DownLoader33.44104
ZillyaDownloader.Chindo.Win32.1251
McAfee-GW-EditionArtemis!Trojan
IkarusTrojan.Indiloadz
JiangminAdWare.StartSurf.cirb
AviraExplorer++.exe
MAXmalware (ai score=88)
ArcabitTrojan.Ursu.DD648B
ZoneAlarmHEUR:Trojan-Downloader.Win32.Chindo.vho
VBA32BScope.Trojan.Ekstak
ALYacGen:Variant.Ursu.877707
Ad-AwareGen:Variant.Ursu.877707
ESET-NOD32a variant of Win32/TrojanDownloader.Chindo.AG
RisingAdware.Agent!1.C221 (RDMK:cmRtazqhOJEsgYkmi9nH15JiCMkS)
FortinetW32/Ursu.789031!tr
AVGWin32:Trojan-gen

How to remove Ursu.877707?

Ursu.877707 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment