Malware

Ursu.955172 (file analysis)

Malware Removal

The Ursu.955172 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.955172 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Network activity contains more than one unique useragent.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ursu.955172?


File Info:

crc32: A5F12730
md5: f212f05dc8c50690d1d920ea07eb53bc
name: 5199hs.exe
sha1: acd95d70ce996db529dff2abf8ce6e17584607cc
sha256: 1f5fd2946d888200ed09e0aa0333de0794228834c8941492177fc17c01f8bf54
sha512: 92285b9329c9aafaef41d2ea1b7a699c0ba68217b9aae073b8c95539c1b00fdd3b0de3b6d6fdd330dc96a794a02842d52c2d7ed7b074392b8f3fd9c6d5940585
ssdeep: 1536:8APnAG0ompO5xc7pVfa6a7W1KOnZLSwQA7Hdx:HPTrmpKsVraHOZb
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ursu.955172 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Ursu.955172
CylanceUnsafe
BitDefenderGen:Variant.Ursu.955172
BitDefenderThetaAI:Packer.20B11C271F
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Ursu.955172
Ad-AwareGen:Variant.Ursu.955172
Trapminesuspicious.low.ml.score
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Wacatac.C!ml
VBA32Trojan.Cometer
ALYacGen:Variant.Ursu.955172
MAXmalware (ai score=83)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FGI
eGambitUnsafe.AI_Score_83%
AVGWin32:Malware-gen
PandaTrj/GdSda.A
Qihoo-360HEUR/QVM20.1.BBD4.Malware.Gen

How to remove Ursu.955172?

Ursu.955172 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment