Malware

UrsuMDTad.329 (file analysis)

Malware Removal

The UrsuMDTad.329 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UrsuMDTad.329 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine UrsuMDTad.329?


File Info:

crc32: 250F85B5
md5: b616cfb482a7aaae50e87eeda7bbb74c
name: B616CFB482A7AAAE50E87EEDA7BBB74C.mlw
sha1: b45963ce80ad5a6beb64f51f798d4f30e5ef533e
sha256: da908fdcc3b8c19d7a6f960bb2a751bf1e787b2dcccb73dddcfdb073661ddc49
sha512: 766d4b38dc6351bb79f6610e43776227cdda6788547859e5b19af442d77d35fad7cd1d91e080ed3e5484841faa0c51e36cc5224266c39115636dd03967a7047f
ssdeep: 1536:3XLAG1kc/OfnOfGoGhCQ+ZFYMIUrbS2/3qXUl5hFRT:rUcGEGthCQ+rVI6fyXUl5hL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: yI0WJS7OgWVTJ3TARVrZe
Assembly Version: 3.35.3.3
InternalName: zxcz.exe
FileVersion: 3.3.35.35
CompanyName: yI0WJS7OgWVTJ3TA
LegalTrademarks: yI0WJS7OgWVTJ3TARV
Comments: eW8LHGyRYZ2JWETUT
ProductName: yI0WJS7OgWVTJ3TARVr
ProductVersion: 3.3.35.35
FileDescription: eW8LHGyRYZ2JWET
OriginalFilename: zxcz.exe

UrsuMDTad.329 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.UrsuMDTad.329
FireEyeGeneric.mg.b616cfb482a7aaae
ALYacGen:Variant.UrsuMDTad.329
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004f60011 )
BitDefenderGen:Variant.UrsuMDTad.329
K7GWTrojan ( 004f60011 )
Cybereasonmalicious.482a7a
BitDefenderThetaAI:Packer.921063A31F
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kryptik.ali2000016
NANO-AntivirusTrojan.Win32.UrsuMDTad.iheqmb
Ad-AwareGen:Variant.UrsuMDTad.329
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.InjectNET.14
ZillyaTrojan.Generic.Win32.1290299
TrendMicroTROJ_GEN.R014C0WLA20
McAfee-GW-EditionRDN/Generic.grp
EmsisoftGen:Variant.UrsuMDTad.329 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/AgentTesla!ml
ArcabitTrojan.UrsuMDTad.329
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.UrsuMDTad.329
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.C4285866
McAfeeRDN/Generic.grp
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Injector
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Injector.QAJ
TrendMicro-HouseCallTROJ_GEN.R014C0WLA20
TencentWin32.Trojan.Inject.Auto
IkarusTrojan.MSIL.Injector
eGambitUnsafe.AI_Score_99%
FortinetMSIL/QAJ!tr
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/Trojan.fdd

How to remove UrsuMDTad.329?

UrsuMDTad.329 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment