Malware

Win32/Agent.ULF (file analysis)

Malware Removal

The Win32/Agent.ULF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.ULF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Expresses interest in specific running processes
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/Agent.ULF?


File Info:

name: EFD1209D70C9775C0089.mlw
path: /opt/CAPEv2/storage/binaries/5a3d0e5655708b135e3538b33bc4a181e6e66fa78700bed8e291ee6ea03084d6
crc32: 9C80EC32
md5: efd1209d70c9775c00895ed395c30024
sha1: dc199d6b6fa8a93e8f2eb772544371a7fd9cbd4b
sha256: 5a3d0e5655708b135e3538b33bc4a181e6e66fa78700bed8e291ee6ea03084d6
sha512: 1ee22451ea9795d25b206e4bbb68971f529fe62a151f54ecd468f432d229454fe31e4d16a0dec34235816a21b0cd4a2750a32142b04c50d7675d210a704c6d2d
ssdeep: 1536:hKIxWVRn5Bczsl4qN0ba/IgrmR/+wJqKDXGrSylpXN/E/xWWdOTMhFdNzUbbujdz:hK2zgxN0baVr0SKrGGylD89dPvOwJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T189A3F1E2F9AE6D50C15055BCA04FBF38A050C636945EB242D7FE8B47C9F8F110B4A96A
sha3_384: 67aa005e332803cab4eee28fbee21e4977b72720e8b063c4a7608b8421a2e47bbac5307fa661bd13389b7c2589b78944
ep_bytes: 60be0030ae008dbe00e091ff5783cdff
timestamp: 2022-01-06 03:37:47

Version Info:

0: [No Data]

Win32/Agent.ULF also known as:

LionicTrojan.Win32.Eb.4!c
DrWebTrojan.PWS.Spy.21553
MicroWorld-eScanTrojan.GenericKD.48245679
FireEyeGeneric.mg.efd1209d70c9775c
CAT-QuickHealTrojan.AgentRI.S26141477
McAfeeRDN/Generic PWS.y
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005715eb1 )
AlibabaTrojan:Win32/ATRAPS.ed493d7e
K7GWTrojan ( 005715eb1 )
Cybereasonmalicious.d70c97
BitDefenderThetaAI:Packer.12FADF241F
CyrenW32/Trojan.VZOV-1500
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ULF
TrendMicro-HouseCallTROJ_GEN.R06CC0WAJ22
Paloaltogeneric.ml
KasperskyTrojan.Win32.Eb.dan
BitDefenderTrojan.GenericKD.48245679
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Heur.Apwj
Ad-AwareTrojan.GenericKD.48245679
EmsisoftTrojan.GenericKD.48245679 (B)
ComodoMalware@#1p41yvbhbp75f
ZillyaTrojan.Agent.Win32.2661058
TrendMicroTROJ_GEN.R06CC0WAJ22
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.48245679
AviraTR/ATRAPS.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.350E3F2
KingsoftWin32.Troj.Eb.d.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4348158
VBA32BScope.Trojan.Eb
MalwarebytesTrojan.MalPack.UPX
APEXMalicious
RisingTrojan.EB!8.10DCC (CLOUD)
YandexTrojan.Agent!X7psaJgiWiM
IkarusTrojan.Win32.Agent
FortinetW32/Agent.ULF!tr
WebrootW32.Trojan.Gen
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Agent.ULF?

Win32/Agent.ULF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment