Threat Database Backdoors Backdoor.Ursu.O

Backdoor.Ursu.O

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 18,435
Threat Level: 60 % (Medium)
Infected Computers: 181
First Seen: February 28, 2022
Last Seen: June 14, 2026
OS(es) Affected: Windows

The detection of Backdoor.Ursu.O on your system indicates a potential security threat that requires immediate attention. This backdoor threat can compromise the security and integrity of your computer, allowing unauthorized access and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Backdoor.Ursu.O?

Backdoor.Ursu.O is a type of malware that creates a secret entrance to your computer, allowing hackers to access and control your system remotely. This backdoor can be used to steal sensitive information, install additional malware, or use your computer as a botnet to launch attacks on other systems. The name Backdoor.Ursu.O suggests that it is a backdoor threat, but the specific characteristics and behavior of this malware are not well-documented.

How Backdoor.Ursu.O Operates

Backdoor.Ursu.O operates by creating a covert communication channel between your computer and a command and control (C2) server controlled by the attackers. This channel allows the attackers to send commands and receive data from your computer, potentially leading to unauthorized access, data theft, and other malicious activities. The backdoor may use various techniques to evade detection, such as encrypting its communication, using legitimate system processes, or hiding in temporary files.

Symptoms of Infection

The symptoms of a Backdoor.Ursu.O infection can be subtle, but they may include unusual system behavior, such as slow performance, unexpected crashes, or unfamiliar programs running in the background. You may also notice suspicious network activity, such as unfamiliar connections or data transfers. In some cases, the backdoor may not exhibit any noticeable symptoms, making it challenging to detect without the aid of security software.

How to Remove Backdoor.Ursu.O

  1. Boot your computer in Safe Mode with Networking to prevent the backdoor from loading and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any related malware.
  3. Uninstall any suspicious programs or applications that may be related to the backdoor.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the backdoor has been completely removed.

Conclusion

Removing Backdoor.Ursu.O requires a combination of technical expertise and caution. It is essential to follow the steps outlined above and to use reputable security software to detect and remove the malware. After removal, it is crucial to take preventive measures to avoid future infections, such as keeping your operating system and software up-to-date, using strong passwords, and being cautious when opening email attachments or clicking on links. By taking these steps, you can help protect your computer and sensitive information from the risks associated with Backdoor.Ursu.O and other malware threats.

Analysis Report

General information

Family Name: Backdoor.Ursu.O
Signature status: Hash Mismatch

Known Samples

MD5: d8affc8e6034d82b4137f7775ae10839
SHA1: 1cfaad75b796f1331937eb61f9ace7957b37b18b
SHA256: 272D12A55A64C48020DB8AD3ACF01D1791DFEC8B85CABA7DDD89EBE3FF13C75F
File Size: 1.58 MB, 1575304 bytes
MD5: bbafc634c81ec06a2bbae7c4fb90f4a7
SHA1: d202c413893db0fc491935dac7cb9726e0e5981a
SHA256: AC0560950FE76493D0F197C33AE8CF9F7BB201BEB0AF0D970B328A0C00C5E87D
File Size: 2.28 MB, 2282040 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Roblox Corporation
File Description Roblox
File Version
  • 1, 6, 0, 5160305
  • 1, 6, 0, 411923
Legal Copyright Copyright © 2020 Roblox Corporation. All rights reserved.
Original Filename Roblox.exe
Product Name Roblox Bootstrapper
Product Version
  • 1, 6, 0, 5160305
  • 1, 6, 0, 411923

Digital Signatures

Signer Root Status
Roblox Corporation DigiCert EV Code Signing CA (SHA2) Hash Mismatch
Roblox Corporation Symantec Class 3 Extended Validation Code Signing CA - G2 Hash Mismatch

File Traits

  • x86

Block Information

Total Blocks: 5,423
Potentially Malicious Blocks: 483
Whitelisted Blocks: 4,476
Unknown Blocks: 464

Visual Map

? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 x 0 ? ? ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? ? ? 0 ? 0 ? 0 ? 0 ? ? ? 0 0 ? 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 x 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 x ? ? 0 ? ? ? ? 0 0 0 0 0 0 x 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 x 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 ? ? x 0 ? ? x 0 x 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 x x 0 ? ? 0 x 0 ? ? 0 0 0 0 ? ? 0 0 ? ? ? ? 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 x x ? 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 0 x 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 ? x 0 ? x x x x x x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 x ? ? 0 0 0 0 0 0 0 ? ? 0 ? 1 x ? ? ? ? ? 0 ? 0 0 ? 0 0 ? ? ? 0 0 ? x x ? ? ? ? ? ? ? ? ? x ? ? ? ? ? 0 ? ? ? x 0 0 ? ? ? ? 0 0 ? x 0 ? ? 0 ? x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 x 0 ? 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x x ? 0 ? 0 x ? x x x x x 0 0 x x ? 0 0 x ? x 0 ? x 0 0 0 0 0 ? ? 0 x ? 0 ? ? x 0 ? ? 0 0 0 0 0 0 0 0 0 ? x x x 0 x x x 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 x ? 0 0 0 0 x ? ? ? 0 0 x 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? x ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 x 0 0 x 0 0 x 0 x 0 0 0 0 0 0 ? ? 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 x 0 ? ? 0 0 0 0 ? ? ? x ? 0 0 x ? x x ? ? ? ? ? 0 x 0 ? ? ? 0 0 ? x ? ? ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? x 0 ? 0 ? 0 ? 0 ? ? 0 ? x x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? x 0 0 0 ? ? x 0 ? 0 0 0 x x ? ? 0 0 0 ? x ? ? 0 0 0 0 x ? x x 0 x ? ? ? ? ? 0 0 0 ? ? ? x 0 x 0 ? x x x x 0 0 0 0 ? ? ? 0 ? x ? x ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 x 0 ? 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 ? x x 0 0 0 0 ? 0 ? 0 0 ? ? ? ? ? ? ? x 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? 0 ? ? ? x x 0 0 0 ? 0 ? 0 x ? 0 ? ? 0 ? 0 0 x 0 ? x x x ? ? ? x ? ? ? 0 0 ? ? 0 ? 0 0 0 x ? ? x ? ? ? x 0 0 ? x x ? ? x ? 0 ? 0 ? 0 0 0 x 0 0 0 0 x x x x x 0 0 ? 0 ? x 0 x 0 0 0 0 ? 0 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 ? x 0 x x 0 0 0 0 0 0 ? ? 0 ? x 0 x 0 x x x x x x 0 ? 0 x ? 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 x x x 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 ? ? ? 0 0 ? 0 0 ? 1 x 0 ? 0 0 ? 0 0 0 0 0 ? 0 x 0 ? x ? x ? 0 ? 0 0 ? 0 x 0 ? 0 x 0 0 x ? ? 0 x 0 x 0 0 x x 0 0 x ? 0 ? ? ? x 0 ? 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 ? x ? 0 0 0 x 0 0 0 x 0 ? x x 0 x x x 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 x x 0 0 ? x ? ? ? 0 ? 0 ? ? ? 0 ? ? 0 ? 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 x 0 0 ? ? ? ? ? 0 x 0 0 0 0 ? 0 x x 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? 0 0 ? 0 ? ? 0 0 0 ? x 0 0 0 x ? ? 0 ? x 0 ? ? ? x x x x x x 0 0 0 x 0 x ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x 0 x 0 x 0 0 x ? 0 x ? ? ? ? 0 ? x ? 0 ? ? 0 0 ? 0 0 0 ? x ? 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 x 0 0 0 0 x x x x 0 x ? ? ? ? 0 0 0 0 ? 0 0 ? x ? ? 0 0 ? 0 0 ? x ? 0 0 ? 0 0 0 ? 0 0 ? ? 0 0 x 0 0 0 0 ? ? x 0 0 x ? 0 0 x 0 0 0 ? x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? x 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 x 0 0 0 0 ? x 0 x x ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 x 0 x x x 0 ? x 0 ? ? 0 0 0 0 0 x x 0 0 x 0 x 0 0 0 0 0 x x x x x x 0 x 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Ursu.O

Files Modified

File Attributes
\device\namedpipe\crashpad_5288_dqfkwbzsawkovgxo Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\crashpad_5288_dqfkwbzsawkovgxo Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\appdata\local\temp\crashpad_roblox\metadata Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\crashpad_roblox\settings.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rbx-3732767a.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rbx-837fcf8d.log Generic Write,Read Attributes

Windows API Usage

Category API
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetQueryOption
Network Winhttp
  • WinHttpOpen
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Network Winsock
  • freeaddrinfo
  • getaddrinfo
Network Info Queried
  • GetAdaptersInfo

Shell Command Execution

c:\users\user\downloads\d202c413893db0fc491935dac7cb9726e0e5981a_0002282040 c:\users\user\downloads\d202c413893db0fc491935dac7cb9726e0e5981a_0002282040 --crashpad --no-rate-limit --database=C:\Users\Eysnvkvu\AppData\Local\Temp\crashpad_roblox --metrics-dir=C:\Users\Eysnvkvu\AppData\Local\Temp\crashpad_roblox --url=https://upload.crashes.rbxinfra.com/post --annotation=UploadAttachmentKiloByteLimit=100 --annotation=UploadPercentage=0 --annotation=format=minidump --annotation=token=a2440b0bfdada85f34d79b43839f2b49ea6bba474bd7d126e844bc119271a1c3 --initial-client-data=0x4f4,0x4f8,0x4fc,0x4d0,0x504,0x74882c,0x74883c,0x74884c

Related Posts

Trending

Most Viewed

Loading...