Threat Database Trojans Trojan.Ulise.TA

Trojan.Ulise.TA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 5,637
Threat Level: 80 % (High)
Infected Computers: 93
First Seen: March 11, 2025
Last Seen: May 24, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Ulise.TA
Signature status: No Signature

Known Samples

MD5: ae86a5580225b3803d4afbac4167806a
SHA1: e2107568743c1755fa1b15090a9a57302fc3f251
SHA256: B568C2AB79933F9A86D7264D84569E663CC78C6D8DD2A131746D3C1CBBCDDCC8
File Size: 7.90 MB, 7903232 bytes
MD5: 3a28dc3e93a6d280166d8730490d4916
SHA1: e1d90a633ce8802ee2535ddae5e10799003bea11
SHA256: A922463EE8304F7C2788E0904D1A986A04D5272E9B8E17083CE627D695B41C53
File Size: 2.16 MB, 2159616 bytes
MD5: c5fd9cfc87acab443d5b2c31c4166abd
SHA1: 0cd5023ec5231e2e95bd9acee278a5c44ff9aeb7
SHA256: 7097BD0D910D220E5726FF6ABF2FF71B8FF2BBFB38B6D1E66FCBDD5E9D537E22
File Size: 1.36 MB, 1356288 bytes
MD5: 88831cdc6a146f1c44f1a9c11ec44862
SHA1: cb5223219c2638591b10b62861b8068ac09b264f
SHA256: 3DC82BAB150BB306CAFFCCF0A387A7A9ACDD76FA9A8DC906B442A65DDA2AD123
File Size: 4.08 MB, 4081678 bytes
MD5: 2580a322d7e598f5d4e93aa775f29f49
SHA1: 4adaa5b7e83fc0a424125e80990e45724bf6bd49
SHA256: A2253B2F2F5E4FE4831934D2799E3FBC0AD2A5E5367430E2BFE82CD6836A83C7
File Size: 1.18 MB, 1175552 bytes
Show More
MD5: 0494dfdf58d435c56f0e8d99108f3e7c
SHA1: d88fa7c1c9d4379e208888ae06563df25434e573
SHA256: 26936158F51023BD09A0FD991E86A9D3B052EC42A83C59386FE22A1254072868
File Size: 3.22 MB, 3222016 bytes
MD5: a0feb925ac9b17c918f48c1f8ae53713
SHA1: a019a090241fa8d9007aeaa00afde1e4e2fc5c3e
SHA256: BE6FE5EF733F9360A724C3F8B0EE4C9AE69BEE081C2E7FDE2C9B81D98C67750C
File Size: 729.60 KB, 729600 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 3.1.2.0
  • 1.0.0.0
Comments 製品版
Company Name
  • Cyber247.VN
  • Nam Dinh
  • www.ChronoCrash.com
  • (株)クリアブルーコミュニケーションズ
File Description
  • Arabic_All_Samsung_by_Albkre_soft
  • AUTOTQC - Pham Tat Thang - 0915980189
  • CMVS
  • Menu Game
  • SORX
File Version
  • 3.22
  • 3.1.2.0
  • 3.0.1.2
  • 1.1.37.02
  • 1.0.0.0
Internal Name
  • Arabic_All_Samsung_by_Albkre_soft.exe
  • Menu Game.exe
  • SORX.exe
  • _Auto3Q2D Lightning private - new.exe
  • クリアブルーマルチビデオシステム
Legal Copyright
  • 2025
  • Copyright (C) 2005-2014
  • Copyright © 2022
  • Copyright © 2023
  • OpenBOR
Legal Trademarks (C)クリアブルーコミュニケーションズ
Original Filename
  • Arabic_All_Samsung_by_Albkre_soft.exe
  • cmvs.exe
  • Menu Game.exe
  • SORX.exe
  • _Auto3Q2D Lightning private - new.exe
Product Name
  • Arabic_All_Samsung_by_Albkre_soft
  • Auto TQC
  • CMVS
  • Menu Game
  • SORX
Product Version
  • 3.22
  • 3.1.2.0
  • 3.0.1.2
  • 1.1.37.02
  • 1.0.0.0
  • 1.0.0

File Traits

  • 2+ executable sections
  • AutoHK
  • Enigma
  • HighEntropy
  • MPRESS
  • MPRESS Win32
  • Native MPRESS x86
  • No Version Info
  • ntdll
  • packed
Show More
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 1,437
Potentially Malicious Blocks: 129
Whitelisted Blocks: 1,307
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x 0 x x x 0 x x 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 x x 0 0 0 x x 0 0 0 x 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 x 0 0 0 x x 0 0 0 0 x x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x x 0 0 0 0 0 0 0 0 x 0 0 0 x x x 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 0 0 x x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 x 0 x x x x x x x 0 x x x x x 0 0 0 0 x x x x x x x x x x x x 0 0 0 0 0 x 0 0 0 0 x x x x x x x 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gamehack.AAD

Trending

Most Viewed

Loading...