Threat Database Trojans Trojan.Ursu.B

Trojan.Ursu.B

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Ursu.B
Signature status: Hash Mismatch

Known Samples

MD5: 807d442e33cd5ec3e504c33c9652fe95
SHA1: a7306e88d7b5da1385a455edec4eef1f4869e34d
SHA256: 87FFA9F8593F8BCA690AA33C3AE9382E23940B1B35B8483D2EA8333DDF2034BE
File Size: 827.10 KB, 827096 bytes
MD5: 55bb029fb7339540a0f58d1c8d8a42a5
SHA1: 009054214f8d7e81f584d0eb634e61cbdae536bf
SHA256: ADA60B4B171ED5DE5B8C75B2FB2D29E72EB9C037ECE7CF45AA2A8DD8F429B0A1
File Size: 823.30 KB, 823296 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Roblox Corporation
File Description Roblox
File Version
  • 1, 6, 3, 166809
  • 1, 6, 3, 163458
Legal Copyright (C) 2012 Roblox Corporation. All rights reserved.
Original Filename Roblox.exe
Product Name Roblox Bootstrapper
Product Version 1, 6, 3, 0

Digital Signatures

Signer Root Status
Roblox Corporation Symantec Class 3 Extended Validation Code Signing CA - G2 Hash Mismatch
Roblox Corporation thawte SHA256 Code Signing CA Hash Mismatch

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 2,859
Potentially Malicious Blocks: 475
Whitelisted Blocks: 2,383
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x x x x x x 0 0 0 x 0 x 0 0 0 0 0 0 0 x x 0 x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 x 0 x 0 0 0 0 0 x x x x x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x 0 0 x x 0 x x 0 1 x x x x 1 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 x x 0 x x x 0 x x x 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 0 x x 0 0 0 0 0 0 x x x 0 x x x x x x x x 0 0 x x 0 x x 0 0 x 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 x x 0 x 0 1 1 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 x 0 x x x 0 0 x x x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 x x x x x x 0 0 x 0 0 0 0 x 0 0 x 0 x x x x x 0 x 0 0 0 0 x 0 x x x x x 0 0 0 x x x x x x x 0 x 0 x x 0 x x x x 0 0 x x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 x 0 x 0 0 0 x x x x 0 0 0 0 1 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 ? 0 0 x x x x 0 x 0 x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x x x 0 x 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 x 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 x x x x 0 x x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 x 0 x x x 0 x 0 0 0 0 0 x x x x x x x x 0 0 x x x x x 0 0 0 0 x x x 0 x 0 0 0 x x 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 x x 0 x 0 0 0 x 0 x 0 x 0 x 0 x x x 0 0 x 0 x 0 0 0 0 0 0 x x x x x x x x 0 0 x x x x x x x x x 0 0 0 0 0 x x 0 x 0 x 0 x 0 x 0 x x x x 0 x x x x x 0 0 0 x x 0 x 0 0 0 x x x x x 0 x x x 0 0 0 x x 0 0 x x x x 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x x x x x x x x x x x x 0 x 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 x x 0 x 0 x x 0 0 0 x 0 0 0 x 0 x x x x x x x x x x 0 x x 0 0 x 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 1 1 0 0 0 0 1 1 1 1 0 2 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 1 1 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Ursu.B
  • Ursu.BF

Files Modified

File Attributes
c:\users\user\appdata\local\temp\rbx-014de9cc.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rbx-71a2f043.log Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\roblox corporation\roblox::cpath C:\Users\user\AppData\LocalLow\rbxcsettings.rbx RegNtPreCreateKey

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Network Info Queried
  • GetAdaptersInfo
Network Wininet
  • HttpOpenRequest
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetSetOption
Network Winhttp
  • WinHttpOpen

Trending

Most Viewed

Loading...