Threat Database Trojans Trojan.Ursu.T

Trojan.Ursu.T

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,742
Threat Level: 80 % (High)
Infected Computers: 95
First Seen: November 21, 2023
Last Seen: July 17, 2026
OS(es) Affected: Windows

The detection of Trojan.Ursu.T on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your computer's security and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.Ursu.T?

Trojan.Ursu.T is a type of malicious software that can infiltrate your computer without your knowledge or consent. Trojans are known for their ability to disguise themselves as legitimate programs, making them difficult to detect. The name Trojan.Ursu.T suggests that it is a unique variant of a Trojan-type threat, but its specific characteristics and behaviors may not be immediately apparent.

How Trojan.Ursu.T Operates

Trojan.Ursu.T, like other Trojans, is designed to operate stealthily, often exploiting vulnerabilities in software or using social engineering tactics to gain access to your system. Once inside, it can perform a variety of malicious activities, such as stealing sensitive information, installing additional malware, or providing unauthorized access to your computer. The exact mechanisms used by Trojan.Ursu.T are not specified, but it is clear that its primary goal is to compromise your system's security and potentially cause harm.

Symptoms of Infection

Identifying a Trojan.Ursu.T infection can be challenging, as it may not exhibit obvious symptoms. However, you may notice unusual system behavior, such as slow performance, unexpected pop-ups, or unfamiliar programs running in the background. Additionally, you may experience issues with your internet connection or notice that your system is behaving erratically. If you suspect that your system is infected with Trojan.Ursu.T, it is crucial to take immediate action to remove the threat.

How to Remove Trojan.Ursu.T

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of Trojan.Ursu.T.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform another full scan to ensure that the threat has been completely removed.

Conclusion

Removing Trojan.Ursu.T from your system requires a thorough and multi-step approach. By following the steps outlined above, you can help ensure that your system is free from this malicious threat. It is essential to remain vigilant and take proactive measures to protect your system from future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when clicking on links or downloading attachments from unknown sources. Remember, the security of your personal data and system depends on your ability to detect and respond to threats like Trojan.Ursu.T.

Analysis Report

General information

Family Name: Trojan.Ursu.T
Signature status: No Signature

Known Samples

MD5: 13f7eee2659d0f5a204c2dddf90df836
SHA1: 1a59dfbcaa3c5724dc6cc052d3b171eab6ea04ed
SHA256: 68193844926FDB2A034E5B2A791D0DE914C5B0719E9E079E516D2EEF71AC4132
File Size: 1.16 MB, 1164197 bytes
MD5: cbfcf4643ac41b3afc1dd8da0481a1cb
SHA1: 7a102aacb0289b5a0309979da4990d56cbfc0a3d
SHA256: 97BAF24A46DB094DC25D122AF2BD7219A6AC53F0D087A0550A30AB674420455D
File Size: 274.94 KB, 274944 bytes
MD5: 8f99148a5130b826188c6d3cbdaddc15
SHA1: 684e2fb5b8a5b5c8a4bf56d496a1791cd141ea62
SHA256: 6528B8234DD5392D179288E9304738E68D551ED1CAF7C9B436B6683606653C53
File Size: 1.55 MB, 1545728 bytes
MD5: a70e8fe92bc4cf4ca458213897b57a95
SHA1: 8a2440e2191fa8ec98e0a2c83fedb6e9833d152c
SHA256: FF967987BB8CB1BF01776CE2929EB17952A51C14871F77B64FB7A6D05BF40E66
File Size: 784.90 KB, 784896 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 4.0.0.2
  • 1.0.0.0
Comments
  • Professional CDMA Software. Powered by Fox
  • This installation was built with Inno Setup.
Company Name
  • Dolphin Futures Limited
  • Microsoft
  • Telecom Logic
File Description
  • Album
  • DFS Universal CDMA Tool
  • Dolphin Futures XPS Viewer Setup
File Version
  • 4.0.0.2
  • 1.0.0.0
Internal Name
  • Album.exe
  • DFS.exe
Legal Copyright
  • Copyright © Microsoft 2010
  • Copyright © TL DFS 2011 (www.cdmatool.com)
  • Dolphin Futures Limited 2010-2013
Legal Trademarks TL DFS
Original Filename
  • Album.exe
  • DFS.exe
Product Name
  • Album
  • DFS
  • Dolphin Futures XPS Viewer
Product Version
  • 4.0.0.2
  • 1.1.0
  • 1.0.0.0

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • packed
  • PEC2
  • PECompact v2.20
  • x86

Block Information

Total Blocks: 343
Potentially Malicious Blocks: 6
Whitelisted Blocks: 334
Unknown Blocks: 3

Visual Map

0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 0 ? ? 1 0 1 0 0 1 1 0 0 1 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 1 1 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 2 3 0 0 0 0 1 0 0 0 0 0 1 1 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 1 0 1 2 0 0 2 2 0 0 0 0 0 1 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\software\microsoft\tip\aggregateresults::data �4 �r[�\�R��m��798 ��������/���̩)� RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 800

Related Posts

Trending

Most Viewed

Loading...