Threat Database Trojans Trojan.Ursu.T

Trojan.Ursu.T

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,417
Threat Level: 80 % (High)
Infected Computers: 78
First Seen: November 21, 2023
Last Seen: January 1, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Ursu.T
Packers: PECompact v2.20
Signature status: No Signature

Known Samples

MD5: 13f7eee2659d0f5a204c2dddf90df836
SHA1: 1a59dfbcaa3c5724dc6cc052d3b171eab6ea04ed
SHA256: 68193844926FDB2A034E5B2A791D0DE914C5B0719E9E079E516D2EEF71AC4132
File Size: 1.16 MB, 1164197 bytes
MD5: cbfcf4643ac41b3afc1dd8da0481a1cb
SHA1: 7a102aacb0289b5a0309979da4990d56cbfc0a3d
SHA256: 97BAF24A46DB094DC25D122AF2BD7219A6AC53F0D087A0550A30AB674420455D
File Size: 274.94 KB, 274944 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name Dolphin Futures Limited
File Description Dolphin Futures XPS Viewer Setup
Legal Copyright Dolphin Futures Limited 2010-2013
Product Name Dolphin Futures XPS Viewer
Product Version 1.1.0

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • packed
  • PEC2
  • PECompact v2.20
  • x86

Block Information

Total Blocks: 361
Potentially Malicious Blocks: 14
Whitelisted Blocks: 347
Unknown Blocks: 0

Visual Map

0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x 0 x x x 0 0 0 0 0 0 0 0 2 0 1 0 0 0 0 1 1 0 0 0 1 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 2 0 0 1 0 0 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 1 1 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 1 0 1 2 0 0 2 2 0 0 0 0 0 1 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Trending

Most Viewed

Loading...