Threat Database Backdoors Backdoor.Ursu.O

Backdoor.Ursu.O

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 22,709
Threat Level: 60 % (Medium)
Infected Computers: 181
First Seen: February 28, 2022
Last Seen: June 14, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Backdoor.Ursu.O
Signature status: Hash Mismatch

Known Samples

MD5: d8affc8e6034d82b4137f7775ae10839
SHA1: 1cfaad75b796f1331937eb61f9ace7957b37b18b
SHA256: 272D12A55A64C48020DB8AD3ACF01D1791DFEC8B85CABA7DDD89EBE3FF13C75F
File Size: 1.58 MB, 1575304 bytes
MD5: bbafc634c81ec06a2bbae7c4fb90f4a7
SHA1: d202c413893db0fc491935dac7cb9726e0e5981a
SHA256: AC0560950FE76493D0F197C33AE8CF9F7BB201BEB0AF0D970B328A0C00C5E87D
File Size: 2.28 MB, 2282040 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Roblox Corporation
File Description Roblox
File Version
  • 1, 6, 0, 5160305
  • 1, 6, 0, 411923
Legal Copyright Copyright © 2020 Roblox Corporation. All rights reserved.
Original Filename Roblox.exe
Product Name Roblox Bootstrapper
Product Version
  • 1, 6, 0, 5160305
  • 1, 6, 0, 411923

Digital Signatures

Signer Root Status
Roblox Corporation DigiCert EV Code Signing CA (SHA2) Hash Mismatch
Roblox Corporation Symantec Class 3 Extended Validation Code Signing CA - G2 Hash Mismatch

File Traits

  • x86

Block Information

Total Blocks: 5,423
Potentially Malicious Blocks: 483
Whitelisted Blocks: 4,476
Unknown Blocks: 464

Visual Map

? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 x 0 ? ? ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? ? ? 0 ? 0 ? 0 ? 0 ? ? ? 0 0 ? 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 x 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 x ? ? 0 ? ? ? ? 0 0 0 0 0 0 x 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 x 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 ? ? x 0 ? ? x 0 x 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 x x 0 ? ? 0 x 0 ? ? 0 0 0 0 ? ? 0 0 ? ? ? ? 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 x x ? 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 0 x 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 ? x 0 ? x x x x x x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 x ? ? 0 0 0 0 0 0 0 ? ? 0 ? 1 x ? ? ? ? ? 0 ? 0 0 ? 0 0 ? ? ? 0 0 ? x x ? ? ? ? ? ? ? ? ? x ? ? ? ? ? 0 ? ? ? x 0 0 ? ? ? ? 0 0 ? x 0 ? ? 0 ? x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 x 0 ? 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x x ? 0 ? 0 x ? x x x x x 0 0 x x ? 0 0 x ? x 0 ? x 0 0 0 0 0 ? ? 0 x ? 0 ? ? x 0 ? ? 0 0 0 0 0 0 0 0 0 ? x x x 0 x x x 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 x ? 0 0 0 0 x ? ? ? 0 0 x 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? x ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 x 0 0 x 0 0 x 0 x 0 0 0 0 0 0 ? ? 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 x 0 ? ? 0 0 0 0 ? ? ? x ? 0 0 x ? x x ? ? ? ? ? 0 x 0 ? ? ? 0 0 ? x ? ? ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? x 0 ? 0 ? 0 ? 0 ? ? 0 ? x x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? x 0 0 0 ? ? x 0 ? 0 0 0 x x ? ? 0 0 0 ? x ? ? 0 0 0 0 x ? x x 0 x ? ? ? ? ? 0 0 0 ? ? ? x 0 x 0 ? x x x x 0 0 0 0 ? ? ? 0 ? x ? x ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 x 0 ? 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 ? x x 0 0 0 0 ? 0 ? 0 0 ? ? ? ? ? ? ? x 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? 0 ? ? ? x x 0 0 0 ? 0 ? 0 x ? 0 ? ? 0 ? 0 0 x 0 ? x x x ? ? ? x ? ? ? 0 0 ? ? 0 ? 0 0 0 x ? ? x ? ? ? x 0 0 ? x x ? ? x ? 0 ? 0 ? 0 0 0 x 0 0 0 0 x x x x x 0 0 ? 0 ? x 0 x 0 0 0 0 ? 0 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 ? x 0 x x 0 0 0 0 0 0 ? ? 0 ? x 0 x 0 x x x x x x 0 ? 0 x ? 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 x x x 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 ? ? ? 0 0 ? 0 0 ? 1 x 0 ? 0 0 ? 0 0 0 0 0 ? 0 x 0 ? x ? x ? 0 ? 0 0 ? 0 x 0 ? 0 x 0 0 x ? ? 0 x 0 x 0 0 x x 0 0 x ? 0 ? ? ? x 0 ? 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 ? x ? 0 0 0 x 0 0 0 x 0 ? x x 0 x x x 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 x x 0 0 ? x ? ? ? 0 ? 0 ? ? ? 0 ? ? 0 ? 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 x 0 0 ? ? ? ? ? 0 x 0 0 0 0 ? 0 x x 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? 0 0 ? 0 ? ? 0 0 0 ? x 0 0 0 x ? ? 0 ? x 0 ? ? ? x x x x x x 0 0 0 x 0 x ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x 0 x 0 x 0 0 x ? 0 x ? ? ? ? 0 ? x ? 0 ? ? 0 0 ? 0 0 0 ? x ? 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 x 0 0 0 0 x x x x 0 x ? ? ? ? 0 0 0 0 ? 0 0 ? x ? ? 0 0 ? 0 0 ? x ? 0 0 ? 0 0 0 ? 0 0 ? ? 0 0 x 0 0 0 0 ? ? x 0 0 x ? 0 0 x 0 0 0 ? x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? x 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 x 0 0 0 0 ? x 0 x x ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 x 0 x x x 0 ? x 0 ? ? 0 0 0 0 0 x x 0 0 x 0 x 0 0 0 0 0 x x x x x x 0 x 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Ursu.O

Files Modified

File Attributes
\device\namedpipe\crashpad_5288_dqfkwbzsawkovgxo Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\crashpad_5288_dqfkwbzsawkovgxo Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\appdata\local\temp\crashpad_roblox\metadata Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\crashpad_roblox\settings.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rbx-3732767a.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rbx-837fcf8d.log Generic Write,Read Attributes

Windows API Usage

Category API
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetQueryOption
Network Winhttp
  • WinHttpOpen
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Network Winsock
  • freeaddrinfo
  • getaddrinfo
Network Info Queried
  • GetAdaptersInfo

Shell Command Execution

c:\users\user\downloads\d202c413893db0fc491935dac7cb9726e0e5981a_0002282040 c:\users\user\downloads\d202c413893db0fc491935dac7cb9726e0e5981a_0002282040 --crashpad --no-rate-limit --database=C:\Users\Eysnvkvu\AppData\Local\Temp\crashpad_roblox --metrics-dir=C:\Users\Eysnvkvu\AppData\Local\Temp\crashpad_roblox --url=https://upload.crashes.rbxinfra.com/post --annotation=UploadAttachmentKiloByteLimit=100 --annotation=UploadPercentage=0 --annotation=format=minidump --annotation=token=a2440b0bfdada85f34d79b43839f2b49ea6bba474bd7d126e844bc119271a1c3 --initial-client-data=0x4f4,0x4f8,0x4fc,0x4d0,0x504,0x74882c,0x74883c,0x74884c

Trending

Most Viewed

Loading...