Malicious
Hacktool for exporting non-exportable RSA private keys, confirmed by YARA rule HKTL_ExportRSA_Feb22_1, process injection (T1055), and evasion tags.
99e23a621c88854578…6aa3b0a97bThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Two tier-1 engines from TrendMicro agree on URSU family, paired with high-severity process injection heuristic and direct-IP C2 pattern. Community annotation explicitly identifies it as an open-source hacktool for private key export, aligning with filename 'exportrsa.exe' and evasion behaviors like debug detection and long sleeps. No signing or trusted history, common but zero-reputation prevalence supports non-benign status. Clean sandbox and children do not outweigh converging hacktool signals.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
TrendMicro (tier1): Trojan.Win32.URSU.AE
communityComments[0]: HKTL_ExportRSA_Feb22_1 YARA rule (hacktool)
triggeredHeuristics[0]: MalwareTips.Synth.ProcessInjection (T1055)
file.tags: detect-debug-environment, long-sleeps
behaviour.contactedIps: 20 direct IPs (e.g., 204.79.197.203, 23.216.147.64)
- 15/17 tier1 clean
- No malicious sandbox verdict
- No malicious dropped children
- Common_old prevalence (159 subs)
- Hacktool: Exports non-exportable private keys
- Process injection (MITRE T1055)
- Direct IP C2 (20 IPs, no DNS)
- Evasion: detect-debug-environment, long-sleeps
- Tier-1 detections: TrendMicro URSU
- Unsigned, zero reputation
Treat as confirmed hacktool and remove. Monitor for private key tampering or injected processes; full system scan recommended.
ursu corroborated by 2 sources
- VT (76 engines)ursu
- MT AI EngineExportRSA
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 204.79.197.203
- 23.216.147.64
- 52.251.79.25
- 20.99.132.105
- 20.99.184.37
- 23.216.147.76
- 20.99.133.109
- 192.229.211.108
- 131.253.33.203
- 20.99.186.246
- \Device\ConDrv
- \Device\ConDrv\\Connect
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER1C3D.tmp.WERInternalMetadata.xml
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER1C4F.tmp.csv
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER1C50.tmp.txt
- C:\Windows\System32\spp\store\2.0\cache\cache.dat
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER3C4.tmp.WERInternalMetadata.xml
Files this sample writes at runtime
This file drops 1 child at runtime. None are currently flagged malicious in our cache.
- 2a3a3e99cf772c20d567…28e263Never scannednever seen before
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
Evidence"C:\Users\<USER>\AppData\Local\Temp\executable.exe"Sample contacted 20 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence204.79.197.203 · 23.216.147.64 · 52.251.79.25
4 detections across 76 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- exportrsa.exe
- Size
- 17.5 KB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 99e23a621c888545780f610f418d6dc63f1decc4a0e8838ccf7bcf6aa3b0a97b
- MD5
- d42f9177a7636f549d19491c4ef2a966
- SHA-1
- 11274bc53a2c8b01269fcbb91ec1a57d0bed6dc7
- PE imphash
- 34d08a421333a7633f63a02a350bd27b
- First seen (VT)
- 6/2/2019, 12:35:11 PM
- Last analysis (VT)
- 11/14/2025, 8:09:47 AM
- First scan (MalwareTips)
- 5/9/2026, 3:51:46 AM
- Last scan (MalwareTips)
- 5/9/2026, 3:51:46 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.