Malware

About “Mal/Generic-R + Mal/Upatre-A” infection

Malware Removal

The Mal/Generic-R + Mal/Upatre-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/Upatre-A virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Mal/Generic-R + Mal/Upatre-A?


File Info:

name: A04011E5301F52FA73A8.mlw
path: /opt/CAPEv2/storage/binaries/dc5be2195fdfcfa38e7ad1e612414ef540392d45002b935e42b4d51d2c13758b
crc32: 7E45AD1C
md5: a04011e5301f52fa73a8e2a2ec4a7c0c
sha1: 2fec069f82eb54a964d03339c0503e681cd4e77b
sha256: dc5be2195fdfcfa38e7ad1e612414ef540392d45002b935e42b4d51d2c13758b
sha512: cf886caf9465866ff52097714f55a2ef1957e46cd502ee8ea604ae4ec7254d96c50ab1a4c57676a4583727aa3023772fd6c4e9eea3b217eb54559f98ebf1282f
ssdeep: 192:zkBKt7bnGFPpHuBp3RGKTxW8YMcvdQgkyAd+6zrPf51JHyqOuEQnU03FDFSjQ/:zk6dvGD8hcv7kyAPzJSjuEQnZSM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T117A211F6EBC70EB4E22786FA64BB96B30021B01DCD130EDD45E536740C23796586DD9A
sha3_384: 08fcf6cb4824e145eb47ee855c6802e339c98da52bbc9d6a3a430506e8f7503d27a9ef1b8e84dd69fb676e6d32eaa032
ep_bytes: e8cbfdffffe97f01000033c0c3558bec
timestamp: 2005-10-12 07:53:35

Version Info:

0: [No Data]

Mal/Generic-R + Mal/Upatre-A also known as:

BkavW32.FamVT.GeND.Trojan
LionicTrojan.Win32.Generic.lX56
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader9.41241
MicroWorld-eScanTrojan.GenericKD.1596624
FireEyeGeneric.mg.a04011e5301f52fa
CAT-QuickHealTrojanDownloader.Upatre.A4
ALYacTrojan.GenericKD.1596624
MalwarebytesMalware.AI.1997875158
ZillyaTrojan.Bublik.Win32.13395
SangforTrojan.Win32.Bublik.cfct
K7AntiVirusTrojan-Downloader ( 0048f6391 )
AlibabaMalware:Win32/km_2434c.None
K7GWTrojan-Downloader ( 0048f6391 )
Cybereasonmalicious.5301f5
BitDefenderThetaGen:NN.ZexaF.34182.bqX@aOaIfiki
VirITTrojan.Win32.Zbot.GDD
CyrenW32/Trojan.LLKN-5319
SymantecDownloader.Upatre!gen5
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Downloader.Upatre-5744092-0
KasperskyTrojan.Win32.Bublik.cfct
BitDefenderTrojan.GenericKD.1596624
NANO-AntivirusTrojan.Win32.Bublik.cufcrr
AvastWin32:Agent-AUID [Trj]
TencentTrojan-Downloader.Win32.Waski.16000151
Ad-AwareTrojan.GenericKD.1596624
TACHYONTrojan/W32.Bublik.22682.B
SophosMal/Generic-R + Mal/Upatre-A
ComodoTrojWare.Win32.Upatre.O@58re0o
BaiduWin32.Trojan-Downloader.Waski.a
VIPRETrojan.Win32.Upatre.jr (v)
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.mm
EmsisoftTrojan.GenericKD.1596624 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BK
JiangminTrojan/Bublik.gss
AviraTR/Rogue.AI.14361
Antiy-AVLTrojan/Generic.ASMalwS.8DF612
ArcabitTrojan.Generic.D185CD0
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
MicrosoftTrojanDownloader:Win32/Upatre.O
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R100612
Acronissuspicious
McAfeeDownloader-FSH
MAXmalware (ai score=80)
VBA32BScope.Trojan.Cloxer
CylanceUnsafe
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLOUD)
YandexTrojan.Bublik!NyFZeIRGXo4
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Agent-AUID [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Mal/Generic-R + Mal/Upatre-A?

Mal/Generic-R + Mal/Upatre-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment