Trojan

Trojan-Downloader.Win32.Upatre.ayt (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Upatre.ayt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.ayt virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Libya)
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan-Downloader.Win32.Upatre.ayt?


File Info:

name: 8F7671F924574A3FAEAE.mlw
path: /opt/CAPEv2/storage/binaries/a9637abe590616bf71df53c74cc54af4d573e7ad869f4365b6b4a3df9e46e69d
crc32: 193F7D5D
md5: 8f7671f924574a3faeae63924cb02e28
sha1: b357eb7bf4b4f2934328c004607614ba9ec2fd29
sha256: a9637abe590616bf71df53c74cc54af4d573e7ad869f4365b6b4a3df9e46e69d
sha512: 54d7ce74ba85c0bb40d6a7e0c08ea4953969f6c06f7684b84020944469837b73ff368d81ea163773de149287e07edb6da0eef2a4e61448e2529a7d824e4c71ed
ssdeep: 192:Ik4BKt0RFqdjHw2wkGXSa0KSZUyZ6LyURc+1oynylZN8QqthPzv/d:FkqdjHrBKAUyZ5mz14ZN8/v1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T131A260BA8B412DFAF210CD35597A410FA3356D11F7720A835698B6314D36EF6AB3E884
sha3_384: 38f5e38ecfaae66241eb6f21ed88ca6c68f5ea4391a3edf61224195b16ff57eb2692d69bcd47db6e6725e460f2106e17
ep_bytes: 535756b900414000e8b0f4ffffc36800
timestamp: 2097-03-20 10:34:13

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Upatre.ayt also known as:

BkavW32.FamVT.GeND.Trojan
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.1867035
ClamAVWin.Trojan.Generickd-826
CAT-QuickHealTrojanDwnldr.Upatre.AA4
ALYacTrojan.GenericKD.1867035
CylanceUnsafe
VIPRETrojan.GenericKD.1867035
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0001140e1 )
K7GWTrojan ( 0001140e1 )
Cybereasonmalicious.924574
BaiduWin32.Trojan-Downloader.Waski.a
VirITTrojan.Win32.Generic.ATO
CyrenW32/Trojan.SLYB-9145
SymantecDownloader.Upatre!gen5
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Upatre.ayt
BitDefenderTrojan.GenericKD.1867035
NANO-AntivirusTrojan.Win32.Upatre.dffuas
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Agent-AULS [Trj]
TencentMalware.Win32.Gencirc.114ba508
Ad-AwareTrojan.GenericKD.1867035
EmsisoftTrojan.GenericKD.1867035 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.EB@5j320p
DrWebTrojan.Upatre.87
ZillyaDownloader.Upatre.Win32.7
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Downloader.mm
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.8f7671f924574a3f
SophosML/PE-A + Troj/Upatre-FA
IkarusTrojan-Spy.Zbot
GDataWin32.Trojan.PSE1.QHQVJ
JiangminTrojanDownloader.Upatre.u
AviraTR/ATRAPS.A.1823
Antiy-AVLTrojan/Generic.ASMalwS.3CF7
ArcabitTrojan.Generic.D1C7D1B
ViRobotDropper.Agent.22016.P
ZoneAlarmTrojan-Downloader.Win32.Upatre.ayt
MicrosoftTrojanDownloader:Win32/Upatre
GoogleDetected
AhnLab-V3Dropper/Win32.Necurs.R119721
McAfeeDownloader-FSH
MAXmalware (ai score=80)
VBA32BScope.TrojanDownloader.Upatre
MalwarebytesUpatre.Trojan.Downloader.DDS
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingTrojan.DL.Win32.Upatre.anc (CLASSIC)
YandexTrojan.DL.Waski!22qgpk0SrSM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaF.34698.bqX@ai!fS3lG
AVGWin32:Agent-AULS [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Downloader.Win32.Upatre.ayt?

Trojan-Downloader.Win32.Upatre.ayt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment