Trojan

Trojan-Downloader.Win32.Upatre.bla (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Upatre.bla is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.bla virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Arabic (Libya)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojan-Downloader.Win32.Upatre.bla?


File Info:

name: 33B6A3E49F059379D5B1.mlw
path: /opt/CAPEv2/storage/binaries/55bdae05746be0b5d620c8df4f6a605843d91a2c19863b1125f907f3b026e116
crc32: C8C7B063
md5: 33b6a3e49f059379d5b1b5b67ef106b3
sha1: 217edfbbb25c66696135b5fe250a29464cc7678c
sha256: 55bdae05746be0b5d620c8df4f6a605843d91a2c19863b1125f907f3b026e116
sha512: ec37d177b18a8f75b904e6300757a2f3a79d21df839a716781c9514a408c8a5a0ab5378b76606862a6c1308f4e0a69a9d17cfea884ce91a96ff9e0aee4c25e61
ssdeep: 384:FlF5u+XVNu9/efXYp2N68wfmt5+CIO8cW:LPu+XVY9/e/ZZw+t5shT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FFF28626D7ED44B5F37B8A3E56B64288882BFD303B41A9DEA18D714105337C6C9B069F
sha3_384: fc04cd78427da7c00376402c0d851e0757b58a2f5c64ce9db92286accd667906e037b63942e4dd1e005ac794acbd77dd
ep_bytes: 57565351e87ef4ffffc3cccccccccccc
timestamp: 1973-03-03 10:25:35

Version Info:

CompanyName: JineJong
FileDescription: JineJong company
FileVersion: Version 2.5.23
InternalName: JineJong
LegalCopyright: Copyright by JineJong
OriginalFilename: JineJong
Translation: 0x040b 0x04e2

Trojan-Downloader.Win32.Upatre.bla also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.33b6a3e49f059379
CAT-QuickHealRansom.Crowti.ZZ6
ALYacTrojan.Ppatre.Gen.1
CylanceUnsafe
ZillyaDownloader.Upatre.Win32.66076
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-Downloader.Waski.a
CyrenW32/Upatre.GR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Downloader.Upatre-6840800-0
KasperskyTrojan-Downloader.Win32.Upatre.bla
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.Upatre.dfecyf
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Agent-AULS [Trj]
TencentMalware.Win32.Gencirc.10b0c5b0
Ad-AwareTrojan.Ppatre.Gen.1
SophosML/PE-A + Troj/HkMain-AZ
ComodoTrojWare.Win32.TrojanDownloader.Upatre.AAL@5iclp5
DrWebTrojan.DownLoad3.34292
VIPRETrojan-Downloader.Win32.Cutwail.bza (v)
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nt
EmsisoftTrojan.Ppatre.Gen.1 (B)
IkarusTrojan.Win32.Bublik
GDataWin32.Trojan-Downloader.Upatre.BK
JiangminTrojanDownloader.Upatre.p
AviraHEUR/AGEN.1135285
Antiy-AVLTrojan/Generic.ASMalwS.BEF522
MicrosoftTrojanDownloader:Win32/Upatre.AA
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Upatre.C2673332
Acronissuspicious
McAfeeUpatre-FAEL!33B6A3E49F05
MAXmalware (ai score=89)
VBA32Trojan.Download
MalwarebytesTrojan.Upatre.Generic
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!+rIQ7cDoUXQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaF.34114.cq1@a8Vb8fmG
AVGWin32:Agent-AULS [Trj]
Cybereasonmalicious.49f059
PandaTrj/Genetic.gen

How to remove Trojan-Downloader.Win32.Upatre.bla?

Trojan-Downloader.Win32.Upatre.bla removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment