Trojan

Trojan-Downloader.Win32.Upatre.cmrz (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Upatre.cmrz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.cmrz virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavior consistent with a dropper attempting to download the next stage.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan-Downloader.Win32.Upatre.cmrz?


File Info:

name: 95D7C6A7EA4E0EC707A2.mlw
path: /opt/CAPEv2/storage/binaries/6f4bfe413dfd9963a6171279165577e2bc4e4b5fd95a395cbc5b99a7af00892e
crc32: 75A7E112
md5: 95d7c6a7ea4e0ec707a252eec87b631d
sha1: 3aaa3fcfad667b6538b67093ca3c9a4877128440
sha256: 6f4bfe413dfd9963a6171279165577e2bc4e4b5fd95a395cbc5b99a7af00892e
sha512: 89ff338917f592552ba5effb184801015f33be6da203f8777f7b81bf595f10edf5a3fe7fde8b6c19612b404f3a1c627ce3f3c47e700a01c51d703266de819dc2
ssdeep: 1536:Om1wCcyp4OH5/PNP4K1d+QXkSofXYVNy4D+jHJGhUXqBsUg5:H1sRK1d+QLofXYVNyYqHEUAsUS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D1736C2277D48572FA33817448B9C6D1666ABC133AA1454F3E8E770E0E727829DB631F
sha3_384: 4a833c92da6d6555b8f1f6f47d10ea195940c1aa59c720bceb9fa2950a6daec18cf55341a739e0858c4189376ba1a476
ep_bytes: e8f4150000e978feffff8bff558bec8b
timestamp: 2014-04-25 08:50:48

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Upatre.cmrz also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader15.18281
MicroWorld-eScanTrojan.Upatre.Gen.3
CAT-QuickHealTrojan.Necurs.MUE.A4
ALYacTrojan.Upatre.Gen.3
CylanceUnsafe
ZillyaDownloader.UpatreGen.Win32.90
K7AntiVirusTrojan ( 004c75411 )
K7GWTrojan ( 004c75411 )
Cybereasonmalicious.7ea4e0
BitDefenderThetaGen:NN.ZexaF.34294.eqX@auvNULhO
CyrenW32/Upatre.BE.gen!Eldorado
SymantecDownloader.Upatre!gen5
ESET-NOD32a variant of Win32/Kryptik.DOJF
APEXMalicious
ClamAVWin.Malware.Upatre-9888345-0
KasperskyTrojan-Downloader.Win32.Upatre.cmrz
BitDefenderTrojan.Upatre.Gen.3
NANO-AntivirusTrojan.Win32.Upatre.dtluqb
AvastWin32:Malware-gen
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareTrojan.Upatre.Gen.3
EmsisoftTrojan.Upatre.Gen.3 (B)
ComodoTrojWare.Win32.TrojanDownloader.Upatre.DOM@5st38w
BaiduWin32.Trojan.Kryptik.jr
VIPRETrojan-Downloader.Win32.Upatre.tfl (v)
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionUpatre-FACQ!95D7C6A7EA4E
FireEyeGeneric.mg.95d7c6a7ea4e0ec7
SophosML/PE-A + Troj/Upatre-OS
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bgsjz
AviraTR/Dldr.Upatre.MU
Antiy-AVLTrojan/Generic.ASMalwS.1F0D298
MicrosoftTrojanDownloader:Win32/Upatre
ArcabitTrojan.Upatre.Gen.3
GDataWin32.Trojan.PSE.MJICGV
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R155998
Acronissuspicious
McAfeeUpatre-FACQ!95D7C6A7EA4E
MAXmalware (ai score=85)
VBA32BScope.TrojanDownloader.Upatre
MalwarebytesTrojan.Upatre
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingMalware.FakePDF/ICON!1.A24C (CLASSIC)
IkarusTrojan.Cryptic
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.DQAA!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Downloader.Win32.Upatre.cmrz?

Trojan-Downloader.Win32.Upatre.cmrz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment