Trojan

What is “Trojan-Downloader.Win32.Upatre.elp”?

Malware Removal

The Trojan-Downloader.Win32.Upatre.elp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.elp virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan-Downloader.Win32.Upatre.elp?


File Info:

name: F0414B2E6416A38C61E4.mlw
path: /opt/CAPEv2/storage/binaries/c0839142fbf1a84ab392e792c409d0e6447fa8d2118057327c5369878926a33a
crc32: 9AC5D2BF
md5: f0414b2e6416a38c61e4c7f9b3c8f58e
sha1: 48692d1990bdd586031c94b4681b314aaa9e56e8
sha256: c0839142fbf1a84ab392e792c409d0e6447fa8d2118057327c5369878926a33a
sha512: 0db85db94e2287875ec5ff91d30115b14f25289db442a122ce1b4af2fda1f6599509d1ce5702b599177ed874c5e299073b67e6f0545019c9b282d71b867a5fc0
ssdeep: 192:yuJ5vKe3A1u3X0Aaolso1Q/9TukoRxj/Qhw/9LtHwXJVRugGn5yNsGJ:yuJ5ie3Aw3Xflu/9akoLjJ9LtHwLRl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137A284788BD60AB8F332CE7249B2825B7534BD216762069F4150FA714833DF29F3E995
sha3_384: 236f5ca3e683371bce30a59ca456fe7cf2dec5634d40bf370cdc8ce07cac5dcfdfc0b3275a682c0c2d95eb81d8a8afe3
ep_bytes: 55505050e827f2ffff5dc3ff6a8b6acc
timestamp: 2071-10-05 01:41:45

Version Info:

CompanyName: FASTER
FileDescription: FASTER company
FileVersion: Version 0.1.8
InternalName: FASTER
LegalCopyright: Copyright by FASTER Inc.
OriginalFilename: FASTER
Translation: 0x0416 0x04e4

Trojan-Downloader.Win32.Upatre.elp also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Downloader.Upatre-5744092-0
FireEyeGeneric.mg.f0414b2e6416a38c
CAT-QuickHealTrojanDwnldr.Upatre.AA4
ALYacTrojan.Ppatre.Gen.1
CylanceUnsafe
ZillyaDownloader.Upatre.Win32.54397
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055dd191 )
BitDefenderTrojan.Ppatre.Gen.1
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.e6416a
BaiduWin32.Trojan-Downloader.Waski.a
VirITTrojan.Win32.Generic.DCC
CyrenW32/A-10a39d23!Eldorado
SymantecDownloader.Upatre!gen5
ESET-NOD32a variant of Win32/Kryptik.CMHS
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Upatre.elp
NANO-AntivirusTrojan.Win32.Kryptik.dgtmdt
MicroWorld-eScanTrojan.Ppatre.Gen.1
RisingDownloader.Waski!1.A489 (RDMK:cmRtazqx9UB4beKIdrUHXyyJBOjI)
Ad-AwareTrojan.Ppatre.Gen.1
EmsisoftTrojan.Ppatre.Gen.1 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.EB@5j320p
DrWebTrojan.Upatre.100
VIPRELooksLike.Win32.Upatre.a (v)
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Downloader.mm
SophosML/PE-A + Troj/Agent-AJCY
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BK
JiangminTrojanDownloader.Upatre.gv
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.C78D69
MicrosoftTrojan:Win32/PWSZbot.GSB!MTB
AhnLab-V3Trojan/Win32.Downloader.R120631
Acronissuspicious
McAfeeDownloader-FSH
VBA32TrojanDownloader.Upatre
MalwarebytesTrojan.Downloader
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentTrojan-Downloader.Win32.Waski.16000151
YandexTrojan.GenAsa!zbyKuNjPV4k
IkarusTrojan.Upatre
eGambitUnsafe.AI_Score_84%
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaF.34182.bq1@aijOHMnO
AVGWin32:Agent-AULS [Trj]
AvastWin32:Agent-AULS [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Upatre.Gen

How to remove Trojan-Downloader.Win32.Upatre.elp?

Trojan-Downloader.Win32.Upatre.elp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment