Trojan

Trojan-Downloader.Win32.Upatre.ihdh malicious file

Malware Removal

The Trojan-Downloader.Win32.Upatre.ihdh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Upatre.ihdh virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

gg-clean.hk
iplogger.org
thepleasurelive.com
apps.identrust.com
ip-api.com

How to determine Trojan-Downloader.Win32.Upatre.ihdh?


File Info:

crc32: 91A630B8
md5: bf0862343a36e7981e27b6d93229fb4e
name: kiskis.exe
sha1: af3afbda46e77454316e7f7803ee3ef3d4f1973a
sha256: 4ede78a39fc323a7449fbd819d861c921dcbcf4b6a6d232b747fda4e0f8803cf
sha512: 1daf6a46c175b80df6e57ad2b1a262c9155f7c6ef1b55918719ad5f96aa67b911da1944ff3b2935d339f8de44edbb52134c04eca100b56ef8afd4beb48c7b0df
ssdeep: 6144:bAzfWPd/AxWIlv2WcRDs2nw6aovqRcnVVbPHgx7DuM72MStKqe:07W9Ilv2WcRDsd6CgVbPAtmtKqe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0219 0x04e4

Trojan-Downloader.Win32.Upatre.ihdh also known as:

MicroWorld-eScanTrojan.GenericKD.32767711
FireEyeGeneric.mg.bf0862343a36e798
ALYacTrojan.GenericKD.32767711
MalwarebytesTrojan.MalPack.GS
SangforMalware
K7AntiVirusTrojan ( 003c36381 )
BitDefenderTrojan.GenericKD.32767711
K7GWTrojan ( 003c36381 )
Cybereasonmalicious.a46e77
BitDefenderThetaGen:NN.ZexaF.32515.uu0@a8ljO1l
SymantecML.Attribute.HighConfidence
ClamAVWin.Packed.Tofsee-7413745-0
GDataTrojan.GenericKD.32767711
KasperskyTrojan-Downloader.Win32.Upatre.ihdh
AlibabaTrojanDownloader:Win32/Upatre.8c8878e7
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.Wacatac!8.10C01 (TFE:5:EcEeBvEz89H)
Ad-AwareTrojan.GenericKD.32767711
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Chapak.domy
DrWebTrojan.Siggen8.58510
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SentinelOneDFI – Malicious PE
Trapminemalicious.high.ml.score
APEXMalicious
CyrenW32/Trojan.BASV-4081
WebrootW32.Trojan.Gen
AviraTR/AD.Chapak.domy
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F3FEDF
ZoneAlarmTrojan-Downloader.Win32.Upatre.ihdh
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.MalPe.R301592
Acronissuspicious
McAfeeRDN/Generic.grp
MAXmalware (ai score=86)
VBA32Malware-Cryptor.Limpopo
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.GYXX
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generik.BXZSALA!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360HEUR/QVM10.2.8A13.Malware.Gen

How to remove Trojan-Downloader.Win32.Upatre.ihdh?

Trojan-Downloader.Win32.Upatre.ihdh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment