Trojan

About “Trojan.Email.Upatre” infection

Malware Removal

The Trojan.Email.Upatre is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Email.Upatre virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Mimics icon used for popular non-executable file format
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Email.Upatre?


File Info:

name: 91BA0E35AE15CC63EDA0.mlw
path: /opt/CAPEv2/storage/binaries/20062bac83a3e9b3dc36a92779a1f3ae4e903509591fcc9a415cc944dd87bfda
crc32: D56BA73D
md5: 91ba0e35ae15cc63eda00f160ad0a020
sha1: 15896872fd3a95debb1aea0e8e5ee969989076ed
sha256: 20062bac83a3e9b3dc36a92779a1f3ae4e903509591fcc9a415cc944dd87bfda
sha512: 5cd45fe8a42a3690b9ec8a764a1c50756b834fb0b4438a6a937c422100e6634faea5dc76b1e7ed3d588c69360554d04cb1f9321280a7398a131358f4a026cd9d
ssdeep: 768:hzOYztCI1BuFPcYvzPCDZTFHvu2gMwje63OWoZu/G1qc5Oe/x:hzOE0AQcYvrO5F22gMwje63OWoZu/G1D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DE27EB17A85D1D0DC657F3CAAA2D21022227F5D3E38F287BC04B65CBB7B6D18816349
sha3_384: 3b2f55c8666606a991120e331a129b481fcfc9e7881fe288159cc3c6e3e44b383950e095a2e00a08f08a1e5231ad30ff
ep_bytes: 64a100000000558bec6aff68c84d4000
timestamp: 2009-05-31 03:05:21

Version Info:

0: [No Data]

Trojan.Email.Upatre also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Upatre.mv8z
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Upatre.Gen.3
FireEyeGeneric.mg.91ba0e35ae15cc63
CAT-QuickHealTrojan.Kadena.B4
ALYacTrojan.Upatre.Gen.3
MalwarebytesTrojan.Email.Upatre
ZillyaDownloader.CTBLocker.Win32.12
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004c2ec91 )
AlibabaMalware:Win32/km_24dec.None
K7GWTrojan ( 004c2ec91 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.F4D9E6E71F
VirITTrojan.Win32.Generic.EOV
CyrenW32/Upatre.Q.gen!Eldorado
SymantecDownloader.Upatre!gm
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.DGUK
APEXMalicious
ClamAVWin.Dropper.Upatre-7524255-0
KasperskyTrojan-Downloader.Win32.Upatre.gpo
BitDefenderTrojan.Upatre.Gen.3
NANO-AntivirusTrojan.Win32.Upatre.drgevv
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Crypt-SAL [Trj]
EmsisoftTrojan.Upatre.Gen.3 (B)
F-SecureTrojan.TR/Kryptik.qgmoy
DrWebTrojan.DownLoader14.17611
VIPRETrojan.Upatre.Gen.3
TrendMicroTROJ_UPATRE.SMJK
McAfee-GW-EditionUpatre-FABR!91BA0E35AE15
Trapminemalicious.high.ml.score
SophosTroj/Dyreza-ET
SentinelOneStatic AI – Suspicious PE
GDataTrojan.Upatre.Gen.3
JiangminTrojanDownloader.Upatre.hld
GoogleDetected
AviraTR/Kryptik.qgmoy
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Upatre.gpo
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.MAUA@5rueuc
ArcabitTrojan.Upatre.Gen.3
ViRobotTrojan.Win32.Upatre.Gen.H
ZoneAlarmTrojan-Downloader.Win32.Upatre.gpo
MicrosoftTrojanDownloader:Win32/Upatre.BC
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R146210
McAfeeUpatre-FACA!91BA0E35AE15
VBA32BScope.TrojanDownloader.Upatre
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMJK
RisingTrojan.Win32.Kryptik.af (CLASSIC)
YandexTrojan.DL.Upatre!Q4yOGBQhmpU
IkarusTrojan.Upatre
FortinetW32/Kryptik.DIZF!tr
AVGWin32:Crypt-SAL [Trj]
Cybereasonmalicious.5ae15c
DeepInstinctMALICIOUS

How to remove Trojan.Email.Upatre?

Trojan.Email.Upatre removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment