Trojan

Trojan.Shipup malicious file

Malware Removal

The Trojan.Shipup is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Shipup virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Shipup?


File Info:

name: 27C3AC3BDE6EA9FF5862.mlw
path: /opt/CAPEv2/storage/binaries/049cc127710bcbfb8ae1dfd5d24d813be85dac2e1be2402e1980831d7aacf36e
crc32: 54B4A34C
md5: 27c3ac3bde6ea9ff586251fa5ed8a8e5
sha1: 1062190e9cbb56173e46c3236de1d3aa20860ea1
sha256: 049cc127710bcbfb8ae1dfd5d24d813be85dac2e1be2402e1980831d7aacf36e
sha512: 2add86f94a405e9ee8a816cb8f44dd30c2d9341e3c96e79698af764a752ceff659ae399499bb32fc586f8ddbd73ee45aa1f00264c533a224e9aef0db4d960696
ssdeep: 3072:roItgTsDAJJRjO13ahGCbe0skXL4zbLFZhh2D+0caj3kyRACm:roIiJJc301XMvn9ozm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15814CF8B945F4B01EC2F9EBB4295C03D184C6B6A5B430F9FCAE5CE89F663CB04615A71
sha3_384: 38c84a37f1041f1b59b939e3557333491f6d85108d3b47cfaa5e7bb5bf5c384e61f6e88e46456ef3610348a082cf799c
ep_bytes: 2dcb23f8ff5289d4512dcb23f8ff5505
timestamp: 2013-04-02 14:39:44

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Trojan.Shipup also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.ShipUp.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cafiko.1
FireEyeGeneric.mg.27c3ac3bde6ea9ff
CAT-QuickHealTrojan.Shipup
McAfeeGenericRXAX-FB!27C3AC3BDE6E
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPREGen:Variant.Cafiko.1
SangforRansom.Win32.Cerber_23.se
K7AntiVirusTrojan ( 005a81c81 )
AlibabaTrojan:Win32/Kryptik.e121
K7GWTrojan ( 005a81c81 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36348.mS1@aaPNq!hc
VirITTrojan.Win32.Generic.ALWV
CyrenW32/Obfuscate.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HBRV
APEXMalicious
ClamAVWin.Packed.ZBot-9783420-1
KasperskyTrojan.Win32.ShipUp.bqh
BitDefenderGen:Variant.Cafiko.1
AvastWin32:Gepys-E [Trj]
TencentTrojan.Win32.Kryptik.16000652
EmsisoftGen:Variant.Cafiko.1 (B)
F-SecureTrojan.TR/Obfuscate.adj
DrWebTrojan.Redirect.140
ZillyaTrojan.ShipUp.Win32.14252
TrendMicroTROJ_KRYPTK.SML3
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
SophosMal/ZAccess-CG
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.DS729D
GoogleDetected
AviraTR/Obfuscate.adj
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.ShipUp
ArcabitTrojan.Cafiko.1
ViRobotTrojan.Win.Z.Cafiko.200208.DQD
ZoneAlarmTrojan.Win32.ShipUp.bqh
MicrosoftTrojan:Win32/Shipup.GJU!MTB
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win.Injector.R582960
ALYacGen:Variant.Cafiko.1
TACHYONTrojan/W32.Shipup.200208
Cylanceunsafe
PandaTrj/Hexas.HEU
TrendMicro-HouseCallTROJ_KRYPTK.SML3
RisingTrojan.Agent!1.6830 (CLASSIC)
YandexTrojan.GenAsa!+fckZEetchE
IkarusTrojan.Win32.Crypt
FortinetW32/Wacatac.B!tr
AVGWin32:Gepys-E [Trj]
Cybereasonmalicious.bde6ea
DeepInstinctMALICIOUS

How to remove Trojan.Shipup?

Trojan.Shipup removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment