Trojan

What is “Trojan.Upatre.Gen.5”?

Malware Removal

The Trojan.Upatre.Gen.5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Upatre.Gen.5 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Mimics icon used for popular non-executable file format
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Upatre.Gen.5?


File Info:

name: 1D03C5AF330B42636E9D.mlw
path: /opt/CAPEv2/storage/binaries/2973816cebb93e553abfefd79745fb9891020b5aad522d075be40452c9f4178d
crc32: 735B51D5
md5: 1d03c5af330b42636e9d1b84fd8b99dd
sha1: d20d257cc3679ee1d2b3e6f70845c6409acab929
sha256: 2973816cebb93e553abfefd79745fb9891020b5aad522d075be40452c9f4178d
sha512: df29298f3ea2d07d03461e1274a0780bd2e0ce236c98f1db01f8314b3b674a28010a24424add9a8a53d3f6421ae466678ac1dadb7b53cb81e168078d27f8d46d
ssdeep: 1536:3xJXH2aHwM7saKGkuoN1AG8DnTd6bGqQxuMZBto:3xQM7VkuoN1LGnJyQxu/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T181D38EA77AC0C0B2E9B7887008B4BE579A3B7C266E255C4B66D43B4B4DF16D14433B23
sha3_384: 2820e1fd965aaf14da4f056aaf046aaec6b107a1b65e484069c000192b94a8a27ae6551b2afaa14f8e512ce3b259091b
ep_bytes: 558bec6aff6820a3400068ec3d400064
timestamp: 2015-07-14 11:15:42

Version Info:

BuildVersion: 7, 15, 22, 129
Translation: 0x0419 0x04b0

Trojan.Upatre.Gen.5 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Upatre.Gen.5
ClamAVWin.Downloader.Upatre-7170285-1
FireEyeGeneric.mg.1d03c5af330b4263
CAT-QuickHealTrojanDownloader.Upatre.RF4
ALYacTrojan.Upatre.Gen.5
Cylanceunsafe
ZillyaDownloader.UpatreGen.Win32.69
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan-Downloader ( 005087911 )
K7GWTrojan-Downloader ( 005087911 )
Cybereasonmalicious.f330b4
CyrenW32/Upatre.BU
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Waski.S
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Upatre.djry
BitDefenderTrojan.Upatre.Gen.5
NANO-AntivirusTrojan.Win32.Upatre.duaxnd
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
TencentTrojan-dl.Win32.Upatre.za
F-SecureTrojan.TR/Dldr.Upatre.MT
DrWebTrojan.DownLoader14.55433
VIPRETrojan.Upatre.Gen.5
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.moderate.ml.score
SophosMal/Vawtrak-T
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Upatre.rmt
WebrootTrojan.Dropper.Gen
AviraTR/Dldr.Upatre.MT
Antiy-AVLTrojan[Downloader]/Win32.Upatre.djry
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.XBB@5te2hk
ArcabitTrojan.Upatre.Gen.5
ViRobotTrojan.Win32.Agent.131072.CQ
ZoneAlarmTrojan-Downloader.Win32.Upatre.djry
GDataWin32.Trojan-Downloader.Upatre.BK
GoogleDetected
AhnLab-V3Win-Trojan/Upatre.131072.B
BitDefenderThetaGen:NN.ZexaF.36196.iqX@aOsUidhc
MAXmalware (ai score=82)
VBA32BScope.TrojanDownloader.Upatre
MalwarebytesWaski.Trojan.Downloader.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!CpLym0yp9Bc
IkarusEmail-Worm.Win32.Locksky
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.S!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Upatre.Gen.5?

Trojan.Upatre.Gen.5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment