Trojan

Trojan.Upatre.Gen.5 (B) (file analysis)

Malware Removal

The Trojan.Upatre.Gen.5 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Upatre.Gen.5 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Mimics icon used for popular non-executable file format
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Upatre.Gen.5 (B)?


File Info:

name: 77F55B319B092EE338A5.mlw
path: /opt/CAPEv2/storage/binaries/8e805606f1a5937fe918a75f1818204fd39ffa0b1271571828148eed01820b8c
crc32: AE3D0E49
md5: 77f55b319b092ee338a5569a02ced4e6
sha1: bee6cd86414437c0d9db34df284e8104935069c4
sha256: 8e805606f1a5937fe918a75f1818204fd39ffa0b1271571828148eed01820b8c
sha512: 69350e3c9cbd21c8bd91c818a263200a849b32d05fd7ed39f0f217e4a1db3dfaa343093e194c2becbbdd8a1a259826e627caae5dba95a3f52941dc7a734dbe9a
ssdeep: 1536:zR2BobiS4jYHNOedAoTJNE2GGOXEIJYL98K:Fqo+AtldAoTPAGOGL9v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FD35A2328A089F7F36EC9B00CB10DBDA776AB1B7335174A8694C84F2C2FD525D65507
sha3_384: 6669de6e3fa1157247927e7253615ffd418a34752747f90bb1bf52b360081cb90d565473c6d96c9e26421084ea6814a1
ep_bytes: 558bec6aff68f8b5400068ac37400064
timestamp: 2015-07-22 08:27:16

Version Info:

BuildVersion: 7, 15, 22, 129
Translation: 0x0419 0x04b0

Trojan.Upatre.Gen.5 (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader15.6021
MicroWorld-eScanTrojan.Upatre.Gen.5
FireEyeGeneric.mg.77f55b319b092ee3
SkyhighBehavesLike.Win32.Generic.cz
McAfeeGenericRXNH-CV!77F55B319B09
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.4661340
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Kryptik.30e833dd
K7GWTrojan ( 004c92211 )
K7AntiVirusTrojan ( 005a9af81 )
BitDefenderThetaGen:NN.ZexaF.36802.iuX@aKJP!8fc
SymantecDownloader.Upatre
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.DQYD
APEXMalicious
TrendMicro-HouseCallTROJ_UPATRE.SM37
AvastWin32:Crypt-SDI [Trj]
ClamAVWin.Downloader.Upatre-7374321-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.Upatre.Gen.5
NANO-AntivirusTrojan.Win32.Dwn.duhhfu
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
TencentMalware.Win32.Gencirc.10b23daa
EmsisoftTrojan.Upatre.Gen.5 (B)
F-SecureTrojan.TR/Kryptik.abbogp
BaiduWin32.Trojan.Kryptik.ks
VIPRETrojan.Upatre.Gen.5
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
SophosMal/Vawtrak-S
IkarusTrojan.Win32.Crypt
JiangminTrojan/Generic.bhigq
GoogleDetected
AviraTR/Kryptik.abbogp
VaristW32/Trojan.JNBU-7452
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojanDownloader:Win32/Upatre
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.DLF@5t0aja
ArcabitTrojan.Upatre.Gen.5
ViRobotTrojan.Win.Z.Upatre.140976.A
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan.PSE.1RZTNBE
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Upatre.R475059
Acronissuspicious
VBA32BScope.Malware-Cryptor.Dyllu
ALYacTrojan.Upatre.Gen.5
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!8D+PFuOKM1c
MAXmalware (ai score=84)
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.DRBQ!tr
AVGWin32:Crypt-SDI [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Trojan.Upatre.Gen.5 (B)?

Trojan.Upatre.Gen.5 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment