Trojan

Trojan.Upatre.NT information

Malware Removal

The Trojan.Upatre.NT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Upatre.NT virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Behavior consistent with a dropper attempting to download the next stage.
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

icanhazip.com

How to determine Trojan.Upatre.NT?


File Info:

name: E851B6DD3EAD622B3E03.mlw
path: /opt/CAPEv2/storage/binaries/f945fc4aad33bbeb71ddb823af76c981bc7987002da815b22f5c05d27f73a1a7
crc32: 234C998A
md5: e851b6dd3ead622b3e03cd51f54a42dc
sha1: 2ece797d890a2d3584865a75d65d5a715b597aaa
sha256: f945fc4aad33bbeb71ddb823af76c981bc7987002da815b22f5c05d27f73a1a7
sha512: 6de8ab63865db1df54a425d6a739edc4a6aada93fd3d190ee29fb752cf6c7277431d22f8c87fa409ea03a0d6c3ef7be5e624ad17ac9ba745b578e75aa0c6b88b
ssdeep: 768:u75mPvJ09MMhrM5hO4eSzvB7nh7+/idC:uMXJ09MMhrM5hO41zvFh74
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16DD2E6C3A7408936E9900F76056A966A4274BD583FB9F98F3D1CB25EB3775C25A30383
sha3_384: f88b0c5f93b2460e0a87f91b972d148ed5c885d29d19d399316a3ff2b2a297ac961a6bd94e3f212159165e376c55a442
ep_bytes: 64a100000000558bec6aff6870384000
timestamp: 2015-01-02 10:10:00

Version Info:

0: [No Data]

Trojan.Upatre.NT also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Upatre.mm2y
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Upatre.Gen.3
CAT-QuickHealTrojan.Kadena.B4
McAfeeUpatre-FACK!E851B6DD3EAD
CylanceUnsafe
ZillyaDownloader.UpatreGen.Win32.44
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004c75411 )
K7GWTrojan ( 004c75411 )
CrowdStrikewin/malicious_confidence_60% (D)
BaiduWin32.Trojan.Kryptik.jc
CyrenW32/Upatre.AI.gen!Eldorado
SymantecDownloader.Upatre!gen5
ESET-NOD32a variant of Win32/Kryptik.DKRX
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Upatre.Gen.3
NANO-AntivirusTrojan.Win32.Upatre.dssczd
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Malware-gen
TencentTrojan.Win32.Kryptik.DKRX
Ad-AwareTrojan.Upatre.Gen.3
EmsisoftTrojan.Upatre.Gen.3 (B)
ComodoTrojWare.Win32.TrojanDownloader.Upatre.BCF@5s4kib
DrWebTrojan.DownLoader15.20173
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_UPATRE.SMJV0
McAfee-GW-EditionBehavesLike.Win32.VirRansom.mm
FireEyeGeneric.mg.e851b6dd3ead622b
SophosML/PE-A + Troj/Dyreza-FS
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.Q
JiangminTrojanDownloader.Upatre.kpz
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Spy.Zbot.txzdsr
ArcabitTrojan.Upatre.Gen.3
ViRobotTrojan.Win32.Upatre.Gen.B
MicrosoftTrojanDownloader:Win32/Upatre
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.C879432
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34294.bqW@a4IgQjfi
ALYacTrojan.Upatre.Gen.3
MAXmalware (ai score=82)
VBA32BScope.TrojanDownloader.Upatre
MalwarebytesTrojan.Upatre.NT
TrendMicro-HouseCallTROJ_UPATRE.SMJV0
RisingTrojan.Win32.Kryptik.af (CLASSIC)
YandexTrojan.DL.Upatre!3k6oqHqXoGU
IkarusVirTool.Obfuscator
eGambitUnsafe.AI_Score_57%
FortinetW32/Waski.A!tr
AVGWin32:Malware-gen
Cybereasonmalicious.d3ead6
PandaTrj/Genetic.gen

How to remove Trojan.Upatre.NT?

Trojan.Upatre.NT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment