Trojan

About “Trojan.Upatre.ZZ4” infection

Malware Removal

The Trojan.Upatre.ZZ4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Upatre.ZZ4 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Upatre.ZZ4?


File Info:

name: E57C9236C3477B2A3D26.mlw
path: /opt/CAPEv2/storage/binaries/b94e051cfc7ff4a42b73b71c488f566c70ab48a9e7c1c2634b9d8ebf13ccbac3
crc32: 63092318
md5: e57c9236c3477b2a3d26dbab86ed274a
sha1: 5dc6cf1741ad871668aa51e1e107bc9990db7fca
sha256: b94e051cfc7ff4a42b73b71c488f566c70ab48a9e7c1c2634b9d8ebf13ccbac3
sha512: bf73ae31da4314725ee4bb404fba548da4872e066c560ee5b2c71f22bdac186a3e680301c96177ce3a6642ab39bb99d63941ec3afbca79a11339b4591adffc82
ssdeep: 384:TgEaziQIBt8yguzjEBNQiviL//U8zYpDc7+57ERk9+:T7a/6BlSvW//pzW7h+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5B34BF33ACDDF2EF12E9EB588B4D0EA5C25791488A2002E75C4E84F1C661E799ED611
sha3_384: b5084742340e4bd898048b074376aa0773b35c1ebefd48db42b1398ba7cc5bc0f35fc19acf6010d077adc9f95e0b6e2a
ep_bytes: 837c24120ae8b6ffffff29d101c1e889
timestamp: 2004-05-28 09:53:59

Version Info:

0: [No Data]

Trojan.Upatre.ZZ4 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.48863363
CAT-QuickHealTrojan.Upatre.ZZ4
ALYacTrojan.GenericKD.48863363
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderTrojan.GenericKD.48863363
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.6c3477
BitDefenderThetaGen:NN.ZexaF.34606.gmY@aebg6tni
CyrenW32/Upatre.NM.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Waski.B
BaiduWin32.Trojan-Downloader.Waski.a
APEXMalicious
ClamAVWin.Dropper.Upatre-9944336-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.pef
NANO-AntivirusTrojan.Win32.Vundo.fncedi
RisingDownloader.Upatre!8.B5 (RDMK:cmRtazoFf0TUDsxvT5I)
Ad-AwareTrojan.GenericKD.48863363
EmsisoftTrojan.GenericKD.48863363 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.B@80t362
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader9.19947
ZillyaDownloader.Upatre.Win32.70481
TrendMicroTROJ_UPATRE.SM5
McAfee-GW-EditionPWSZbot-FMO!E57C9236C347
FireEyeGeneric.mg.e57c9236c3477b2a
SophosML/PE-A + Troj/Zbot-HMB
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.fqcv
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.7D7FCD
MicrosoftTrojanDownloader:Win32/Upatre.A
ArcabitTrojan.Generic.D2E99883
GDataWin32.Trojan-Downloader.Upatre.BJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Upatre.R477425
McAfeePWSZbot-FMO!E57C9236C347
MAXmalware (ai score=81)
VBA32TrojanDownloader.Upatre
MalwarebytesSimbot.Backdoor.Stealer.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_UPATRE.SM5
TencentTrojan.Win32.Delf.wd
YandexTrojan.GenAsa!G7HTEQf3zWI
IkarusTrojan-Spy.Zbot
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.CF!tr
AVGWin32:Waski-B [Cryp]
AvastWin32:Waski-B [Cryp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Upatre.ZZ4?

Trojan.Upatre.ZZ4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment