Trojan

Trojan.VUPX.ON malicious file

Malware Removal

The Trojan.VUPX.ON is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.VUPX.ON virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.VUPX.ON?


File Info:

name: 5FE9154D5D74491BBBC9.mlw
path: /opt/CAPEv2/storage/binaries/044749df9f7e7ed560ab5d15e9031b15b6e497fe068a82e4e6de821dfb807a1f
crc32: 3F584795
md5: 5fe9154d5d74491bbbc9434cb6aa7a7a
sha1: 1965f0cf2d6f7381891f4d5e2d859a7d3e80f802
sha256: 044749df9f7e7ed560ab5d15e9031b15b6e497fe068a82e4e6de821dfb807a1f
sha512: 4eb53951126da8b0b8cbe2943db518d0367ca6e22495c857954e3c81d7f155db44dbb54931ae95a4e2f3c320de2f39a9c3cdffa3ac9396da2af84f5d741103a0
ssdeep: 3072:CJ1leFhNojC9MtNkHGS85js8KXqmFHQndOs5Renlm4SZvkooutH3:G1moj9tyGS9XEndNRQlm4SLoSX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DAE3120BCACBD8E2D67B4535893B68560504A71EE921C73347E630BEF049BACF167B52
sha3_384: 55a64db4f36b57758698f958bdd8eb54dab4cbec938611ce4fdc7033b5e9cd2b54e84bc0466e68a145f7f5faab4d10d4
ep_bytes: 60be008042008dbe0090fdff5789e58d
timestamp: 2011-04-12 16:58:06

Version Info:

CompanyName: Orb Networks
FileDescription: Amity Calm Archer
FileVersion: 7.9
InternalName: Altar Axiom Peace
LegalCopyright: Year Asia Witch 2002 2006
OriginalFilename: Carry.exe
ProductName: Ingot
Translation: 0x0409 0x04b0

Trojan.VUPX.ON also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.547
MicroWorld-eScanGen:Trojan.Heur.Zbot.6
FireEyeGeneric.mg.5fe9154d5d74491b
CAT-QuickHealTrojanPWS.Zbot.Y
ALYacGen:Trojan.Heur.Zbot.6
CylanceUnsafe
VIPRETrojan.Win32.Reveto.D (v)
SangforTrojan.Win32.Gen.6
K7AntiVirusPassword-Stealer ( 003c6e581 )
AlibabaTrojan:Win32/Kryptik.57f930b9
K7GWTrojan ( 005685bd1 )
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaAI:Packer.EB5647A916
VirITTrojan.Win32.Generic.BLPF
CyrenW32/Zbot.DP.gen!Eldorado
SymantecPacked.Generic.350
ESET-NOD32a variant of Win32/Kryptik.AJLI
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.Zbot.6
NANO-AntivirusTrojan.Win32.Panda.yandp
SUPERAntiSpywareTrojan.Agent/Gen-Faker[desc]
AvastFileRepMalware
TencentWin32.Trojan.Crypt.Tbsz
Ad-AwareGen:Trojan.Heur.Zbot.6
SophosML/PE-A + Mal/Zbot-EZ
ComodoTrojWare.Win32.Kryptik.ZWX@4mhf54
ZillyaTrojan.Kryptik.Win32.384109
McAfee-GW-EditionBehavesLike.Win32.ZBot.cc
EmsisoftGen:Trojan.Heur.Zbot.6 (B)
IkarusTrojan.Win32.Reveton
JiangminTrojan/Generic.voif
WebrootW32.Trojan.Gen
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.4C5836
MicrosoftPWS:Win32/Zbot
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Heur.Zbot.6
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R19830
Acronissuspicious
McAfeePWS-Zbot.gen.rn
VBA32BScope.Trojan.Winlock
MalwarebytesTrojan.VUPX.ON
APEXMalicious
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.Kryptik!WrR4UA21G78
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.ABC!tr
AVGFileRepMalware
Cybereasonmalicious.d5d744
PandaTrj/CI.A

How to remove Trojan.VUPX.ON?

Trojan.VUPX.ON removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment