Trojan

What is “Trojan.Win32.ShipUp.bpo”?

Malware Removal

The Trojan.Win32.ShipUp.bpo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.ShipUp.bpo virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.ShipUp.bpo?


File Info:

name: A81D0A26B1F9B28351F4.mlw
path: /opt/CAPEv2/storage/binaries/54d839c1365a6845f207b6a1ecfb35f9a4218782d012ae70972ecbfc7844dc2a
crc32: E6DB68FC
md5: a81d0a26b1f9b28351f4a6b78342674e
sha1: 766c63b0f73c252fac97382379e19f06296bfd72
sha256: 54d839c1365a6845f207b6a1ecfb35f9a4218782d012ae70972ecbfc7844dc2a
sha512: 37eb9396a8d6bdfbfeed01ecd9296638cf9262ea88c1576adee01330fa9a1a13c21bac3209703f313605a1119f8885db5bf0bdb446f09bab5b5f5169bd415710
ssdeep: 12288:tBXXXXXXXXXAXX7hx6UhqX3Z1Xok3IpaZQ10hSnA/Qz5wYGfW:sx6Uo51j3IsprI7GfW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T148C4F0DFC157D323ECC56078BBA580F7A67D3B54ED83568A40D0EB44AE4CA88772496C
sha3_384: 5e472e574659a7ac51b4a2d6df0b62d7e5eedfa3f1c1e507a1ff7ae8c6599c4fab7f058035100948a9dbc6a6678b4420
ep_bytes: 558bec5155c745fc5f010000c745fc5f
timestamp: 2013-03-29 06:28:14

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Trojan.Win32.ShipUp.bpo also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.Redirect.140
MicroWorld-eScanGen:Variant.Ransom.TorrentLocker.92
FireEyeGeneric.mg.a81d0a26b1f9b283
SkyhighBehavesLike.Win32.PWSZbot.hc
McAfeeGenericRXCQ-PF!A81D0A26B1F9
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.4663256
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.Ky3@aChdnwoc
VirITTrojan.Win32.Generic.ACYF
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AXRD
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.ShipUp.bpo
BitDefenderGen:Variant.Ransom.TorrentLocker.92
NANO-AntivirusTrojan.Win32.ShipUp.bqoadx
AvastWin32:Agent-ARAC [Trj]
TencentTrojan.Win32.Shipup.xe
EmsisoftGen:Variant.Ransom.TorrentLocker.92 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Trojan.Agent.eq
VIPREGen:Variant.Ransom.TorrentLocker.92
TrendMicroTROJ_KRYPTK.SMAD
Trapminemalicious.high.ml.score
SophosMal/Zbot-FG
IkarusTrojan.Win32.ShipUp
JiangminTrojan.ShipUp.egs
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLGrayWare/Win32.Generic
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Zbot!pz
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
ArcabitTrojan.Ransom.TorrentLocker.92
ZoneAlarmTrojan.Win32.ShipUp.bpo
GDataWin32.Trojan.PSE.1ETBRXH
VaristW32/Zbot.JC.gen!Eldorado
AhnLab-V3Trojan/Win.ShipUp.R639660
Acronissuspicious
VBA32BScope.Trojan.ShipUp
ALYacGen:Variant.Ransom.TorrentLocker.92
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/Hexas.HEU
TrendMicro-HouseCallTROJ_KRYPTK.SMAD
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.WebSpoof.Gen.AL
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYTK!tr
AVGWin32:Agent-ARAC [Trj]
Cybereasonmalicious.6b1f9b
DeepInstinctMALICIOUS

How to remove Trojan.Win32.ShipUp.bpo?

Trojan.Win32.ShipUp.bpo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment