Trojan

Trojan.Win32.ShipUp.bpv (file analysis)

Malware Removal

The Trojan.Win32.ShipUp.bpv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.ShipUp.bpv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.ShipUp.bpv?


File Info:

name: 5F8A1EB457B6F828E6F3.mlw
path: /opt/CAPEv2/storage/binaries/cf875fa3e577024e293d2a04a06c98fd60addba83047c20892dae2b6bd8f6afd
crc32: A84CC650
md5: 5f8a1eb457b6f828e6f31ac41c1900c5
sha1: b66ee0596d7f3273437eb5ec20d9b56c6e154366
sha256: cf875fa3e577024e293d2a04a06c98fd60addba83047c20892dae2b6bd8f6afd
sha512: 9f7a28f2c41ffc4350fe263f4deff5866588d3edc9821d68924b276501c5b17bcd446e7aca9165a8b8ea498be7a07fecbe6658a1bf924c0d99614865ad50dfaf
ssdeep: 3072:7Og+a5MVqLgWj7ZmCrYoFL22JcgeLfKidjQVJWXoI:7Oj2gW3Zk8L2uc3LfKYcm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EBE302229075DA46C563053AD53863FCC8366C7A2F779C6BBC08F34B8E359E89A94183
sha3_384: e895209eb5203a12c96b5c37618d7c983000ca4a5539c2cbccbdfa2ca078872d39f3b4413eb203ea0d1ea71b35b497c1
ep_bytes: 60be009043008dbe0080fcff5783cdff
timestamp: 2013-03-30 11:31:42

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Trojan.Win32.ShipUp.bpv also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.95851
SkyhighBehavesLike.Win32.PWSZbot.cc
McAfeePWS-Zbot-FATG!E54A29A80F19
MalwarebytesTrojan.Dropper
ZillyaTrojan.ShipUp.Win32.16201
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.457b6f
BaiduWin32.Trojan.Agent.eq
SymantecPacked.Generic.459
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.AXTR
APEXMalicious
TrendMicro-HouseCallTROJ_KRYPTK.SMAD
ClamAVWin.Packed.Shipup-10025547-0
KasperskyTrojan.Win32.ShipUp.bpv
BitDefenderTrojan.GenericKDZ.95851
NANO-AntivirusTrojan.Win32.ShipUp.bqoayj
AvastWin32:Zbot-UQA [Trj]
TencentTrojan.Win32.Kryptik.16000652
TACHYONTrojan/W32.Shipup.227856
SophosMal/EncPk-AIT
GoogleDetected
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Packed.24096
VIPRETrojan.GenericKDZ.95851
TrendMicroTROJ_KRYPTK.SMAD
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.5f8a1eb457b6f828
EmsisoftTrojan.GenericKDZ.95851 (B)
IkarusTrojan.Win32.ShipUp
JiangminTrojan/ShipUp.ir
VaristW32/Kryptik.JSF.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Zbot!pz
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
ArcabitTrojan.Generic.D1766B
ZoneAlarmTrojan.Win32.ShipUp.bpv
GDataWin32.Trojan.PSE.16MG4RL
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Kryptk.R640506
Acronissuspicious
VBA32Trojan.ShipUp
ALYacTrojan.GenericKDZ.95851
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/Hexas.HEU
RisingTrojan.Agent!8.B1E (TFE:5:bs35bzlU9pL)
YandexTrojan.GenAsa!RZsp6sC8eys
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYUW!tr
BitDefenderThetaGen:NN.ZexaF.36802.jmLfa8ZtCMac
AVGWin32:Zbot-UQA [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.ShipUp.bpv?

Trojan.Win32.ShipUp.bpv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment