Trojan

About “Trojan.Win32.ShipUp.deon” infection

Malware Removal

The Trojan.Win32.ShipUp.deon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.ShipUp.deon virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.ShipUp.deon?


File Info:

name: 27E6405C30A0C0FC6C5D.mlw
path: /opt/CAPEv2/storage/binaries/17dee368fd2faf8c0677291fbbefee6a283102b47b62cbce1ceb0e887efa7b8c
crc32: ED33825C
md5: 27e6405c30a0c0fc6c5d87dc8629f3ee
sha1: 2a51b43fdd538996d140e7f296fef0b718162698
sha256: 17dee368fd2faf8c0677291fbbefee6a283102b47b62cbce1ceb0e887efa7b8c
sha512: 600ab8be4b8bfd8dc8f3337c89454876e10b353c51669657e1ba58ded7b8f25d7a30c09355312e8335c3a56b3ed689a91cff29cdec078d1bd9b799fd022792cf
ssdeep: 6144:7FrGHs9qWF2zw6r4FNpzBdD+4LVxk/NBE:7FSMIWF2E6sFNpzBxN4BE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E1346A87623969BFC2B58BB20FACCC3060F9AD855760D3B13CE2F59E21D577914AC819
sha3_384: fd06bab6d09a772213450e53fdb88fd5c58d29c0c6d83180fe4b40ab9447992f8203ae2ec8b68fa5cfbc132df7534ec5
ep_bytes: 558bec51689c0100006a00ff1524c040
timestamp: 2013-04-10 12:28:14

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Trojan.Win32.ShipUp.deon also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
SkyhighBehavesLike.Win32.PWSZbot.dh
McAfeeGeneric-FAGO!27E6405C30A0
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.ShipUp.Win32.16111
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004cf6b81 )
K7GWTrojan ( 004cf6b81 )
Cybereasonmalicious.c30a0c
BaiduWin32.Trojan.Agent.eq
VirITI-WORM.Beagle.DM
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AYMY
APEXMalicious
TrendMicro-HouseCallTROJ_KRYPTK.SMAD
ClamAVWin.Trojan.Redirect-6055402-0
KasperskyTrojan.Win32.ShipUp.deon
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusVirus.Win32.Sality.bgiylc
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Gepys-E [Trj]
TencentTrojan.Win32.Kryptik.16000289
EmsisoftTrojan.Ransom.Cerber.1 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Redirect.140
VIPRETrojan.Ransom.Cerber.1
TrendMicroTROJ_KRYPTK.SMAD
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.27e6405c30a0c0fc
SophosTroj/Gyepis-A
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=82)
JiangminTrojan/Generic.avpsx
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Zbot.JC.gen!Eldorado
Antiy-AVLTrojan/Win32.ShipUp
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDropper:Win32/Gepys!pz
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
ArcabitTrojan.Ransom.Cerber.1
ZoneAlarmTrojan.Win32.ShipUp.deon
GDataWin32.Trojan.PSE.1A06N6
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.ShipUp.R639187
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36802.oK1@aaNr1Znc
ALYacTrojan.Ransom.Cerber.1
VBA32BScope.Malware-Cryptor.Zbot.2413
Cylanceunsafe
PandaTrj/Hexas.HEU
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.GenAsa!LKbQEYuJY4g
IkarusTrojan-Dropper.Win32.Gepys
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYUW!tr
AVGWin32:Gepys-E [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.ShipUp.deon?

Trojan.Win32.ShipUp.deon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment