Trojan

What is “TrojanDownloader:Win32/Upatre!pz”?

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: BA34BD23A002AF04023F.mlw
path: /opt/CAPEv2/storage/binaries/2eb9432d8b1006e95d22a6a3055de4f75dcfe682ef1d199d309c7e3f9155b305
crc32: B54F1B97
md5: ba34bd23a002af04023f1c3e5eca47dd
sha1: 2db043f58dd18fbae3f0e5b63179cd4c99f847d9
sha256: 2eb9432d8b1006e95d22a6a3055de4f75dcfe682ef1d199d309c7e3f9155b305
sha512: c655531354fdd160141a8a11b2a4f3ea1547787063e2664a5caac2d973605a51e32ed81bb1226241d76064e5311eba983090428bbc5f7b920fa9a48c1ec67344
ssdeep: 192:WHO6V6CXZSYp0aiZni7PJPydYvVnD2EoxzT6zuPzmhUQ4on:W6CpSYp0ai1+PxWQ4EoF0IzmCQ4on
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D17268786ED92576E3BBCA76C5F651C7FD34B4223916980D40DB43840823F66EDA0B2E
sha3_384: 5ad74a486c25b7b37fd1b4e27292d89a2940d8ea23c00947c237577b687ab3f20a444f9871bc6b3a07f980a99e8e3b25
ep_bytes: 558becb83c200000e893030000535657
timestamp: 2013-09-11 14:39:41

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.94601
FireEyeGeneric.mg.ba34bd23a002af04
CAT-QuickHealDownldr.Upatre.S3306061
SkyhighBehavesLike.Win32.Downloader.lz
ALYacTrojan.GenericKDZ.94601
Cylanceunsafe
VIPRETrojan.GenericKDZ.94601
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderTrojan.GenericKDZ.94601
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.58dd18
BitDefenderThetaGen:NN.ZexaF.36792.bmY@aGuejGf
VirITTrojan.Win32.Upatre.BT
SymantecDownloader.Upatre!gm
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Small.PRL
APEXMalicious
ClamAVWin.Malware.Bavs-6804154-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
NANO-AntivirusTrojan.Win32.DownLoad3.cqsjfu
RisingDownloader.Agent!1.E264 (CLASSIC)
EmsisoftTrojan.GenericKDZ.94601 (B)
BaiduWin32.Trojan-Downloader.Waski.k
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader26.64201
ZillyaTrojan.Bublik.Win32.24463
TrendMicroTROJ_GEN.R03BC0CK623
Trapminemalicious.high.ml.score
SophosTroj/Upatre-YJ
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
JiangminTrojanDownloader.Genome.acpr
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/S-c2fca85b!Eldorado
Antiy-AVLVirus/Win32.Expiro.imp
Kingsoftmalware.kb.b.1000
MicrosoftTrojanDownloader:Win32/Upatre!pz
XcitiumTrojWare.Win32.TrojanDownloader.Small.PRN@7tcee6
ArcabitTrojan.Generic.D17189
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R234120
Acronissuspicious
McAfeeDownloader-FBRM!BA34BD23A002
DeepInstinctMALICIOUS
VBA32Trojan.Delf
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0CK623
TencentTrojan-Downloader.Win32.Waski.16000151
YandexTrojan.GenAsa!LXiB97J6ZtU
IkarusTrojan-Downloader.Win32.Small
MaxSecureDownloader.Upatre.a
FortinetW32/Tiny.NIV!tr
AVGWin32:Downloader-WID [Trj]
AvastWin32:Downloader-WID [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment