Trojan

TrojanDownloader:Win32/Upatre!pz (file analysis)

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: 2FB3268E4FA60026ACD6.mlw
path: /opt/CAPEv2/storage/binaries/4ce47e152f55729a8234aad4921a7f6ec850b96a45718311b981f5ccd1d3598e
crc32: 9DE31C8B
md5: 2fb3268e4fa60026acd69812b1afd71f
sha1: 54944a60b84aa7d08c0d49814e8729ae0e9a02b0
sha256: 4ce47e152f55729a8234aad4921a7f6ec850b96a45718311b981f5ccd1d3598e
sha512: bdc533fc94384e28b2acf7ad45f418b7fb5c857a534613167f30503257c0ee05460fdebbdd5c81c65f5fd3cc648e452c8f3000eb92c6dbd3ede285766996fe9f
ssdeep: 192:jn9FwXnwR2bsfunHMnHFb1emUVyKsal6lvjDY3Vb7IdLC1F:zOnwR2tHMnHFAm5KFl6lvYh7eLIF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133D243396ED51573E3BBCAB6C5F645C6FA64B1233A029C0E50DB03850C13F57AD92A1E
sha3_384: 32145d6be85c25df9bd23d51c3c997674c8ffa0e445b90ab855b4fc82f38dfc73d2eefb75e2a1c0189a728121c99ff03
ep_bytes: 558bec81ec3c04000053565733f656ff
timestamp: 2013-08-29 14:03:58

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Upatre.1j!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop22.59242
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.2fb3268e4fa60026
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Dropper.nz
McAfeeGenericRXUB-BS!2FB3268E4FA6
Cylanceunsafe
ZillyaTrojan.Waski.Win32.5821
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0048f6391 )
AlibabaTrojanDownloader:Win32/Upatre.d817c763
K7GWTrojan-Downloader ( 0048f6391 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36608.buX@ae9PCLei
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.A
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.Upatre-10009275-0
KasperskyHEUR:Trojan.Win32.Bublik.pef
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.Waski.jypgxs
AvastWin32:Upatre-X [Trj]
RisingDownloader.Agent!1.E264 (CLASSIC)
SophosTroj/Upatre-YW
F-SecureTrojan.TR/Crypt.XPACK.Gen7
BaiduWin32.Trojan-Downloader.Waski.k
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Ppatre.Gen.1 (B)
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojan.Generic.hrhyb
VaristW32/Agent.GYF.gen!Eldorado
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=88)
Antiy-AVLTrojan[Downloader]/Win32.Upatre
Kingsoftmalware.kb.a.998
MicrosoftTrojanDownloader:Win32/Upatre!pz
XcitiumTrojWare.Win32.TrojanDownloader.Small.CDC@8mzsfr
ArcabitTrojan.Ppatre.Gen.1
ViRobotTrojan.Win.Z.Upatre.30924
ZoneAlarmHEUR:Trojan.Win32.Bublik.pef
GDataWin32.Trojan-Downloader.Upatre.BJ
GoogleDetected
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacTrojan.Ppatre.Gen.1
MalwarebytesMalware.AI.1414193334
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentTrojan.Win32.Downloader.wb
YandexTrojan.GenAsa!xjw/xZS1BKE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Dloader.ADC!tr
AVGWin32:Upatre-X [Trj]
Cybereasonmalicious.0b84aa
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment