Trojan

TrojanDownloader:Win32/Upatre!pz malicious file

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: 1E5070F0F4F9771D5C74.mlw
path: /opt/CAPEv2/storage/binaries/6a0a4a0d741736c4f29e6749a78f2f56a836ba7856009a2905edcf6c3027bffb
crc32: 3D32E662
md5: 1e5070f0f4f9771d5c74ea246117dade
sha1: 732bc4cb9fa29719ff6f5be267bc768c2f6e92bf
sha256: 6a0a4a0d741736c4f29e6749a78f2f56a836ba7856009a2905edcf6c3027bffb
sha512: 6f3a5462dfcf1ee358ea567e564ac57693c6f74fc92adda6d485e9b8c3541d49f26cc092784b6b8b5aa16f55525041b1dd686aaf1a64e25af23feacd9509ab07
ssdeep: 384:Xz8qWI9TtGINz8PUAZL5G2WdLxSiPuVoEfW:XYqTTIINYPJZLOdLxxWhe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E82223C5ED519B2E377CAB6CAF245C7BD65B42239129CCE40CB03850813F66BDA1A1E
sha3_384: 008168a66c43f8e749bb65d402a20db04e57fe51f7fb2c8092f341742710d10851ad39153e0d70c7f185d76f937eaad2
ep_bytes: b800624000ffe088f8a8d46994d9b7f5
timestamp: 2013-09-11 14:39:41

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.DownLoader26.64201
MicroWorld-eScanTrojan.Ppatre.Gen.1
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.lt
McAfeeGenericRXIH-XP!1E5070F0F4F9
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005568151 )
K7GWTrojan ( 005568151 )
Cybereasonmalicious.b9fa29
BitDefenderThetaAI:Packer.5516F9F41E
SymantecDownloader.Upatre!gm
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Small.PRL
APEXMalicious
ClamAVWin.Malware.Ppatre-7113132-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ppatre.Gen.1
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Kryptik!1.BB30 (CLASSIC)
SophosW32/Systro-AB
F-SecureTrojan.TR/Dldr.Small.slalf
ZillyaDownloader.Generic.Win32.8667
TrendMicroTROJ_UPATRE.SMAS
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1e5070f0f4f9771d
EmsisoftTrojan.Ppatre.Gen.1 (B)
IkarusTrojan-Downloader.Win32.Small
MAXmalware (ai score=84)
GDataWin32.Trojan.PSE.H9T46E
JiangminTrojan.Generic.dunym
GoogleDetected
AviraTR/Dldr.Small.slalf
VaristW32/S-c0caa7f2!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Upatre
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.ACC@56yhj8
ArcabitTrojan.Ppatre.Gen.1
ZoneAlarmVHO:Trojan-Downloader.Win32.Waski.gen
MicrosoftTrojanDownloader:Win32/Upatre!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R289382
Acronissuspicious
VBA32Trojan.Downloader
ALYacTrojan.Ppatre.Gen.1
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMAS
TencentTrojan-DL.Win32.Upatre.kaj
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Parite.C
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment