Trojan

Trojan:Win32/Upatre.ACM!MTB (file analysis)

Malware Removal

The Trojan:Win32/Upatre.ACM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre.ACM!MTB virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Upatre.ACM!MTB?


File Info:

name: 2F2828B5E21FBCE5A938.mlw
path: /opt/CAPEv2/storage/binaries/77f0a95b761fdad3f5c815dac2cf4f9fbcc9c8865b2c57b7cc4baceba1eba09a
crc32: 904C6EFC
md5: 2f2828b5e21fbce5a938e4c83df5e529
sha1: 4332d3ac6891e78653a79fe120c2cd634add3977
sha256: 77f0a95b761fdad3f5c815dac2cf4f9fbcc9c8865b2c57b7cc4baceba1eba09a
sha512: a17c2fb17cbf6fd306c3281ec42facfb7ec5c0045240d96bf6bc5adcaa8bcc99747e2716b93f7863ea035b46e7f666c24e712cc8b4904d3ee3d77827f3867798
ssdeep: 192:X4NPnwR2xVk6tvSDmE4BArmf7PXHBnSuQLhOCHJxCvo+6zN3ctF0:XaPnwR2jk3OzPXhCJx8o+8N3/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15C92C33C5AF51676E7BBCEB685F651C6B934B4227D02D80D409A43880823F66EDB0B1F
sha3_384: d0a7f57b7ab0c878562f591851a8270eabbff43b6770373d4fa69f2ccc8b8d1150b69e590159b3f3e9cdce7d87d1fbd0
ep_bytes: 558bec81ec3c08000053565733f656ff
timestamp: 2013-10-09 06:59:08

Version Info:

0: [No Data]

Trojan:Win32/Upatre.ACM!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.74346
FireEyeGeneric.mg.2f2828b5e21fbce5
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.GenericKDZ.74346
CylanceUnsafe
VIPRETrojan-Downloader.Win32.Upatre.a (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 0048f6391 )
Cybereasonmalicious.5e21fb
BaiduWin32.Trojan-Downloader.Waski.k
CyrenW32/Upatre.KG.gen!Eldorado
SymantecDownloader.Upatre!gm
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Downloader.Upatre-7598844-0
KasperskyVHO:Trojan-Downloader.Win32.Genome.gen
BitDefenderTrojan.GenericKDZ.74346
NANO-AntivirusTrojan.Win32.DownLoad3.cnbuup
AvastWin32:Downloader-WID [Trj]
RisingDownloader.Agent!1.C06E (CLASSIC)
Ad-AwareTrojan.GenericKDZ.74346
SophosML/PE-A + Mal/EncPk-ACO
ComodoTrojWare.Win32.TrojanDownloader.Small.CDC@8mzsfr
DrWebTrojan.DownLoad3.28161
ZillyaTrojan.Generic.Win32.902291
TrendMicroTROJ_UPATRE.SMAZ
McAfee-GW-EditionBehavesLike.Win32.Generic.lz
EmsisoftTrojan.GenericKDZ.74346 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojan/Generic.azrzv
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.F96F0A
MicrosoftTrojan:Win32/Upatre.ACM!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
McAfeeGenericATG-FKM!2F2828B5E21F
MAXmalware (ai score=83)
VBA32Trojan.Downloader
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
TencentTrojan.Win32.BitCoinMiner.la
YandexTrojan.GenAsa!xjw/xZS1BKE
IkarusTrojan-Downloader.Win32.Upatre
eGambitUnsafe.AI_Score_96%
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaF.34294.bqY@a4diuRo
AVGWin32:Downloader-WID [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan:Win32/Upatre.ACM!MTB?

Trojan:Win32/Upatre.ACM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment