Trojan

Trojan:Win32/Upatre.AM!MTB information

Malware Removal

The Trojan:Win32/Upatre.AM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre.AM!MTB virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Upatre.AM!MTB?


File Info:

name: 1E5B6BC4614CE46AA8DF.mlw
path: /opt/CAPEv2/storage/binaries/a8a8a4f7403adec9f59d83a0cef821c7562498eb28172e639a14a43ddfd56170
crc32: 7982BCDF
md5: 1e5b6bc4614ce46aa8df98c9498c3fa1
sha1: 42a6d0cfaeea23afea960d4b76149f63b238bff4
sha256: a8a8a4f7403adec9f59d83a0cef821c7562498eb28172e639a14a43ddfd56170
sha512: 1552fbd0edb0f57443d9794b81b7730070aeb8f33f962af1081d4d932c2f5d5f30c97932c7257ca7ec8367424a3b06af7d063e95d901de388566eff412b36b0c
ssdeep: 96:SqBLTcceuHnnwR2Ud2ClAhxFKI3qDLCq5agm9XSTEpSlqi9ZZ9i9Xi9i9i9i9i9k:FBEcvnwR2kBAxKYqDL55B36sFSIqp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170128A3D6FD51A76F37BCE7589F651C6AA74B4123D03880D50AB03890823F56EDB0A1E
sha3_384: d61cb06fcaf2e3b0a92fd9bd9f3ddf96199f5fc51dff910e2e790392a2f4bd33aaaafaf07c566be6e34ffc2d70b293d7
ep_bytes: 558bec81ec3808000053565733f656ff
timestamp: 2014-04-26 13:39:01

Version Info:

0: [No Data]

Trojan:Win32/Upatre.AM!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.1e5b6bc4614ce46a
CAT-QuickHealTrojanDownlder.Upatre.MUE.A5
McAfeeGenericATG-FKM!1E5B6BC4614C
CylanceUnsafe
ZillyaDownloader.Small.Win32.76003
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 0055f33b1 )
Cybereasonmalicious.4614ce
BitDefenderThetaGen:NN.ZexaF.34294.auX@aeZCPXii
CyrenW32/S-654ac031!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
ClamAVWin.Downloader.Upatre-6719233-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad3.cxbzvg
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Waski-A [Trj]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareTrojan.Ppatre.Gen.1
TACHYONTrojan/W32.Agent.9866.G
EmsisoftTrojan.Ppatre.Gen.1 (B)
ComodoTrojWare.Win32.TrojanDownloader.Upatre.A@52i1eo
BaiduWin32.Trojan-Downloader.Small.ck
VIPRETrojan-Downloader.Win32.Upatre.a (v)
TrendMicroTROJ_DLOADER.SM3
McAfee-GW-EditionBehavesLike.Win32.Generic.zz
SophosML/PE-A + Mal/EncPk-ACO
IkarusTrojan-Downloader.Win32.Upatre
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojan/Generic.azrvz
MaxSecureTrojan.Upatre.Gen
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.9B9E05
ArcabitTrojan.Ppatre.Gen.1
MicrosoftTrojan:Win32/Upatre.AM!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dloader.R87521
Acronissuspicious
VBA32Trojan.Download
ALYacTrojan.Ppatre.Gen.1
MAXmalware (ai score=80)
MalwarebytesTrojan.Upatre.Generic
TrendMicro-HouseCallTROJ_DLOADER.SM3
RisingDownloader.Agent!1.C06E (CLASSIC)
YandexTrojan.Agent!7+N9QLzSd6g
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_93%
FortinetW32/Waski.A!tr
AVGWin32:Waski-A [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Upatre.AM!MTB?

Trojan:Win32/Upatre.AM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment