Trojan

Trojan:Win32/Upatre.MG!MTB (file analysis)

Malware Removal

The Trojan:Win32/Upatre.MG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Upatre.MG!MTB virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Upatre.MG!MTB?


File Info:

name: 0418918CE9C6673BDEBE.mlw
path: /opt/CAPEv2/storage/binaries/f6bd94a68978e69e16a5d5dc5de2d143ef1628f73e3effac855ae5bbe0ffd205
crc32: 356F4167
md5: 0418918ce9c6673bdebee999116bcf0f
sha1: aad1d2b088f22029a04a67e82bde3379ff0742cc
sha256: f6bd94a68978e69e16a5d5dc5de2d143ef1628f73e3effac855ae5bbe0ffd205
sha512: f6be3e347ba9b40bbbdae5dc492bc814d9073c8e6d2b8ad516ec0a35a0797dff0afc87c29521674b8c1bb9d771e60165ae02fb1b2548793deb77e43661c22e5d
ssdeep: 384:tQ7ruB+UthhIdi3ZSz+EJxuVczXKSuSHYGSjyc3bcXVYpT0u1GcfMD01j6QITeQl:ZPt8dH5JZTKSu7ycEfcTu7zVs0ei2A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E6E3FE387ED56672E37BCEB5C6F642C6F934B4227D02D80D40DA47850823F5AEDA1A1E
sha3_384: 31a02ae8639a777073319dff50d83478d18b2304b6913e670645108ddf378fd32a719c3a9ca3d04175827d5b72d52bb2
ep_bytes: 558bec6aff6850300004684019000464
timestamp: 2014-03-17 18:46:26

Version Info:

0: [No Data]

Trojan:Win32/Upatre.MG!MTB also known as:

BkavW32.AIDetectMalware
DrWebTrojan.DownLoader9.48808
MicroWorld-eScanGen:Variant.Jaik.63945
CAT-QuickHealTrojan.GenericPMF.S31032585
SkyhighBehavesLike.Win32.Infected.cz
McAfeeGeneric-FANY!0418918CE9C6
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Jaik.63945
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.088f22
ArcabitTrojan.Jaik.DF9C9
BitDefenderThetaGen:NN.ZexaF.36680.imY@aW34oLh
VirITTrojan.Win32.Upatre.AO
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.B
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Upatre-9934559-0
KasperskyHEUR:Trojan.Win32.Tremp.gen
BitDefenderGen:Variant.Jaik.63945
NANO-AntivirusTrojan.Win32.Crypted.cvonkg
AvastWin32:Trojan-gen
TencentTrojan.Win32.Generic.ta
EmsisoftGen:Variant.Jaik.63945 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
BaiduWin32.Trojan-Downloader.Waski.l
ZillyaDownloader.Waski.Win32.50916
SophosTroj/Wonton-AH
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojan/Bublik.gxy
WebrootW32.Trojan.Dropper
VaristW32/Upatre.NC.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Bublik
Kingsoftmalware.kb.b.999
XcitiumTrojWare.Win32.Bublik.SKI@59ow1o
MicrosoftTrojan:Win32/Upatre.MG!MTB
ViRobotTrojan.Win32.Bublik.26112.A
ZoneAlarmHEUR:Trojan.Win32.Tremp.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
GoogleDetected
AhnLab-V3Downloader/Win.Upatre.R536865
Acronissuspicious
VBA32Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.21752
RisingTrojan.Kryptik!1.DBE3 (CLASSIC)
YandexTrojan.GenAsa!kn7uOjKO7pI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.BXKM!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Upatre.MG!MTB?

Trojan:Win32/Upatre.MG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment