Malware

About “Win32:Downloader-UNP [Drp]” infection

Malware Removal

The Win32:Downloader-UNP [Drp] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Downloader-UNP [Drp] virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Win32:Downloader-UNP [Drp]?


File Info:

name: 42221E808EC658816A1C.mlw
path: /opt/CAPEv2/storage/binaries/d4282fc0eb3053e8ca4ca3ac0c8a7000815b969ddf608d511bbb41e761499e1d
crc32: 9B55B809
md5: 42221e808ec658816a1ca7aca2435cbb
sha1: fbd520ab34fb02fb6ccc0b26b06295fcd13b5a2e
sha256: d4282fc0eb3053e8ca4ca3ac0c8a7000815b969ddf608d511bbb41e761499e1d
sha512: 5a81e0ccf01f4a8fd16976c4035bf86d20b2a057d05d1e8e25ae31d03919ed39637984bc46c9a88fdda4b1cb7191dd98b46cff541e8b4985230a5c5f506c3924
ssdeep: 768:DdtFVLwgb+AsLoP0LJvVHaUEe7+3nCcJLf7Rpu9fWWq53Ewb:DXFVLnJsLrvV1GnCeLf7Rpu9fWWq53j
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EEF23971BAC49A84E81611B0DCF7D6411416BD9D50779A0FBA99FE26F8F338070A2B1F
sha3_384: 9570da74acfc17cf477e188ed19a142b5ac6a44792bc1393eda07a1c09b54317aa4263276ca33103a5aa37c4fb8384b7
ep_bytes: e84b04000050e8bb29000090e9130800
timestamp: 2013-10-29 08:38:25

Version Info:

0: [No Data]

Win32:Downloader-UNP [Drp] also known as:

BkavW32.FamVT.GeND.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.1367334
FireEyeGeneric.mg.42221e808ec65881
ALYacTrojan.GenericKD.1367334
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.142495
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0001140e1 )
K7AntiVirusTrojan ( 0001140e1 )
BaiduWin32.Trojan-Downloader.Small.ck
VirITTrojan.Win32.Banker.YB
CyrenW32/Trojan.GKSI-3564
SymantecDownloader
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
ClamAVWin.Downloader.Upatre-5744087-0
KasperskyTrojan-Spy.Win32.Zbot.qnlf
BitDefenderTrojan.GenericKD.1367334
NANO-AntivirusTrojan.Win32.Zbot.cnbsms
AvastWin32:Downloader-UNP [Drp]
TencentTrojan-Downloader.Win32.Waski.16000151
Ad-AwareTrojan.GenericKD.1367334
EmsisoftTrojan.GenericKD.1367334 (B)
ComodoTrojWare.Win32.Injector.KXE@5415yx
DrWebTrojan.Siggen.65294
VIPRETrojan.GenericKD.1367334
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nm
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Agent-AEIK
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojanSpy.Zbot.dxgz
WebrootW32.Rogue.Gen
AviraTR/Dldr.Small.aab.7
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASBOL.C6E4
ArcabitTrojan.Generic.D14DD26
MicrosoftTrojanDownloader:Win32/Dungees.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.C212277
McAfeeTrojan-FDEJ!42221E808EC6
VBA32BScope.Trojan.Inject
MalwarebytesTrojan.Email
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLASSIC)
IkarusTrojan.Win32.Badur
MaxSecureTrojan.Upatre.Gen
FortinetW32/Zbot.QNLF!tr
BitDefenderThetaGen:NN.ZexaF.34786.cqX@ay2PRbji
AVGWin32:Downloader-UNP [Drp]
Cybereasonmalicious.08ec65
PandaGeneric Malware

How to remove Win32:Downloader-UNP [Drp]?

Win32:Downloader-UNP [Drp] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment