Emails with subject Part 0, Part 1, Part 2, Part 3,… contains Trojan/Win32.Upatre


MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject like:

Part 0
Part 1
Part 2
Part 3
Part 4
Part 5
Part 6
Part 7
Part 8
Part 9

This email is send from spoofed address and has the following very short body:

I will send final part also

The attached file 9ZENF7xtLTtz.zip contains the 48 kB large file part_DGStyutyuertQ34G_xpdf.exe. The combinations in the filenames will vary with each email.

The trojan is known as Trojan/Win32.Upatre, W32/Upatre.E3.gen!Eldorado, TR/Crypt.ZPACK.Gen or Downloader.Upatre!gen9.

At the time of writing, 9 of the 57 AV engines did detect the trojan at Virus Total.

Use the Virus Total or Malwr for more detailed information.
SHA256: b69e2ba2cb7b7d901060366ef0876a00894733d2e028d6fb38e9d5bc112e20fe

One thought on “Emails with subject Part 0, Part 1, Part 2, Part 3,… contains Trojan/Win32.Upatre

Comments are closed.