Upatre Downloader Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
It is typically delivered via spam email containing either an attachment or link to a hosting site. Various exploit kits have also been used as an infection vector for Upatre. Once installed, it will disable security services on Windows and Internet Explorer before spawning an instance of msiexec.exe and injecting itself into the process. Upatre also makes heavy use of code obfuscation and custom string encoding to prevent analysis.
Upatre uses encrypted .bit top-level domains for its command and control infrastructure to prevent removal by authorities. HTTP POST requests are used to retrieve the intended secondary malware as well as to transfer any data collected by Upatre to the threat actors.
Remediation advice
To prevent and detect an infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:56 pm