Collection of Upatre Samples ( alpha version)

Config File for 03721dc899125df9dba81f6d8d8997cf

md5
03721dc899125df9dba81f6d8d8997cf
source
malwr
link
https://malwr.com/analysis/MDViYzNhNGMwMzEyNGU0YzgzYzlhM2I0OWY5YzRlM2E/
malware_name
nlibzar.exe
temp_file
bwtBBCB.tmp
scandate
2015-04-12 20:53:11
parsed
2015-07-26 05:59:37
decrypt_keys
327a32f4
check_keys
14202409
c2_server
141.105.141.87
baseport
9587
useragent
Mazilla/5.0
payload_format
reg
old
0
clientip
checkip.dyndns.org
nr_targets
3
nr_delivery_sites
2
nr_delivery_sites_online
0
nr_payloads
0
ksa
pdir
0704uk11
delivered payloads:
no payloads delivered when checked
delivery sites:
1
https://encontrosonline.net/wp-includes/css/mandoc1.pdf
2
https://enercomis.com/mandoc1.pdf