Collection of Upatre Samples ( alpha version)

Config File for 05466d93bcfa75829b0b9cd2904e0b90

md5
05466d93bcfa75829b0b9cd2904e0b90
source
virusshare
link
download.4n6?sample=17cacb8e5f1b0556264c59a61924dda464f59b8e4d78b285bcffe0ccf0d9705b
malware_name
dylkemi.exe
temp_file
scandate
2015-09-05 09:55:50
parsed
2015-09-15 11:56:01
decrypt_keys
31ab6e57
check_keys
c2_server
93.185.4.90
baseport
9587
useragent
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:38.0) Gecko/20100101 Firefox/38.0
payload_format
sim
old
0
clientip
checkip.dyndns.org
nr_targets
51
nr_delivery_sites
50
nr_delivery_sites_online
22
nr_payloads
1
ksa
dec
pdir
TACH2
delivered payloads:
1
f2f631c81ff4ab91505cb927ed6e3c94
downloaded
2015-09-15 11:56:01
scanned (on VT)
2015-09-15 09:54:01
positives
12 / 57
detected as
Zillya
Trojan.Kryptik.Win32.764687
K7AntiVirus
Trojan ( 004c97a01 )
K7GW
Trojan ( 004c97a01 )
ESET-NOD32
a variant of Win32/Kryptik.DRKS
Avast
Win32:Dyre-K [Trj]
NANO-Antivirus
Trojan.Win32.DownLoader15.dvruhq
DrWeb
Trojan.DownLoader15.20317
Antiy-AVL
Trojan/Win32.TSGeneric
Microsoft
VirTool:Win32/Obfuscator.AOE
Fortinet
W32/Kryptik.DRKS!tr
AVG
Crypt4.BPDH
Panda
Trj/Genetic.gen
not detected by:
Bkav, TotalDefense, MicroWorld-eScan, nProtect, CMC, CAT-QuickHeal, McAfee, Malwarebytes, AegisLab, Alibaba, TheHacker, Agnitum, F-Prot, Symantec, TrendMicro-HouseCall, ClamAV, GData, Kaspersky, BitDefender, SUPERAntiSpyware, Tencent, Ad-Aware, Sophos, Comodo, F-Secure, VIPRE, TrendMicro, McAfee-GW-Edition, Emsisoft, Cyren, Jiangmin, Avira, Kingsoft, Arcabit, ViRobot, AhnLab-V3, ByteHero, ALYac, AVware, VBA32, Baidu-International, Zoner, Rising, Ikarus, Qihoo-360
delivery sites:
1
https://24.220.92.193/ic2.png
2
https://176.36.251.208/ic2.png
3
https://67.221.195.6/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
4
https://69.163.81.211/ic2.png
5
https://216.254.231.11/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
6
https://24.33.131.116/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
7
https://104.174.123.66/ic2.png
8
https://72.230.82.80/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
9
https://173.248.31.6/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
10
https://69.9.204.114/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
11
https://188.255.239.34/ic2.png
12
https://69.144.171.44/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
13
https://65.33.236.173/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
14
https://98.214.11.253/ic2.png
15
https://24.148.217.188/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
16
https://173.216.247.74/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
17
https://77.48.30.156/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
18
https://37.57.144.177/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
19
https://95.143.141.50/ic2.png
20
https://194.228.203.19/ic2.png
21
https://87.249.142.189/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
22
https://85.135.104.170/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
23
https://76.84.81.120/ic2.png
24
https://84.246.161.47/ic2.png
25
https://217.168.210.122/ic2.png
26
https://68.70.242.203/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
27
https://64.111.36.52/ic2.png
28
https://178.222.250.35/ic2.png
29
https://94.154.107.172/ic2.png
30
https://194.106.166.22/ic2.png
31
https://188.255.243.105/ic2.png
32
https://188.255.236.184/ic2.png
33
https://98.181.17.39/ic2.png
34
https://67.207.229.215/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
35
https://67.206.96.68/ic2.png
36
https://67.222.197.54/ic2.png
37
https://69.8.50.85/ic2.png
38
https://67.22.167.163/ic2.png
39
https://209.40.238.170/ic2.png
40
https://64.111.42.64/ic2.png
41
https://72.174.240.148/ic2.png
42
https://63.248.156.246/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
43
https://72.175.10.116/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
44
https://73.142.130.81/ic2.png
45
https://208.117.68.78/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
46
https://162.153.189.143/ic2.png
47
https://72.171.9.146/ic2.png
48
https://67.222.201.61/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
49
https://209.27.49.117/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94
50
https://67.222.201.222/ic2.png
f2f631c81ff4ab91505cb927ed6e3c94