Collection of Upatre Samples ( alpha version)

Config File for 0e58f183180ff9697c1f1ac7910125d0

md5
0e58f183180ff9697c1f1ac7910125d0
source
virusshare
link
download.4n6?sample=cac6598fc9d85e9fd971b32581f7f664c7da52cbad0f935638b9b73cbbfcc224
malware_name
wavitoh.exe
temp_file
scandate
2015-09-04 22:03:14
parsed
2015-09-15 10:09:41
decrypt_keys
12be8b2d
check_keys
c2_server
93.185.4.90
baseport
9587
useragent
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.34 (KHTML, like Gecko) Chrome/43.0.2455.81 Safari/535.34
payload_format
sim
old
0
clientip
checkip.dyndns.org
nr_targets
51
nr_delivery_sites
50
nr_delivery_sites_online
23
nr_payloads
1
ksa
dec
pdir
Q20
delivered payloads:
1
4198992ab8d75c54cd5e0db597c1c56f
downloaded
2015-09-15 10:09:41
scanned (on VT)
2015-09-15 08:07:43
positives
14 / 56
detected as
Malwarebytes
Trojan.Agent.ED
Zillya
Trojan.Battdil.Win32.299
K7GW
Trojan ( 004c9c7b1 )
K7AntiVirus
Trojan ( 004c9c7b1 )
ESET-NOD32
Win32/Battdil.AK
Avast
Win32:Dyre-K [Trj]
Kaspersky
HEUR:Trojan.Win32.Generic
NANO-Antivirus
Trojan.Win32.ZPACK.dvvaab
Comodo
TrojWare.Win32.TrojanDownloader.Upatre.MAUA
VIPRE
Trojan-Downloader.Win32.Upatre.tfl (v)
Microsoft
PWS:Win32/Dyzap.T
AVware
Trojan-Downloader.Win32.Upatre.tfl (v)
Fortinet
W32/Monlin.A!tr
AVG
Ransomer.JJR
not detected by:
Bkav, MicroWorld-eScan, nProtect, CMC, CAT-QuickHeal, McAfee, SUPERAntiSpyware, TheHacker, Alibaba, Agnitum, F-Prot, Symantec, TrendMicro-HouseCall, ClamAV, GData, BitDefender, ViRobot, ByteHero, Tencent, Ad-Aware, Emsisoft, F-Secure, DrWeb, TrendMicro, McAfee-GW-Edition, Sophos, Cyren, Jiangmin, Antiy-AVL, Kingsoft, Arcabit, AegisLab, AhnLab-V3, TotalDefense, ALYac, VBA32, Panda, Zoner, Rising, Ikarus, Baidu-International, Qihoo-360
delivery sites:
1
https://24.220.92.193/t20.zip
2
https://176.36.251.208/t20.zip
3
https://67.221.195.6/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
4
https://69.163.81.211/t20.zip
5
https://216.254.231.11/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
6
https://24.33.131.116/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
7
https://104.174.123.66/t20.zip
8
https://72.230.82.80/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
9
https://173.248.31.6/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
10
https://69.9.204.114/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
11
https://188.255.239.34/t20.zip
12
https://69.144.171.44/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
13
https://65.33.236.173/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
14
https://98.214.11.253/t20.zip
15
https://24.148.217.188/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
16
https://173.216.247.74/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
17
https://77.48.30.156/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
18
https://37.57.144.177/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
19
https://95.143.141.50/t20.zip
20
https://87.249.142.189/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
21
https://85.135.104.170/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
22
https://76.84.81.120/t20.zip
23
https://84.246.161.47/t20.zip
24
https://217.168.210.122/t20.zip
25
https://68.70.242.203/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
26
https://64.111.36.52/t20.zip
27
https://178.222.250.35/t20.zip
28
https://94.154.107.172/t20.zip
29
https://194.106.166.22/t20.zip
30
https://188.255.243.105/t20.zip
31
https://188.255.236.184/t20.zip
32
https://98.181.17.39/t20.zip
33
https://67.207.229.215/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
34
https://67.206.96.68/t20.zip
35
https://67.222.197.54/t20.zip
36
https://67.22.167.163/t20.zip
37
https://209.40.238.170/t20.zip
38
https://64.111.42.64/t20.zip
39
https://72.174.240.148/t20.zip
40
https://63.248.156.246/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
41
https://72.175.10.116/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
42
https://208.117.68.78/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
43
https://162.153.189.143/t20.zip
44
https://72.171.9.146/t20.zip
45
https://67.222.201.61/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
46
https://209.27.49.117/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
47
https://67.222.201.222/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
48
https://109.236.121.91/t20.zip
49
https://203.129.197.50/t20.zip
4198992ab8d75c54cd5e0db597c1c56f
50
https://45.64.176.132/t20.zip