Collection of Upatre Samples ( alpha version)

Config File for 296690695b13cb5a384e8fa73dc727b1

md5
296690695b13cb5a384e8fa73dc727b1
source
malwr
link
https://malwr.com/analysis/M2VlOWY4YjE2ZTY0NDkxN2FlZjU0ZGIyYTRlMjc0Mzk/
malware_name
begbakel.exe
temp_file
scandate
2015-08-03 23:51:02
parsed
2015-08-04 19:18:35
decrypt_keys
15ae8b62
check_keys
c2_server
93.185.4.90
baseport
9587
useragent
Mozilla/5.0 (Windows NT 6.1;WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2272.89 Safari/537.36 OPR/28.0.1750.48
payload_format
sim
old
0
clientip
checkip.dyndns.org
nr_targets
51
nr_delivery_sites
50
nr_delivery_sites_online
46
nr_payloads
1
ksa
dec
pdir
MN1
delivered payloads:
1
6f06c83a6b524d7f514f0c43ac432a10
downloaded
2015-08-04 19:18:35
scanned (on VT)
2015-08-04 17:17:50
positives
3 / 56
detected as
Malwarebytes
Trojan.Agent.ED
ESET-NOD32
Win32/Battdil.AK
Kaspersky
HEUR:Trojan.Win32.Generic
not detected by:
Bkav, TotalDefense, MicroWorld-eScan, nProtect, CAT-QuickHeal, McAfee, Zillya, SUPERAntiSpyware, TheHacker, Alibaba, K7GW, K7AntiVirus, Agnitum, Cyren, Symantec, TrendMicro-HouseCall, Avast, ClamAV, GData, BitDefender, NANO-Antivirus, ViRobot, Tencent, Ad-Aware, Emsisoft, Comodo, F-Secure, DrWeb, VIPRE, TrendMicro, McAfee-GW-Edition, Sophos, F-Prot, Jiangmin, Avira, Antiy-AVL, Kingsoft, Arcabit, AegisLab, AhnLab-V3, Microsoft, ByteHero, ALYac, AVware, VBA32, Baidu-International, Zoner, Rising, Ikarus, Fortinet, AVG, Panda, Qihoo-360
delivery sites:
1
https://24.220.92.193/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
2
https://176.36.251.208/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
3
https://67.221.195.6/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
4
https://69.163.81.211/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
5
https://216.254.231.11/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
6
https://24.33.131.116/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
7
https://104.174.123.66/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
8
https://72.230.82.80/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
9
https://173.248.31.6/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
10
https://69.9.204.114/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
11
https://188.255.239.34/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
12
https://69.144.171.44/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
13
https://65.33.236.173/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
14
https://98.214.11.253/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
15
https://24.148.217.188/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
16
https://173.216.247.74/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
17
https://77.48.30.156/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
18
https://37.57.144.177/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
19
https://95.143.141.50/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
20
https://87.249.142.189/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
21
https://85.135.104.170/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
22
https://76.84.81.120/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
23
https://84.246.161.47/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
24
https://217.168.210.122/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
25
https://68.70.242.203/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
26
https://64.111.36.52/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
27
https://178.222.250.35/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
28
https://94.154.107.172/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
29
https://194.106.166.22/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
30
https://188.255.243.105/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
31
https://188.255.236.184/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
32
https://98.181.17.39/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
33
https://67.207.229.215/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
34
https://67.206.96.68/mn21.zip
35
https://67.222.197.54/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
36
https://67.22.167.163/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
37
https://209.40.238.170/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
38
https://64.111.42.64/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
39
https://72.174.240.148/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
40
https://63.248.156.246/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
41
https://72.175.10.116/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
42
https://208.117.68.78/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
43
https://162.153.189.143/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
44
https://72.171.9.146/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
45
https://67.222.201.61/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
46
https://209.27.49.117/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
47
https://67.222.201.222/mn21.zip
48
https://109.236.121.91/mn21.zip
49
https://203.129.197.50/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
50
https://45.64.176.132/mn21.zip