Collection of Upatre Samples ( alpha version)

Config File for 2bafc99b1f149a88044963b577385f3b

md5
2bafc99b1f149a88044963b577385f3b
source
virusshare
link
download.4n6?sample=110dc2cdabc3ffcc924312b44e025072ec2641bf55bdcc8abdc426ddd9e8eced
malware_name
rifws.exe
temp_file
scandate
0000-00-00 00:00:00
parsed
2015-07-07 22:02:16
decrypt_keys
894a9863
check_keys
c2_server
188.165.205.194
baseport
9587
useragent
Opera
payload_format
sim
old
0
clientip
nr_targets
4
nr_delivery_sites
4
nr_delivery_sites_online
0
nr_payloads
0
ksa
pdir
1408cw_2, 1408h
delivered payloads:
no payloads delivered when checked
delivery sites:
1
https://aqumen-freight.co.uk/guide/404.zip
2
https://knutars.com/handler/404.zip
3
https://insercomgas.com/website/imgs/148h.zip
4
https://mcjetlee.com/css/148h.zip