Collection of Upatre Samples ( alpha version)

Config File for 32f0a124ec9b0848e11a0969e694de20

md5
32f0a124ec9b0848e11a0969e694de20
source
virusshare
link
download.4n6?sample=9a4166f6037cf01d20c736949a7bf0426a85f4dc88e852663425d45af9f01ea2
malware_name
begbakel.exe
temp_file
scandate
2015-09-05 09:05:01
parsed
2015-09-16 11:47:28
decrypt_keys
15ae8b62
check_keys
c2_server
93.185.4.90
baseport
9587
useragent
Mozilla/5.0 (Windows NT 6.1;WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2272.89 Safari/537.36 OPR/28.0.1750.48
payload_format
sim
old
0
clientip
checkip.dyndns.org
nr_targets
51
nr_delivery_sites
50
nr_delivery_sites_online
23
nr_payloads
1
ksa
dec
pdir
MN1
delivered payloads:
1
6f06c83a6b524d7f514f0c43ac432a10
downloaded
2015-08-04 19:18:35
scanned (on VT)
2015-08-04 17:17:50
positives
3 / 56
detected as
Malwarebytes
Trojan.Agent.ED
ESET-NOD32
Win32/Battdil.AK
Kaspersky
HEUR:Trojan.Win32.Generic
not detected by:
Bkav, TotalDefense, MicroWorld-eScan, nProtect, CAT-QuickHeal, McAfee, Zillya, SUPERAntiSpyware, TheHacker, Alibaba, K7GW, K7AntiVirus, Agnitum, Cyren, Symantec, TrendMicro-HouseCall, Avast, ClamAV, GData, BitDefender, NANO-Antivirus, ViRobot, Tencent, Ad-Aware, Emsisoft, Comodo, F-Secure, DrWeb, VIPRE, TrendMicro, McAfee-GW-Edition, Sophos, F-Prot, Jiangmin, Avira, Antiy-AVL, Kingsoft, Arcabit, AegisLab, AhnLab-V3, Microsoft, ByteHero, ALYac, AVware, VBA32, Baidu-International, Zoner, Rising, Ikarus, Fortinet, AVG, Panda, Qihoo-360
delivery sites:
1
https://24.220.92.193/mn21.zip
2
https://176.36.251.208/mn21.zip
3
https://67.221.195.6/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
4
https://69.163.81.211/mn21.zip
5
https://216.254.231.11/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
6
https://24.33.131.116/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
7
https://104.174.123.66/mn21.zip
8
https://72.230.82.80/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
9
https://173.248.31.6/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
10
https://69.9.204.114/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
11
https://188.255.239.34/mn21.zip
12
https://69.144.171.44/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
13
https://65.33.236.173/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
14
https://98.214.11.253/mn21.zip
15
https://24.148.217.188/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
16
https://173.216.247.74/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
17
https://77.48.30.156/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
18
https://37.57.144.177/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
19
https://95.143.141.50/mn21.zip
20
https://87.249.142.189/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
21
https://85.135.104.170/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
22
https://76.84.81.120/mn21.zip
23
https://84.246.161.47/mn21.zip
24
https://217.168.210.122/mn21.zip
25
https://68.70.242.203/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
26
https://64.111.36.52/mn21.zip
27
https://178.222.250.35/mn21.zip
28
https://94.154.107.172/mn21.zip
29
https://194.106.166.22/mn21.zip
30
https://188.255.243.105/mn21.zip
31
https://188.255.236.184/mn21.zip
32
https://98.181.17.39/mn21.zip
33
https://67.207.229.215/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
34
https://67.206.96.68/mn21.zip
35
https://67.222.197.54/mn21.zip
36
https://67.22.167.163/mn21.zip
37
https://209.40.238.170/mn21.zip
38
https://64.111.42.64/mn21.zip
39
https://72.174.240.148/mn21.zip
40
https://63.248.156.246/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
41
https://72.175.10.116/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
42
https://208.117.68.78/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
43
https://162.153.189.143/mn21.zip
44
https://72.171.9.146/mn21.zip
45
https://67.222.201.61/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
46
https://209.27.49.117/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
47
https://67.222.201.222/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
48
https://109.236.121.91/mn21.zip
49
https://203.129.197.50/mn21.zip
6f06c83a6b524d7f514f0c43ac432a10
50
https://45.64.176.132/mn21.zip