Collection of Upatre Samples ( alpha version)

Config File for 3847bfdf6656e3bd9b7cd6043de3ed5f

md5
3847bfdf6656e3bd9b7cd6043de3ed5f
source
virusshare
link
download.4n6?sample=77a2f7975c086b6018f31ec81030074ca10d9a72a940d2387b7c42eafe1ed591
malware_name
aloyzan.exe
temp_file
scandate
2015-07-23 22:30:36
parsed
2015-07-24 08:59:03
decrypt_keys
0e607a92
check_keys
c2_server
38.65.142.12
baseport
9587
useragent
Mozilla/5.0 (Windows NT 6.1; rv:36.0) Gecko/20100101 Firefox/36.0
payload_format
sim
old
0
clientip
icanhazip.com
nr_targets
51
nr_delivery_sites
50
nr_delivery_sites_online
37
nr_payloads
1
ksa
dec
pdir
RT77
delivered payloads:
1
4227d39d28895efe3402eaaab1730ac9
downloaded
2015-07-10 20:19:20
scanned (on VT)
2015-07-10 18:19:40
positives
1 / 55
detected as
DrWeb
Trojan.Dyre.546
not detected by:
Bkav, TotalDefense, MicroWorld-eScan, nProtect, CAT-QuickHeal, ALYac, Malwarebytes, Zillya, AegisLab, K7AntiVirus, BitDefender, K7GW, TheHacker, NANO-Antivirus, F-Prot, Symantec, ESET-NOD32, TrendMicro-HouseCall, Avast, ClamAV, GData, Kaspersky, Alibaba, Agnitum, SUPERAntiSpyware, Tencent, Ad-Aware, Emsisoft, Comodo, F-Secure, VIPRE, TrendMicro, Sophos, Cyren, Jiangmin, Avira, Antiy-AVL, Kingsoft, Arcabit, ViRobot, AhnLab-V3, Microsoft, ByteHero, McAfee, AVware, VBA32, Baidu-International, Zoner, Rising, Ikarus, Fortinet, AVG, Panda, Qihoo-360
delivery sites:
1
https://109.86.226.85/rt17.png
4227d39d28895efe3402eaaab1730ac9
2
https://24.220.92.193/rt17.png
4227d39d28895efe3402eaaab1730ac9
3
https://176.36.251.208/rt17.png
4227d39d28895efe3402eaaab1730ac9
4
https://173.216.240.56/rt17.png
5
https://69.163.81.211/rt17.png
4227d39d28895efe3402eaaab1730ac9
6
https://216.254.231.11/rt17.png
4227d39d28895efe3402eaaab1730ac9
7
https://24.33.131.116/rt17.png
4227d39d28895efe3402eaaab1730ac9
8
https://104.174.123.66/rt17.png
4227d39d28895efe3402eaaab1730ac9
9
https://72.230.82.80/rt17.png
4227d39d28895efe3402eaaab1730ac9
10
https://173.248.22.227/rt17.png
11
https://173.248.31.6/rt17.png
4227d39d28895efe3402eaaab1730ac9
12
https://173.243.255.79/rt17.png
4227d39d28895efe3402eaaab1730ac9
13
https://69.9.204.114/rt17.png
4227d39d28895efe3402eaaab1730ac9
14
https://188.255.239.34/rt17.png
4227d39d28895efe3402eaaab1730ac9
15
https://69.144.171.44/rt17.png
4227d39d28895efe3402eaaab1730ac9
16
https://65.33.236.173/rt17.png
4227d39d28895efe3402eaaab1730ac9
17
https://71.99.130.24/rt17.png
18
https://216.16.93.250/rt17.png
19
https://98.214.11.253/rt17.png
4227d39d28895efe3402eaaab1730ac9
20
https://24.148.217.188/rt17.png
4227d39d28895efe3402eaaab1730ac9
21
https://98.209.75.164/rt17.png
22
https://76.105.248.137/rt17.png
23
https://173.216.247.74/rt17.png
4227d39d28895efe3402eaaab1730ac9
24
https://77.48.30.156/rt17.png
4227d39d28895efe3402eaaab1730ac9
25
https://37.57.144.177/rt17.png
4227d39d28895efe3402eaaab1730ac9
26
https://68.55.59.145/rt17.png
27
https://95.143.141.50/rt17.png
28
https://194.228.203.19/rt17.png
4227d39d28895efe3402eaaab1730ac9
29
https://87.249.142.189/rt17.png
4227d39d28895efe3402eaaab1730ac9
30
https://85.135.104.170/rt17.png
4227d39d28895efe3402eaaab1730ac9
31
https://76.84.81.120/rt17.png
4227d39d28895efe3402eaaab1730ac9
32
https://84.246.161.47/rt17.png
4227d39d28895efe3402eaaab1730ac9
33
https://217.168.210.122/rt17.png
4227d39d28895efe3402eaaab1730ac9
34
https://81.90.175.7/rt17.png
35
https://81.93.205.218/rt17.png
4227d39d28895efe3402eaaab1730ac9
36
https://81.93.205.251/rt17.png
4227d39d28895efe3402eaaab1730ac9
37
https://87.229.109.250/rt17.png
38
https://68.70.242.203/rt17.png
4227d39d28895efe3402eaaab1730ac9
39
https://66.215.30.118/rt17.png
40
https://64.111.36.52/rt17.png
4227d39d28895efe3402eaaab1730ac9
41
https://178.222.250.35/rt17.png
4227d39d28895efe3402eaaab1730ac9
42
https://94.154.107.172/rt17.png
4227d39d28895efe3402eaaab1730ac9
43
https://68.119.5.32/rt17.png
44
https://194.106.166.22/rt17.png
4227d39d28895efe3402eaaab1730ac9
45
https://188.255.243.105/rt17.png
4227d39d28895efe3402eaaab1730ac9
46
https://188.255.236.184/rt17.png
4227d39d28895efe3402eaaab1730ac9
47
https://98.181.17.39/rt17.png
4227d39d28895efe3402eaaab1730ac9
48
https://67.221.195.175/rt17.png
49
https://67.207.229.215/rt17.png
4227d39d28895efe3402eaaab1730ac9
50
https://67.206.96.68/rt17.png
4227d39d28895efe3402eaaab1730ac9