Collection of Upatre Samples ( alpha version)

Config File for 63244c991b3f52cd5e2bac87cebcbaf3

md5
63244c991b3f52cd5e2bac87cebcbaf3
source
virusshare
link
download.4n6?sample=0875c59c8f7c69befb7dce934db7c9652614a9ad90cabc37721f56114bb026f0
malware_name
fevar.exe
temp_file
scandate
0000-00-00 00:00:00
parsed
2015-07-07 21:40:43
decrypt_keys
894a9863
check_keys
c2_server
188.165.205.194
baseport
9587
useragent
Opera
payload_format
sim
old
0
clientip
nr_targets
4
nr_delivery_sites
4
nr_delivery_sites_online
0
nr_payloads
0
ksa
pdir
1408cw, 1408h
delivered payloads:
no payloads delivered when checked
delivery sites:
1
https://aqumen-freight.co.uk/guide/404.zip
2
https://knutars.com/handler/404.zip
3
https://insercomgas.com/website/imgs/148h.zip
4
https://mcjetlee.com/css/148h.zip