Collection of Upatre Samples ( alpha version)

Config File for 6915e9e242cd6cbae6d9b9d37da10a4f

md5
6915e9e242cd6cbae6d9b9d37da10a4f
source
malwr
link
https://malwr.com/analysis/ZjI2M2MxZTBhM2U0NDY1YTk4ZDU1N2RmY2M3ZWVlYzE/
malware_name
ekrakdeep.exe
temp_file
scandate
2015-08-15 12:43:13
parsed
2015-08-16 03:31:41
decrypt_keys
3e281d47
check_keys
c2_server
93.185.4.90
baseport
9587
useragent
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.36 (KHTML, like Gecko) Chrome/44.0.2455.81 Safari/535.36
payload_format
sim
old
0
clientip
checkip.dyndns.org
nr_targets
51
nr_delivery_sites
50
nr_delivery_sites_online
33
nr_payloads
1
ksa
dec
pdir
ACE2
delivered payloads:
1
638b6cc95a452a29077ae4b9edfcc8bf
downloaded
2015-07-21 22:26:25
scanned (on VT)
2015-07-21 20:26:10
positives
13 / 56
detected as
MicroWorld-eScan
Gen:Variant.Kazy.686583
K7GW
Trojan ( 004c8d431 )
K7AntiVirus
Trojan ( 004c8d431 )
ESET-NOD32
Win32/Battdil.AH
BitDefender
Gen:Variant.Kazy.686583
ViRobot
Trojan.Win32.Upatre.489984.A[h]
ByteHero
Trojan.Malware.Obscu.Gen.002
Ad-Aware
Gen:Variant.Kazy.686583
Emsisoft
Gen:Variant.Kazy.686583 (B)
F-Secure
Gen:Variant.Kazy.686583
Arcabit
Trojan.Kazy.DA79F7
GData
Gen:Variant.Kazy.686583
AVG
Ransomer.JIQ
not detected by:
Bkav, nProtect, CAT-QuickHeal, McAfee, Malwarebytes, VIPRE, SUPERAntiSpyware, TheHacker, Alibaba, NANO-Antivirus, F-Prot, Symantec, TrendMicro-HouseCall, Avast, ClamAV, Kaspersky, Agnitum, Tencent, Comodo, DrWeb, Zillya, TrendMicro, McAfee-GW-Edition, Sophos, Cyren, Jiangmin, Avira, Fortinet, Antiy-AVL, Kingsoft, AegisLab, AhnLab-V3, Microsoft, TotalDefense, ALYac, AVware, VBA32, Panda, Zoner, Rising, Ikarus, Baidu-International, Qihoo-360
delivery sites:
1
https://24.220.92.193/ac12.png
2
https://176.36.251.208/ac12.png
3
https://67.221.195.6/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
4
https://69.163.81.211/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
5
https://216.254.231.11/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
6
https://24.33.131.116/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
7
https://104.174.123.66/ac12.png
8
https://72.230.82.80/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
9
https://173.248.31.6/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
10
https://173.243.255.79/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
11
https://69.9.204.114/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
12
https://188.255.239.34/ac12.png
13
https://69.144.171.44/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
14
https://65.33.236.173/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
15
https://216.16.93.250/ac12.png
16
https://98.214.11.253/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
17
https://24.148.217.188/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
18
https://173.216.247.74/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
19
https://77.48.30.156/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
20
https://37.57.144.177/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
21
https://68.55.59.145/ac12.png
22
https://95.143.141.50/ac12.png
23
https://194.228.203.19/ac12.png
24
https://87.249.142.189/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
25
https://85.135.104.170/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
26
https://76.84.81.120/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
27
https://84.246.161.47/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
28
https://217.168.210.122/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
29
https://81.90.175.7/ac12.png
30
https://81.93.205.218/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
31
https://81.93.205.251/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
32
https://68.70.242.203/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
33
https://64.111.36.52/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
34
https://178.222.250.35/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
35
https://94.154.107.172/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
36
https://68.119.5.32/ac12.png
37
https://194.106.166.22/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
38
https://188.255.243.105/ac12.png
39
https://188.255.236.184/ac12.png
40
https://98.181.17.39/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
41
https://67.207.229.215/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
42
https://67.206.96.68/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
43
https://67.222.197.54/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
44
https://69.8.50.85/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
45
https://67.22.167.163/ac12.png
46
https://209.40.238.170/ac12.png
638b6cc95a452a29077ae4b9edfcc8bf
47
https://98.102.44.38/ac12.png
48
https://64.111.42.64/ac12.png
49
https://192.232.14.249/ac12.png
50
https://72.174.240.148/ac12.png