Collection of Upatre Samples ( alpha version)

Config File for 8afb19562401113afef92ace304d1396

md5
8afb19562401113afef92ace304d1396
source
malwr
link
https://malwr.com/analysis/NDk4YzVmNzc2NTBkNGI5M2JlYzhhNDk0YWZmM2I0ZGE/
malware_name
tvsetiti.exe
temp_file
scandate
2015-07-20 05:51:46
parsed
2015-07-23 23:21:35
decrypt_keys
49a7eb36
check_keys
c2_server
38.65.142.12
baseport
13920
useragent
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.33 (KHTML, like Gecko) Chrome/43.0.2457.81 Safari/537.33
payload_format
sim
old
0
clientip
icanhazip.com
nr_targets
51
nr_delivery_sites
50
nr_delivery_sites_online
31
nr_payloads
1
ksa
dec
pdir
U12
delivered payloads:
1
9348bb3d95f75d15ac7e42a03b3216fb
downloaded
2015-07-26 08:02:11
scanned (on VT)
2015-07-08 18:34:40
positives
18 / 56
detected as
MicroWorld-eScan
Trojan.Agent.BKYZ
nProtect
Trojan.Agent.BKYZ
Malwarebytes
Trojan.Upatre.Gen
K7AntiVirus
Trojan ( 004c7c6a1 )
BitDefender
Trojan.Agent.BKYZ
K7GW
Trojan ( 004c7c6a1 )
ByteHero
Virus.Win32.Heur.c
Avast
Win32:Malware-gen
Ad-Aware
Trojan.Agent.BKYZ
Sophos
Troj/Upatre-OU
F-Secure
Trojan.Agent.BKYZ
DrWeb
Trojan.Upatre.5179
VIPRE
Trojan.Win32.Generic.pak!cobra
Emsisoft
Trojan.Agent.BKYZ (B)
Arcabit
Trojan.Agent.BKYZ
AhnLab-V3
Trojan/Win32.Upatre
ESET-NOD32
Win32/Battdil.AD
GData
Trojan.Agent.BKYZ
not detected by:
Bkav, CAT-QuickHeal, ALYac, Zillya, AegisLab, TheHacker, Agnitum, F-Prot, Symantec, TrendMicro-HouseCall, ClamAV, Kaspersky, Alibaba, NANO-Antivirus, ViRobot, Rising, Comodo, TrendMicro, McAfee-GW-Edition, Cyren, Jiangmin, Avira, Fortinet, Antiy-AVL, Kingsoft, SUPERAntiSpyware, Microsoft, TotalDefense, McAfee, AVware, VBA32, Panda, Zoner, Tencent, Ikarus, AVG, Baidu-International, Qihoo-360
delivery sites:
1
https://109.86.226.85/u12.png
2
https://24.220.92.193/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
3
https://176.36.251.208/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
4
https://173.216.240.56/u12.png
5
https://69.163.81.211/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
6
https://216.254.231.11/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
7
https://24.33.131.116/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
8
https://104.174.123.66/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
9
https://72.230.82.80/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
10
https://173.248.22.227/u12.png
11
https://173.248.31.6/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
12
https://173.243.255.79/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
13
https://69.9.204.114/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
14
https://188.255.239.34/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
15
https://98.222.64.184/u12.png
16
https://69.144.171.44/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
17
https://65.33.236.173/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
18
https://66.196.63.33/u12.png
19
https://71.99.130.24/u12.png
20
https://216.16.93.250/u12.png
21
https://66.196.61.218/u12.png
22
https://98.214.11.253/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
23
https://24.148.217.188/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
24
https://98.209.75.164/u12.png
25
https://76.105.248.137/u12.png
26
https://173.216.247.74/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
27
https://77.48.30.156/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
28
https://77.95.195.68/u12.png
29
https://37.57.144.177/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
30
https://68.55.59.145/u12.png
31
https://95.143.141.50/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
32
https://194.228.203.19/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
33
https://87.249.142.189/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
34
https://85.135.104.170/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
35
https://76.84.81.120/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
36
https://84.246.161.47/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
37
https://217.168.210.122/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
38
https://81.90.175.7/u12.png
39
https://81.93.205.218/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
40
https://81.93.205.251/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
41
https://87.229.109.250/u12.png
42
https://96.46.103.232/u12.png
43
https://68.70.242.203/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
44
https://66.215.30.118/u12.png
45
https://96.46.99.183/u12.png
46
https://96.46.100.49/u12.png
47
https://64.111.36.52/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
48
https://178.222.250.35/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
49
https://94.154.107.172/u12.png
9348bb3d95f75d15ac7e42a03b3216fb
50
https://68.119.5.32/u12.png