Collection of Upatre Samples ( alpha version)

Config File for afe4d9eec99eb7c6e5f45791a27d0206

md5
afe4d9eec99eb7c6e5f45791a27d0206
source
malwr
link
https://malwr.com/analysis/ZDc0YWVkZDk2MDY4NDQ3NGFlYjRjNTA4ZDY5ZjRmN2Q/
malware_name
tocuweek.exe
temp_file
scandate
2015-07-22 05:30:36
parsed
2015-07-26 04:51:52
decrypt_keys
3458a145
check_keys
c2_server
93.185.4.90
baseport
9587
useragent
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.36 (KHTML, like Gecko) Chrome/44.0.2455.81 Safari/535.36
payload_format
sim
old
0
clientip
checkip.dyndns.org
nr_targets
51
nr_delivery_sites
50
nr_delivery_sites_online
43
nr_payloads
1
ksa
dec
pdir
K23
delivered payloads:
1
0932936358511e3621dafa030022c339
downloaded
2015-09-01 18:55:10
scanned (on VT)
2015-07-30 10:15:18
positives
27 / 56
detected as
MicroWorld-eScan
Gen:Variant.Kazy.689830
McAfee
PWS-FCDJ!EEE7F5701C78
Malwarebytes
Spyware.Dyre
VIPRE
LooksLike.Win32.Dyzap.b (v)
K7GW
Trojan ( 004c92a31 )
K7AntiVirus
Trojan ( 004c92a31 )
NANO-Antivirus
Trojan.Win32.DownLoader15.dukats
ESET-NOD32
a variant of Win32/Kryptik.DQYP
GData
Gen:Variant.Kazy.689830
BitDefender
Gen:Variant.Kazy.689830
Agnitum
Trojan.Kryptik!SEJgnm2cOE4
Ad-Aware
Gen:Variant.Kazy.689830
Emsisoft
Gen:Variant.Kazy.689830 (B)
F-Secure
Gen:Variant.Kazy.689830
TrendMicro
TROJ_GEN.R01TC0DGS15
McAfee-GW-Edition
PWS-FCDJ!EEE7F5701C78
Sophos
Mal/EncPk-NZ
Cyren
W32/Trojan.CAPI-8828
Arcabit
Trojan.Kazy.DA86A6
Microsoft
PWS:Win32/Dyzap.T
ALYac
Gen:Variant.Kazy.689830
AVware
LooksLike.Win32.Dyzap.b (v)
Baidu-International
Adware.Win32.iBryte.DQYP
Ikarus
Trojan.Win32.Crypt
Fortinet
W32/Kryptik.DQYP!tr
AVG
PSW.Generic12.CBAH
Panda
Trj/CI.A
not detected by:
Bkav, nProtect, CAT-QuickHeal, SUPERAntiSpyware, TheHacker, Alibaba, F-Prot, Symantec, TrendMicro-HouseCall, Avast, ClamAV, Kaspersky, AegisLab, ByteHero, Tencent, Comodo, DrWeb, Zillya, Jiangmin, Avira, Antiy-AVL, Kingsoft, ViRobot, AhnLab-V3, TotalDefense, VBA32, Zoner, Rising, Qihoo-360
delivery sites:
1
https://24.220.92.193/g13.png
0932936358511e3621dafa030022c339
2
https://176.36.251.208/g13.png
0932936358511e3621dafa030022c339
3
https://67.221.195.6/g13.png
0932936358511e3621dafa030022c339
4
https://69.163.81.211/g13.png
0932936358511e3621dafa030022c339
5
https://216.254.231.11/g13.png
0932936358511e3621dafa030022c339
6
https://24.33.131.116/g13.png
0932936358511e3621dafa030022c339
7
https://104.174.123.66/g13.png
0932936358511e3621dafa030022c339
8
https://72.230.82.80/g13.png
0932936358511e3621dafa030022c339
9
https://173.248.31.6/g13.png
0932936358511e3621dafa030022c339
10
https://173.243.255.79/g13.png
0932936358511e3621dafa030022c339
11
https://69.9.204.114/g13.png
0932936358511e3621dafa030022c339
12
https://188.255.239.34/g13.png
0932936358511e3621dafa030022c339
13
https://69.144.171.44/g13.png
0932936358511e3621dafa030022c339
14
https://65.33.236.173/g13.png
0932936358511e3621dafa030022c339
15
https://216.16.93.250/g13.png
16
https://98.214.11.253/g13.png
0932936358511e3621dafa030022c339
17
https://24.148.217.188/g13.png
0932936358511e3621dafa030022c339
18
https://173.216.247.74/g13.png
0932936358511e3621dafa030022c339
19
https://77.48.30.156/g13.png
0932936358511e3621dafa030022c339
20
https://37.57.144.177/g13.png
0932936358511e3621dafa030022c339
21
https://68.55.59.145/g13.png
22
https://95.143.141.50/g13.png
0932936358511e3621dafa030022c339
23
https://194.228.203.19/g13.png
0932936358511e3621dafa030022c339
24
https://87.249.142.189/g13.png
0932936358511e3621dafa030022c339
25
https://85.135.104.170/g13.png
0932936358511e3621dafa030022c339
26
https://76.84.81.120/g13.png
0932936358511e3621dafa030022c339
27
https://84.246.161.47/g13.png
0932936358511e3621dafa030022c339
28
https://217.168.210.122/g13.png
0932936358511e3621dafa030022c339
29
https://81.90.175.7/g13.png
30
https://68.70.242.203/g13.png
0932936358511e3621dafa030022c339
31
https://64.111.36.52/g13.png
0932936358511e3621dafa030022c339
32
https://178.222.250.35/g13.png
0932936358511e3621dafa030022c339
33
https://94.154.107.172/g13.png
0932936358511e3621dafa030022c339
34
https://68.119.5.32/g13.png
35
https://194.106.166.22/g13.png
0932936358511e3621dafa030022c339
36
https://188.255.243.105/g13.png
0932936358511e3621dafa030022c339
37
https://188.255.236.184/g13.png
0932936358511e3621dafa030022c339
38
https://98.181.17.39/g13.png
0932936358511e3621dafa030022c339
39
https://67.207.229.215/g13.png
0932936358511e3621dafa030022c339
40
https://67.206.96.68/g13.png
0932936358511e3621dafa030022c339
41
https://67.222.197.54/g13.png
0932936358511e3621dafa030022c339
42
https://69.8.50.85/g13.png
0932936358511e3621dafa030022c339
43
https://67.22.167.163/g13.png
0932936358511e3621dafa030022c339
44
https://209.40.238.170/g13.png
0932936358511e3621dafa030022c339
45
https://98.102.44.38/g13.png
46
https://64.111.42.64/g13.png
0932936358511e3621dafa030022c339
47
https://192.232.14.249/g13.png
48
https://72.174.240.148/g13.png
0932936358511e3621dafa030022c339
49
https://63.248.156.246/g13.png
0932936358511e3621dafa030022c339
50
https://64.184.183.20/g13.png