Collection of Upatre Samples ( alpha version)

Config File for bfc64d7a9ad68d39ac9b999ed34481b6

md5
bfc64d7a9ad68d39ac9b999ed34481b6
source
malwr
link
https://malwr.com/analysis/MDIzODIxYmVmNWM5NDRhNTk1MDVjMTRkYTAxNDFmNmQ/
malware_name
wdmquickly.exe
temp_file
scandate
2015-07-21 05:46:22
parsed
2015-07-21 22:33:18
decrypt_keys
76281d42
check_keys
c2_server
93.185.4.90
baseport
9587
useragent
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.36 (KHTML, like Gecko) Chrome/44.0.2455.81 Safari/535.36
payload_format
sim
old
0
clientip
checkip.dyndns.org
nr_targets
51
nr_delivery_sites
50
nr_delivery_sites_online
46
nr_payloads
1
ksa
dec
pdir
PKP2
delivered payloads:
1
22cf8295bad1846fb6c2f38e6934bf1a
downloaded
2015-07-21 22:33:18
scanned (on VT)
2015-07-21 20:33:03
positives
9 / 56
detected as
MicroWorld-eScan
Gen:Variant.Kazy.686583
ESET-NOD32
Win32/Battdil.J
GData
Gen:Variant.Kazy.686583
BitDefender
Gen:Variant.Kazy.686583
ByteHero
Trojan.Malware.Obscu.Gen.002
Ad-Aware
Gen:Variant.Kazy.686583
Emsisoft
Gen:Variant.Kazy.686583 (B)
F-Secure
Gen:Variant.Kazy.686583
Arcabit
Trojan.Kazy.DA79F7
not detected by:
Bkav, nProtect, CAT-QuickHeal, McAfee, Malwarebytes, VIPRE, SUPERAntiSpyware, TheHacker, Alibaba, K7GW, K7AntiVirus, NANO-Antivirus, F-Prot, Symantec, TrendMicro-HouseCall, Avast, ClamAV, Kaspersky, Agnitum, ViRobot, Rising, Comodo, DrWeb, Zillya, TrendMicro, McAfee-GW-Edition, Sophos, Cyren, Jiangmin, Avira, Antiy-AVL, Kingsoft, AegisLab, AhnLab-V3, Microsoft, TotalDefense, ALYac, AVware, VBA32, Panda, Zoner, Tencent, Ikarus, Fortinet, AVG, Baidu-International, Qihoo-360
delivery sites:
1
https://24.220.92.193/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
2
https://176.36.251.208/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
3
https://67.221.195.6/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
4
https://69.163.81.211/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
5
https://216.254.231.11/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
6
https://24.33.131.116/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
7
https://104.174.123.66/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
8
https://72.230.82.80/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
9
https://173.248.31.6/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
10
https://173.243.255.79/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
11
https://69.9.204.114/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
12
https://188.255.239.34/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
13
https://69.144.171.44/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
14
https://65.33.236.173/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
15
https://216.16.93.250/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
16
https://98.214.11.253/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
17
https://24.148.217.188/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
18
https://173.216.247.74/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
19
https://77.48.30.156/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
20
https://37.57.144.177/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
21
https://95.143.141.50/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
22
https://194.228.203.19/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
23
https://87.249.142.189/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
24
https://85.135.104.170/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
25
https://76.84.81.120/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
26
https://84.246.161.47/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
27
https://217.168.210.122/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
28
https://81.90.175.7/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
29
https://68.70.242.203/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
30
https://64.111.36.52/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
31
https://178.222.250.35/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
32
https://94.154.107.172/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
33
https://68.119.5.32/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
34
https://194.106.166.22/pikp12.png
35
https://188.255.243.105/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
36
https://188.255.236.184/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
37
https://98.181.17.39/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
38
https://67.207.229.215/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
39
https://67.206.96.68/pikp12.png
40
https://67.222.197.54/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
41
https://69.8.50.85/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
42
https://67.22.167.163/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
43
https://209.40.238.170/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
44
https://98.102.44.38/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
45
https://64.111.42.64/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
46
https://72.174.240.148/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
47
https://63.248.156.246/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a
48
https://64.184.183.20/pikp12.png
49
https://72.175.10.116/pikp12.png
50
https://74.116.183.136/pikp12.png
22cf8295bad1846fb6c2f38e6934bf1a