Collection of Upatre Samples ( alpha version)

Config File for ed1691bcb02e70a3f7678c07b2f50df5

md5
ed1691bcb02e70a3f7678c07b2f50df5
source
malwr
link
https://malwr.com/analysis/YjE3YjMyMDNlYTllNGYwNGE3YjgzYjM4NGZhYTBiYjI/
malware_name
livrew.exe
temp_file
liva8BA5.log
scandate
2015-04-07 05:05:51
parsed
2015-07-26 12:33:41
decrypt_keys
28571a75
check_keys
5ff1bd0a
c2_server
141.105.141.87
baseport
9587
useragent
Mazilla/5.0
payload_format
reg
old
0
clientip
checkip.dyndns.org
nr_targets
3
nr_delivery_sites
2
nr_delivery_sites_online
0
nr_payloads
0
ksa
pdir
0304uk21
delivered payloads:
no payloads delivered when checked
delivery sites:
1
https://eltubazopanama.com/zar3.rtf
2
https://encontrohuambo.com/css/zar3.rtf