Collection of Upatre Samples ( alpha version)

Config File for fca303684917f844897503f567b63920

md5
fca303684917f844897503f567b63920
source
malwr
link
https://malwr.com/analysis/MmZiNDY1M2EwOGYxNDlhNjk0ODMyNjM0MTMxMTgwYTQ/
malware_name
helocex.exe
temp_file
hel818.log
scandate
2015-03-03 03:25:38
parsed
2015-06-24 21:33:40
decrypt_keys
3dde79b0
check_keys
40060adb
c2_server
190.111.9.129
baseport
9587
useragent
Mazilla/5.0
payload_format
reg
old
0
clientip
checkip.dyndns.org
nr_targets
3
nr_delivery_sites
2
nr_delivery_sites_online
0
nr_payloads
0
ksa
pdir
0203us22
delivered payloads:
no payloads delivered when checked
delivery sites:
1
https://ingenieriayahorrodeenergia.com/razey/keys/textd.pdf
2
https://dejavuproduction.com/data/media/textd.pdf