Collection of Upatre Samples ( alpha version)

Config File for c5024b027926ea4c573945492e91a0c8

md5
c5024b027926ea4c573945492e91a0c8
source
virusshare
link
download.4n6?sample=fdb5ee90aacbac3fcde716adfc837f96d0f12f85d9a5ffd9f60eea6f66376b00
malware_name
document.exe
temp_file
act8A5E.tmp
scandate
0000-00-00 00:00:00
parsed
2015-06-29 01:26:40
decrypt_keys
66f0291f
check_keys
650174b0
c2_server
202.153.35.133
baseport
9587
useragent
Mozilla/5.0
payload_format
reg
old
0
clientip
nr_targets
2
nr_delivery_sites
2
nr_delivery_sites_online
0
nr_payloads
0
ksa
pdir
2801uk12
delivered payloads:
no payloads delivered when checked
delivery sites:
1
https://ruralcostarica.com/handler/kora_k12.pdf
2
https://saddlebrookschooldistrict.org/sys3000.org/files/kora_k12.pdf