Last seven days
- First activity
- Aug 28, 2026
- Last activity
- Sep 3, 2026
- Feed role
- C2 / Distribution
- Host form
- 3 IP / 83 hostnames
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 8d793a16bf2e7153df21e2ede4b0baf6e080596073b27ecbeac6613b6a68b8d8 d780677e97da00b2b90849741720c1a02e758356630b63242a18074775c69e1c 5ed4549130cffbb84b5e76479cfd8067932e6c4c329abb7f97246f15d815f899 6acc0714d3cbab8c42b03d03044f0c56134ed9a651bd1f7a88d8c8f56c978f6a ad4f485adf4c3d7570a745e01f8c201b1ba0265cc6f58db6c48ebcc902bb58b3 d4f64726fa4b1f0c35f4f346e192babdfee3fc8e7c1ac41421073ae18eed7feb e593726c92fe5a9d88df8f134726b57ad66c5ed04fc3d61144406ec8214d8680 Reporting
Upatre, a malware downloader commonly spread through phishing emails, was observed using a simple anti-analysis technique to avoid detection in automated sandbox environments. The malware calls the Windows API GetTickCount and terminates if the infected system appears to have been running for less than roughly 12 minutes, a condition that often matches freshly booted virtual machines used for short-lived malware analysis. The evasion tactic can cause Upatre samples to appear benign because they never execute their malicious payload during analysis. Researchers reported a surge in new Upatre samples using the method and noted that the downloader is frequently used to fetch the Dyre banking Trojan, which steals credentials. Palo Alto Networks said its WildFire platform mitigates the trick by modifying the GetTickCount return value so the malware believes the host has been running for hours.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.