sha1:
- 903283f46df39c46d3be506fd99fdf61b6f0edeb (st.exe)
Packer: PYINSTALLER
Description
A trojan written in C++ and designed to run on computers with Microsoft Windows operating systems. It functions as an SFTP client for downloading files and directories from infected machines.
Operating routine
The malware accepts four arguments:
- sftp_server — the server to which a target file or directory is to be uploaded;
- sftp_user — the SFTP username;
- sftp_password — the SFTP password;
- folder_path — the path to the file or directory to be downloaded.
The trojan uses the domain eu-central-1[.]sftpcloud[.]io as the SFTP server.
Trojan.Uploader.36875 creates an archive folder_backup.zip containing the target directory and uploads it to the remote server.
An example of the trojan’s execution:
st.exe eu-central-1[.]sftpcloud[.]io 40433706825f4152a64f5fefbe1675d8 Nv6Rf4aL0E37jZRr2kHvgZomsTSUGi3h C:\Users\<user_name>\Documents\tda