SHA1 hash:
- 633885f16ef1e848a2e057169ab45d363f3f8c57 (Информация по письму в МИД от 6 июля статус и прилагаемые документы.exe)
Description
A backdoor written in the C++ programming language and targeting computers running the Windows OS. It allows malicious actors to remotely connect to target devices via a remote shell in order to execute commands.
Operating routine
BackDoor.RShell.169 connects to the C2 server at 109[.]172.85[.]63. Next, it uses silent mode to run the cmd.exe command prompt, through which attackers execute commands in the system.
The backdoor’s logic that is responsible for connecting to the C2 server and remotely executing commands via the cmd.exe command prompt