SHA1 hash:
- dd98dcf6807a7281e102307d61c71b7954b93032 (Аппарат Правительства Российской Федерации по вопросу отнесения реализуемых на территории Сибирского федерального округа проектов к проектам.exe)
Description
A backdoor that runs a reverse shell on Windows OS computers and allows cybercriminals to access them remotely. It is written in the Golang programming language.
Operating routine
Depending on which modification is involved, the backdoor connects to the following IP addresses:
- 195[.]2.78[.]133
- 62[.]113.114[.]209
The backdoor’s logic that is responsible for connecting to the C2 server