SHA1 hash:
- f40ef5cd25c3f9d552be6a43218be91d07650660 (ConsoleApp1.exe)
Description
A trojan app written in the C# programming language and designed for computers running the Microsoft Windows operating system. It steals documents, text files, and images from infected devices and sends them to the attackers.
Operating routine
Trojan.FileSpyNET.5 searches for files of the following formats on an infected computer .txt, .doc, .docx, .xlsx, .jpg, .png, .pdf. It copies the files it has found to the directory C:\\Users\\Public\\Libraries\\. It then puts them into a ZIP archive and uploads to the C2 server at 89[.]110.98[.]234/fileupper/getupper.php.