SHA1:
- 390e62c53526f78e50502c1aacf67a1715de458d (rar-sfx)
- 390e62c53526f78e50502c1aacf67a1715de458d (py2exe)
- 2a171430d489bcc522d1ce2cb8b9063bc8ae12a6 (yadiskclient__main__.pyc)
A spying Trojan for Microsoft Windows devices. Written in Python. The malicious script’s original name is yadiskclient.py.
The Trojan scans hard drives searching for Telegram, FileZilla, cookies files and saved browser passwords based on Chromium. It also searches for files with the following extensions: DOCX, DOC, TXT, DAT, RTF, PDF. All found information is packed into archives and loaded to the Yandex.Disk account registered by cybercriminals.