For a description of Keydnap, please see the article about Keydnap on WeLiveSecurity.
SHA-1 | Filename | First seen on VirusTotal | Backdoor download URL | Decoy description or URL |
---|---|---|---|---|
|
info_list.txt |
2016-05-09 |
hxxp://dev.aneros.com/media/icloudsyncd |
"Most Common Interview Questions" |
|
screenshot_2016-06-28-01.jpg |
2016-06-28 |
hxxp://freesafesoft.com/icloudsyncd |
BlackHat-TDS Panel screenshot |
|
screenshot.jpg |
2016-05-07 |
hxxp://dev.aneros.com/media/icloudsyncd |
Firefox 20 about screenshot |
|
CVdetails.doc |
2016-05-03 |
hxxp://lovefromscratch.ca/wp-admin/css/icloudsyncd |
hxxp://lovefromscratch.ca/wp-admin/CVdetails.doc |
|
CVdetails.doc |
2016-05-03 |
hxxp://lovefromscratch.ca/wp-admin/css/icloudsyncd |
hxxp://lovefromscratch.ca/wp-admin/CVdetails.doc |
|
logo.jpg |
2016-06-02 |
hxxp://dev.aneros.com/media/icloudsyncd |
sanelite logo |
|
screenshot_9324 2.jpg |
2016-06-28 |
hxxp://freesafesoft.com/icloudsyncd |
Some C&C panel |
SHA-1 | C&C | Version |
---|---|---|
|
hxxps://g5wcesdfjzne7255.onion.to |
1.3.1 |
|
hxxps://r2elajikcosf7zee.onion.to |
1.3.5 |
A patch for UPX to unpack the samples is provided here: https://github.com/eset/malware-research/blob/master/keydnap/keydnap_upx.patch