Saefko

Malware family · 5 sample(s) · 5 indicator record(s) · 1 signing certificate(s) · Active 2019-03-20 → 2019-10-07 (experimental)

About Saefko

Multi-layered RAT. Identified by the com.sas.seafkoagent.seafkoagent package; the C2 URL and server password are static field init values of the GLOBALS config class.

Indicators

IndicatorTypeSampleFirst seen
choice-takeoff.000webhostapp.com/server.php domain 1ef3612c8b83… 2019-03-20
kingparrot.000webhostapp.com/server.php domain fb94d34523b0… 2019-10-07
sassaefko.000webhostapp.com/server.php domain 83ebcc9ac17e… 2019-10-04
sys1234567.000webhostapp.com/server.php domain 08cea5ba0e69… 2019-10-05
webknight619.000webhostapp.com/server.php domain 6260f500a084… 2019-10-04