logo

Sayad (Flying Kitten) Infostealer - malware analysis

ID: 1b4040a3-c2da-4ed5-a3d7-35d4b497d384

STIX ID: report--1b4040a3-c2da-4ed5-a3d7-35d4b497d384

Threat Score

70/100

Uploaded: 2026-08-14

Published Date: 2014-12-03

Last Modified Date: 2014-12-03

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This analysis details the Sayad infostealer distributed via phishing which unpacks a binder and a .NET DLL (DiagnosticsService.dll) that collects system info, browser data, credentials, chat histories, VPN/RDP/FTP credentials, keylogs and screenshots, encrypts the stolen data with an embedded RSA key and uploads it to a hardcoded C2 (0o0o0o0o0.com / 107.6.182.179); the report documents process behavior, persistence via HKCU Run entries, file hashes, YARA rules, and suggests a possible link to the Ajax Security Team.