Malware Signature

The following table shows a list of malware samples and the corresponding botnet C&C (ip:port) associated with Sofacy

Database Entry


Malware:Sofacy
First seen:2016-11-04 10:27:38 UTC
Last seen:never

Malware Samples


The table below documents all malware samples associated with this malware family.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-11-04 10:27:386831f2daff7fbf3e693018f99dcee010Virustotal results 43/70 (61.43%) Sofacy87.236.215.21:443
2016-11-04 10:27:386831f2daff7fbf3e693018f99dcee010Virustotal results 43/70 (61.43%) Sofacy87.236.215.21:443