{"id":2455,"date":"2021-04-17T21:48:29","date_gmt":"2021-04-18T02:48:29","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2455"},"modified":"2021-04-17T21:49:12","modified_gmt":"2021-04-18T02:49:12","slug":"saint-bot-a-new-password-stealing-threat","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/","title":{"rendered":"Saint bot &#8211; A new password stealing threat"},"content":{"rendered":"\n<p>Saint Bot is a downloader that appeared recently, and is slowly gaining momentum. Thieves (Taurus Stealer) or additional chargers were seen falling, but its design allows it to be used to distribute any type of malware in addition to employing a wide variety of techniques that, although not novel, indicate a certain level of sophistication considering its relatively new appearance.<\/p>\n\n\n\n<p>The infection chain analyzed by the cybersecurity firm begins with a phishing email containing an embedded ZIP file (&#8220;bitcoin.zip&#8221;) claiming to be a bitcoin wallet when, in fact, it is a PowerShell script under the guise of a file of shortcut .LNK. This PowerShell script then downloads the malware from the next stage, a WindowsUpdate.exe executable, which in turn drops a second executable (InstallUtil.exe) that is responsible for downloading two more executables called def.exe and putty. exe.<\/p>\n\n\n\n<p>This threat has the purpose of implementing additional malware on the compromised system. It is likely to be used as a first stage payload, which can sit idle and wait for further instructions from the command and control server. Depending on the Saint Bot Malware configuration, it can disguise its malicious process under different names; It seems that it commonly uses the fake process &#8216;EhStorAurhn.exe&#8217;.<\/p>\n\n\n\n<p>Cybersecurity experts mention that it has the ability to avoid certain types of targets. First, it will check the default language settings of the infected system. If it belongs to Russia, Ukraine, Belarus, Armenia, Kazakhstan, Romania or Moldova, it will not proceed with the attack. Like other Trojan downloaders, it also checks registry entries and system drivers for strings typical of virtual environments. In this way, threats like Saint Bot Malware try to bypass the controlled environments used for malware analysis.<\/p>\n\n\n\n<p>Regardless of how sophisticated Saint Bot Malware is, you can be sure that stopping it is not difficult. All you need to do is use an anti-malware software package remember that you can never be completely protected.<\/p>\n\n\n\n<p>Related reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/pos-malware-is-a-virus-that-steals-financial-data\/\">PoS Malware is a Virus that steals financial data<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/omg-cable-a-method-to-steal-all-your-data\/\">OMG Cable \u2013 A method to steal all your data<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Saint Bot is a downloader that appeared recently, and is slowly gaining momentum. Thieves (Taurus Stealer) or additional chargers were seen falling, but its design allows it to be used to distribute any type of malware in addition to employing a wide variety of techniques that, although not novel, indicate a certain level of sophistication [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2456,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2455","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Saint bot - A new password stealing threat - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"A new Malware rises with the name of Saint bot, which allows the distribution of any type of malware and that is why we will analyze it today\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Saint bot - A new password stealing threat - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"A new Malware rises with the name of Saint bot, which allows the distribution of any type of malware and that is why we will analyze it today\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-04-18T02:48:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-04-18T02:49:12+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/neee.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1707\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/saint-bot-a-new-password-stealing-threat\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/saint-bot-a-new-password-stealing-threat\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Saint bot &#8211; A new password stealing threat\",\"datePublished\":\"2021-04-18T02:48:29+00:00\",\"dateModified\":\"2021-04-18T02:49:12+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/saint-bot-a-new-password-stealing-threat\\\/\"},\"wordCount\":353,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/saint-bot-a-new-password-stealing-threat\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/neee.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/saint-bot-a-new-password-stealing-threat\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/saint-bot-a-new-password-stealing-threat\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/saint-bot-a-new-password-stealing-threat\\\/\",\"name\":\"Saint bot - A new password stealing threat - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/saint-bot-a-new-password-stealing-threat\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/saint-bot-a-new-password-stealing-threat\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/neee.jpg\",\"datePublished\":\"2021-04-18T02:48:29+00:00\",\"dateModified\":\"2021-04-18T02:49:12+00:00\",\"description\":\"A new Malware rises with the name of Saint bot, which allows the distribution of any type of malware and that is why we will analyze it today\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/saint-bot-a-new-password-stealing-threat\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/saint-bot-a-new-password-stealing-threat\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/saint-bot-a-new-password-stealing-threat\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/neee.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/neee.jpg\",\"width\":2560,\"height\":1707},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/saint-bot-a-new-password-stealing-threat\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Saint bot &#8211; A new password stealing threat\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Saint bot - A new password stealing threat - Truxgo Server Blog","description":"A new Malware rises with the name of Saint bot, which allows the distribution of any type of malware and that is why we will analyze it today","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/","og_locale":"es_MX","og_type":"article","og_title":"Saint bot - A new password stealing threat - Truxgo Server Blog","og_description":"A new Malware rises with the name of Saint bot, which allows the distribution of any type of malware and that is why we will analyze it today","og_url":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-04-18T02:48:29+00:00","article_modified_time":"2021-04-18T02:49:12+00:00","og_image":[{"width":2560,"height":1707,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/neee.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Saint bot &#8211; A new password stealing threat","datePublished":"2021-04-18T02:48:29+00:00","dateModified":"2021-04-18T02:49:12+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/"},"wordCount":353,"commentCount":2,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/neee.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/","url":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/","name":"Saint bot - A new password stealing threat - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/neee.jpg","datePublished":"2021-04-18T02:48:29+00:00","dateModified":"2021-04-18T02:49:12+00:00","description":"A new Malware rises with the name of Saint bot, which allows the distribution of any type of malware and that is why we will analyze it today","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/neee.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/04\/neee.jpg","width":2560,"height":1707},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/saint-bot-a-new-password-stealing-threat\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Saint bot &#8211; A new password stealing threat"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2455","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2455"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2455\/revisions"}],"predecessor-version":[{"id":2464,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2455\/revisions\/2464"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2456"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2455"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2455"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2455"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}