SHA1:
- 6ee6296b0dd259aaa8bc4bb8641966e0fbfc8afb
Windows loader Trojan that is distributed using the DoublePulsar backdoor.
pdb: C:\Users\чГ╜\Desktop\RunDLL\Release\RunDLL.pdb
Downloads an executable file “hxxp://183.***.***.244:5317/mat.exe”, saves it as “c:\\matt.exe” and launches it. After that the Trojan adds to the system a user “Administrstor” with password “Dj.djapple445”. The added user is also included in the group “Administrators”.