SHA1:
- 8d06ee83054c790f2401352af29ad0c56b0db52f (updater.dll)
- b7c0b0f7c8765a3021b4f907e0835f8bee53730b (fc.exe)
Description
An enhanced version of Trojan.MonsterInstall.8. The script and the address for data transmission have been changed: https://corteli[.]com/file-checker/v2/enter.php.
The fc.exe file is downloaded at http://corteli[.]com/file-checker/v2/FC.exe.
The executable file contains the path to the debugging symbols:
B:\Develop\VisualStudioProject\LEGACY\FCInstall\FC\Release\FC.pdb