SHA1:
- ecc02c3cccf8496d12ce48e98e5219128ed72e05 (install.zip)
- 271bbad1ba905d5a5971f712f8084710cbfa76fa (install.js)
- c0d39a50799fa11ea402a7634b972479d5a6e16c (MonsterInstall.dll)
Description
A module of the MonsterInstall trojan. It is downloaded as a ZIP archive at https://corteli[.]com/file-checker/install.zip Operating routine
The install.js file launches the exported “mymain” function of the MonsterInstall.dll library.
The MonsterInstall.dll library connects to https://corteli.com/file-checker/enter.php and receives links to the trojan “updater” and “worker” modules. It then downloads those components and installs them.