SHA1:
- befdec16c459bd71bd7e735276ad1a10adc8fd76 (updater.dll)
- 25186470ae0982fff93c2569fb9de5e489fc011b (updater.dll)
Description
A module of the MonsterInstall trojan.
Operating routine
It sends user device information to https://xyi-sosi-guboi-trisi[.]xyz/app.php. In response, it receives links to the “worker” and “updater” trojan files, unpacks them, and installs them on the system.
The executable file contains the path to the debugging symbols: B:\Develop\VisualStudioProject\botnet\MonsterInstall\Release\MonsterInstall.pdb