Kill files thats all payload. Sample courtesy of nullptr, he found it and was so kind to share.
Valid digital certificate - Air Software, certification center - COMODO Time Stamping Signer.
However this maybe not a true trojan but a buggy part of some kind of installation. However obviously deleting user files in current directory its kind of malicious behavior.
Valid digital certificate - Air Software, certification center - COMODO Time Stamping Signer.
However this maybe not a true trojan but a buggy part of some kind of installation. However obviously deleting user files in current directory its kind of malicious behavior.
Attachments
pass: malware
(220.28 KiB) Downloaded 53 times
(220.28 KiB) Downloaded 53 times
Ring0 - the source of inspiration