SHA1:
- 0950ba59af3ffa8ac32882aa280d1fbe604d5c68 (VvaldiSetup.exe)
- 2857eca1bb4dd401958107a9b7d0d2faaeea4e61 (MonsterInstall.exe)
- b934131ab7fbf66caf58a9deb6c689bf6d979fee (MonsterInstall.exe)
Description
The MonsterInstall trojan installer.
Operating routine
It checks the operating system bitness, to download and launch the appropriate version of http://fastscreen[.]ru/app/other/Chrome32.exe or http://fastscreen[.]ru/app/other/Chrome64.exe.
The downloaded file has an overlay with additional information:
The trojan checks the first number in the “source” parameter value. If it is not 10, it quits. Then it checks whether Windows Node is installed. If it is, it goes idle. If not, it unpacks winsw from its body in C:\Windows\WinKit\0.0.0.1\daemon\service.exe. After that, it downloads http://fastscreen[.]ru/app/other/winKit.7z and unpacks it in C:\Windows\WinKit\0.0.0.1\.
The last step is to launch C:\Windows\WinKit\0.0.0.1\run.exe update.js.