Do not download - Cryptominer
The archive is password protected to avoid AV getting the content before unpacking
This are the contents of the .rar archive:
the Flyff.exe is the one that is the Cryptominer. It will get moved to:
C:\Users\%USERNAME%\AppData\Roaming:
After it has been moved it will be renamed to ctfmon.exe and added to the system startup:
it will load up a Cryptominer:
Code:
"✅ Произошёл запуск клиппера на компьютере: WDAGUtilityAccount\n🤖 Worker: 607012704"
Code:
@"{""ok"":true,""result"":{""message_id"":22615,""from"":{""id"":5200079587,""is_bot"":true,""first_name"":""clipteseterdcp"",""username"":""clipteseterdcpbot""},""chat"":{""id"":607012704,""first_name"":""Leon26"",""username"":""Sssr26"",""type"":""private""},""date"":1674651087,""text"":""\u2705 \u041f\u0440\u043e\u0438\u0437\u043e\u0448\u0451\u043b \u0437\u0430\u043f\u0443\u0441\u043a \u043a\u043b\u0438\u043f\u043f\u0435\u0440\u0430 \u043d\u0430 \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u0435: WDAGUtilityAccount\n\ud83e\udd16 Worker: 607012704""}}"
If you have downloaded this, please reinstall your system