<Drive name for removable media>:\$recycler\<File name>.exe
<Drive name for removable media>:\documents.lnk
<Drive name for removable media>:\photos.lnk
<Drive name for removable media>:\backup.lnk
Malicious functions
Patches code
in AMSI dll
nnrqxno.exe process, Amsi.dll module
in NTDLL dll
nnrqxno.exe process, ntdll.dll module
Modifies file system
Sets the 'hidden' attribute to the following files
<Drive name for removable media>:\$recycler\<File name>.exe
Network activity
Connects to
'ap#.#pify.org':443
'ic###azip.com':443
'17#.#15.236.150':44411
TCP
Other
'ap#.#pify.org':443
'ic###azip.com':443
UDP
DNS ASK ap#.#pify.org
DNS ASK ic###azip.com
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more