The sample we examined is an installer of a popular firewall app for Mac and Windows called Little Snitch, available for download from various torrent websites. Names of the .NET compiled Windows executable are as follows: ...When the downloaded .ZIP file is extracted, it contains a .DMG file hosting the installer for Little Snitch.
geblokkeerd