Phoenix

Por_ela.rar

Once run, it uses DLL Side-Loading to execute malicious code within a legitimate Windows process. 3. Malware Behavior

The archive contains a heavily obfuscated loader. Por_Ela.rar

Por_Ela.rar , Fatura_Vencida.rar , Documento_Digital.rar Once run, it uses DLL Side-Loading to execute